HomeSecurityRA World ransomware group attacks construction sector

RA World ransomware group attacks construction sector

RA World, an emerging ransomware group, has been increasingly active since March 2024, using a multi-extortion tactic to steal data and threaten to leak it if the ransom is not paid.

See also: Los Angeles Superior Court: Systems shutdown due to ransomware

RA World ransomware

Its leak website shows a recent shift in targets from healthcare organizations to the manufacturing sector, possibly due to the search for higher ransom payments, but the reason remains unclear. The RA World ransomware group, active since mid-2023, primarily targets the manufacturing sector. According to leak website data, it has also affected organizations in the US, Europe , and Asia.

The group recently changed its name from RA Group to RA World, as reflected in the ransom notes and the encrypted file extension (.RAWLD). The RA World ransomware group maintains a leak website to pressure victims into paying the ransom. The website was redesigned in 2024, with a dark theme and incorporating pop culture references.

The leak website displays a list of victims and allows visitors to search for relevant information on a social media platform. For each victim, RA World can reveal allegedly stolen data and use manipulative tactics to damage the victim’s reputation.

The analysis identified RA World attackers targeting poorly configured or vulnerable servers for initial access.

See also: Play ransomware: New Linux variant targets VMWare ESXi environments

For lateral movement, the attackers used Impacket to execute remote commands on compromised endpoints, extracting the NTDS database , SAM group , and system registry, archiving the databases with makecab , and deleting the originals.

RA World ransomware group attacks construction sector

A recent RA World ransomware attack used a multi-stage infection chain. The initial loader (Stage1.exe) recognized the system domain and looked for exclusion rules.

It then deployed Stage2.exe to a shared network path, whose behavior depended on the Safe Mode state, where it decrypted and executed a Babuk variant using a domain name-based key.

According to Palo Alto Networks, the Babuk variant (Stage3.exe) used custom modifications, including a new mutex, ransom note file name, and encrypted file extension.

The RA World ransomware group shares some TTPs (Tactics, Techniques, and Procedures) with BRONZE STARLIGHT, a Chinese threat group. Both groups use the open source NPS tool, exploit Impacket modules for lateral movement, and deploy Babuk-based ransomware.

See also: Russian hackers admitted their involvement in LockBit ransomware

Ransomware attacks have become increasingly prevalent in our digital landscape, posing significant threats to individuals, businesses, and entire organizations. These malicious attacks typically begin when an unsuspecting user clicks on a deceptive link or downloads compromised software, leading to the encryption of critical files and data. Once files are locked, cybercriminals demand a ransom, often in cryptocurrency, in exchange for the decryption key. The impact of such attacks can be devastating, resulting in financial losses, operational disruptions, and long-term reputational damage.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS