HomeSecurityRansomHub exploits ZeroLogon in ransomware attacks

RansomHub exploits ZeroLogon in ransomware attacks

In recent attacks involving the RansomHub ransomware, attackers have exploited the ZeroLogon flaw in the Windows Netlogon Remote Protocol from 2020 (CVE-2020-1472) to gain initial access to the victim's environment.

See also: Linux version of TargetCompany ransomware targets VMware ESXi

ZeroLogon ransomware

Before deploying the ransomware, attackers used several dual-purpose tools, including remote access products from companies like Atera and Splashtop and network scanners from NetScan among others, according to researchers at Symantec Broadcom.

“ZeroLogon involves an escalation of privilege condition that occurs when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller using the Netlogon Remote Protocol,” says Adam Neel, senior threat intelligence engineer at Critical Start. “It is critical for organizations to ensure that this vulnerability ZeroLogon is patched and mitigated to help protect against ransomware attacks from RansomHub.”

RansomHub is a ransomware-as-a-service (RaaS) and a threat that has garnered a lot of attention since it first appeared in February. Symantec currently ranks it as the fourth most prolific ransomware in terms of victims demanded, after Lockbit , Play, and Qilin.

See also: LockBit ransomware: FBI recovered over 7,000 decryption keys

BlackFog — among several security vendors tracking the threat — has listed more than five dozen organizations that RansomHub has targeted in the few months it has been operating. Many appear to be smaller and mid-sized companies, though there are a few recognizable names, most notably auction house Christie's and UnitedHealth Group subsidiary Change Healthcare

RansomHub

Dick O'Brien, principal intelligence analyst in Symantec's threat hunting team, says the ransomware group that exploited ZeroLogon has publicly admitted to 61 victims in the past three months. That compares to 489 victims for Lockbit, 101 for the Play group, and 92 for Qilin, he says.

RansomHub is among a small group of RaaS operators that have emerged following the recent takedowns by law enforcement of major ransomware companies Lockbit and ALPHV/BlackCat. The group has sought to capitalize on some of the uncertainty and distrust caused by the takedowns to try to attract new affiliates to its RaaS. One of its tactics is to offer affiliates the ability to collect ransom payments directly from victims and then pay RansomHub a 10%. This is very different from the usual model where the RaaS operator is the one who collects the ransom payments from victims and later pays a percentage to the affiliate.

See also: Russia behind ransomware attack on London hospitals

Ransomware-as-a-Service (RaaS), such as RansomHub exploiting ZeroLogon in attacks, represents a growing threat in the cybersecurity realm. This model allows cybercriminals , often with minimal technical expertise, to deploy ransomware attacks by renting the necessary tools and infrastructure from more skilled developers. Operating similarly to legitimate Software-as-a-Service (SaaS), RaaS platforms offer user-friendly interfaces, customer support, and payment management. As a result, the barrier to entry for conducting ransomware attacks is significantly lowered. This proliferation has led to an increased frequency and sophistication of ransomware incidents, posing significant risks to individuals, organizations, and governments worldwide.

Source: darkreading

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS