The BlackCat/ALPHV ransomware criminal group has started using a new tool called 'Munchkin', which uses virtual machines to install encryptors on hidden network devices.
See also: Alphv/BlackCat ransomware: Did it steal data from Morrison Community Hospital?

Manchkin allows BlackCat to run on remote systems or remotely encrypt Server Message Block (SMB) or Common Internet File (CIFS).
The introduction of Munchkin to BlackCat's already extensive and advanced arsenal makes RaaS more attractive to cybercriminals looking to become partners in data breaches.
Palo Alto Networks' Unit 42 team discovered that BlackCat's new Munchkin tool is a customized distribution of the Alpine OS Linux operating system , which is provided as an ISO file.
After compromising a device, the malicious actors install VirtualBox and create a new virtual machine using the Munchkin ISO. This Munchkin virtual machine includes a series of scripts and tools that allow the threat actors to extract passwords, spread laterally across the network, create a malicious BlackCat 'Sphynx' encryption payload, and execute programs on computers on the network.
Upon startup, it changes the root password to one known only to the attackers and uses the 'tmux' tool to execute a malicious Rust-based binary named 'controller' that begins loading scripts used in the attack. The 'controller' uses the included configuration file, which provides the access IDs, victims' credentials, and authentication secrets, as well as configuration instructions, directories and blacklists of files and folders, tasks to run, and nodes to attack for encryption.
This configuration is used to create customized BlackCat Encryptor executables in the /payloads/. These files are then sent to remote devices to encrypt files or encrypt SMB and CIFS network shares.
A common problem affecting malware victims and cybercriminals is that samples are often leaked through malware analysis websites. Analyzing malware samples allows researchers to have full access to the negotiation conversation between a malware gang and its victim
See also: BlackCat ransomware: Claimed responsibility for attack on Florida courts
To prevent this, collaborators provide negotiated access credentials to the Tor negotiation site at startup. This makes it impossible for them to access a victim's negotiation conversation, even if they have access to the sample used in the attack.

Because of this, the attackers are warning partners to delete Munchkin VMs and ISOs to prevent these access credentials from being leaked. The developers also include instructions and tips for using the 'Controller' to monitor the progress of the attack and initiate tasks.
Munchkin makes it easier for BlackCat ransomware collaborators to perform various tasks, including bypassing security solutions protecting the device . This is because virtual machines provide a layer of isolation from the operating system, making detection and analysis more challenging for security software.
Additionally, the choice of the Alpine operating system ensures a small digital footprint, while the tool’s automated functions reduce the need for manual intervention and noise from command feeds. Finally, Munchkin’s versatility, with a variety of Python, unique configurations, and the ability to replace payloads as needed, makes the tool easy to customize for specific goals or campaigns.
See also: McLaren Health Care – Blackcat ransomware: Patient data leaked to the dark web?
An attack by BlackCat ransomware can have significant impacts on affected systems.
- File Encryption: BlackCat ransomware encrypts the user's files and documents, making them inaccessible.
- Data Loss: If the user cannot decrypt their files or if they are unable to pay the required ransom, the data can be lost forever.
- Interference with System Operation: BlackCat ransomware can cause severe limitations in system operation, affecting its performance.
Tips for Dealing with BlackCat Ransomware
Professional environments and individual users should take the necessary measures to prevent and respond to attacks from BlackCat ransomware.
- Regularly back up important organizational data and adhere to strict policies during the process.
- Install strong security software and keep it always up to date to detect and block malicious threats.
- Be informed and educate your staff about common hacker tactics.
Source: bleepingcomputer
