A newly discovered ransomware operation named “Kasseika” has joined the club of threats that use Bring Your Own Vulnerable Driver (BYOVD) to disable software before encrypting files.
See also: ALPHV/BlackCat ransomware: Recent outage may be due to a “strike” by authorities

Kasseika ransomware exploits the Martini driver (Martini.sys/viragt64.sys), which belongs to TG Soft's VirtIT Agent System, to disable products protecting the system it targets.
According to Trend Micro, the company's analysts first discovered and examined Kasseika in December 2023. The new ransomware variant features multiple attack chains and source code similarities to BlackMatter.
As BlackMatter's code has not been publicly leaked since its deactivation in late 2021, Kasseika was likely created by former members of the threat group or experienced ransomware actors who purchased its code.
The attacks begin with a phishing email sent to employees of the targeted organization, aiming to steal their credentials, which will be used for initial access to the corporate network.
Kasseika operators then abuse the Windows PsExec tool to execute malicious .bat files on the infected system and other systems they have gained access to through lateral movement.
The batch file checks for the existence of a process named 'Martini.exe' and terminates it to prevent interference. It then downloads the vulnerable driver 'Martini.sys' to the target machine.
See also: Spain: Phishing emails distribute LockBit Locker ransomware
The presence of this driver is critical in the attack chain, as Kasseika will not proceed further if the creation of the 'Martini' service fails or if 'Martini.sys' is not found on the system.
Using BYOVD attacks, also known as exploiting flaws in the loaded driver, the malware gains the rights to terminate 991 processes from a predefined list, many of which correspond to antivirus products, security tools, analysis tools, and system management tools.

Finally, Kasseika ransomware executes Martini.exe to terminate the CA processes and then launches the main ransomware file (smartscreen_protected.exe). It then executes a 'clear.bat' script to remove traces of the attack.
The ransomware uses the ChaCha20 and RSA encryption algorithms to encrypt target files, adding a pseudo-random character to the file names, similar to BlackMatter. Kasseika leaves a ransom demand on each folder it encrypts and also changes the computer wallpaper to display a note about the attack.
Finally, Kasseika purges system event logs after encryption, using commands such as 'wevutil.exe' to erase traces of its activities and make security analysis more difficult.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: HTC Global Services: Is ALPHV/BlackCat ransomware behind the attack?
BlackMatter ransomware is an aggressive type of malware that can have serious impacts on IT systems. Once it infects a system, it encrypts the user's data, making it inaccessible.
This means that users cannot access their data, which may include important documents, photos, videos, and other files. This can cause significant disruption to business operations and have serious financial implications.
Additionally, BlackMatter ransomware demands that users pay a ransom to decrypt their data. This can be very expensive and there is no guarantee that the attackers will actually restore the data after payment.
Finally, a BlackMatter ransomware infection can lead to a breach . Attackers can steal sensitive information, such as personal data, corporate documents, or customer information, before encrypting files. This can lead to further legal and regulatory implications.
Source: bleepingcomputer
