HomeSecurityFaust, Kasseika, Kuiper: New ransomware gangs in the threat landscape

Faust, Kasseika, Kuiper: New ransomware gangs in the threat landscape

Security researchers have identified a new variant of the Phobos, known as Faust.

Faust, Kasseika, Kuiper ransomware

Fortinet FortiGuard Labs, which analyzed this new ransomware variant, said it spreads via a Microsoft Excel (.XLAM) containing a VBA script.

“ The attackers used the Gitea to store multiple encrypted files, each of which carried a malicious binary service ,” said security researcher Cara Lin . “ When these files are injected into a system’s memory, they initiate a file encryption attack .”

See also: Akira ransomware: Cyberattack on Bucks County emergency system

Faust is the latest variant of Phobos ransomware. Other variants include Eking, Eight, Elbie, Devos, and 8Base. It is worth noting that Faust was documented by Cisco Talos in November 2023.

The new variant is said to be active since 2022 and “does not target specific industries or regions.”

The infection begins with an XLAM document that, when opened, downloads Base64-encoded data from the Gitea service to save a harmless file . At the same time, it secretly downloads an executable file disguised as an update for AVG AntiVirus software (“AVG updater. exe”).

In turn, the binary acts as a downloader to retrieve and launch another executable named “SmartScreen Defender Windows.exe.” This is how the encryption process begins via a fileless attack to deploy the malicious shellcode.

“The Faust variant exhibits the ability to maintain persistence in an environment and create multiple threads for efficient execution,” Lin said.

See also: NoName ransomware: Many organizations on its victim list

The new variant comes alongside several other new ransomware families, including Albabat (also known as White Bat), Kasseika, Kuiper, Mimus, and NONAME.

Trellix, which tested the Windows, Linux, and macOS versions of Kuiper, attributed the ransomware (based on Golang) to a group called RobinHood.

Faust, Kasseika, Kuiper: New ransomware gangs in the threat landscape

NONAME has also attracted attention because data mimics that of the LockBit group.

New ransomware groups are increasing the risk to businesses. At the same time, hackers are using new as well as old, tried and tested techniques. For example, they are using spear phishing, which targets specific individuals or organizations and is more likely to be successful.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Additionally, these groups use deception techniques to convince victims to click on malicious links or open malicious files. This may include forging official emails or websites to appear trustworthy.

See also: NCSC: Artificial intelligence (AI) will increase ransomware attacks

Finally, new ransomware groups often exploit vulnerabilities to invade victims' systems. This can include exploiting older versions of software that have not been updated or exploiting unreported vulnerabilities (zero-day vulnerabilities).

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS