For about three years, the NoName ransomware gang has been targeting small and medium-sized businesses around the world with its own malware, but it is now believed to be operating as an affiliate of the RansomHub group.

Generally, the gang uses custom tools, known as the Spacecolon malware family, and deploys them after gaining access to a network through brute-force. It also exploits vulnerabilities such as EternalBlue (CVE-2017-0144) or ZeroLogon (CVE-2020-1472).
In more recent attacks, hackers have used ScRansom ransomware , which replaced their previous encryptor, Scarab . Additionally, attackers have used the leaked LockBit 3.0 ransomware builder , creating a similar data leak website and using similar ransom notes
ScRansom encryptor
Cybersecurity firm ESET calls the NoName ransomware gang “CosmicBeetle” and has been tracking its activities since 2023.
See also: Charles Darwin High School closed after Ransomware attack
In a new report, researchers report that ScRansom supports partial encryption with different speed modes, while there is also an 'ERASE' mode that overwrites the file contents with a fixed value, making them unrecoverable.
ScRansom can encrypt files on all drives, including fixed, remote, and removable media. Additionally, attackers can specify which file extensions to target, via a customizable list.
Before launching the encryptor, ScRansom interrupts a list of processes and services running on a Windows computer, including Windows Defender, Volume Shadow Copy, SVCHost, RDPclip, LSASS, and processes related to VMware tools.
ESET notes that ScRansom's encryption scheme is quite complex, using a combination of AES-CTR-128 and RSA-1024 and an additional AES key generated to protect the public key. However, the multi-step process, with multiple key exchanges, sometimes introduces errors that can lead to failure to decrypt files (even when the correct keys are used).
“This decryption approach is typical of an inexperienced ransomware operator. Experienced gangs prefer to make the decryption process as easy as possible to increase the chances of successful decryption, which boosts their reputation and increases the likelihood that victims” ESET said.
See also: Ransomware Fog group attacks financial services

NoName ransomware gang “uses” the popularity of other groups
Since ScRansom was not an established name in the ransomware landscape, the gang decided to take a different approach to become more famous.
In September 2023, CosmicBeetle created a dark web called “NONAME”, which was a modified copy of the LockBit site. The site featured victims who had actually been compromised by LockBit, not ScRansom.
In November 2023, hackers registered the domain lockbitblog[.]info and used the LockBit theme and logo.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Researchers also discovered some recent attacks where a LockBit sample was deployed, but the ransom note had a victim ID that they had already linked to the CosmicBeetle group. Additionally, the tools and malware used in this attack have been attributed to CosmicBeetle/NoName.
“Using leaked builders is a common practice for inexperienced ransomware gangs. It allows them to abuse the brand of their established competitors, while also providing them with a ransomware sample that usually works properly,” ESET explained.
NoName ransomware gang develops RansomHub tools
While investigating a recent ransomware incident involving a failed ScRansom deployment, ESET researchers found that hackers attacked again using the RansomHub group's EDR killer, a tool that allows for privilege escalation and disabling of security agents.
See also: 2024: Significant increase in active ransomware gangs
Two days later, NoName hackers executed the RansomHub ransomware on the compromised machine.
The researchers noted that the EDR killer's extraction method was typical of the CosmicBeetle/NoName group and not a RansomHub affiliate.
Given that there are no public leaks of RansomHub code or its builder, ESET researchers “believe with moderate confidence that CosmicBeetle/NoName has registered as a new RansomHub affiliate.”

Ransomware protection
Back up your data: One of the most effective ways to protect yourself from a attack is to regularly back up your data. This ensures that even if your data is encrypted by ransomware, you will have a safe copy that can be restored without paying the ransom.
Update your operating system and software: Out-of-date operating systems and software are vulnerable to cyberattacks. It is important to regularly update your devices with the latest security and software updates to prevent any vulnerabilities that could be exploited by ransomware.
Beware of suspicious emails and links: Ransomware attacks often start with a phishing email or malicious link. It is important to be cautious when opening emails from unknown senders. Also, do not click on suspicious links. These could lead to ransomware being installed on your device.
Use antivirus software: Installing reputable antivirus software on your devices can help you detect and prevent attacks . Be sure to update your antivirus software regularly to ensure it is equipped to handle new threats.
Education: One of the most important steps to protect against ransomware is education. It is important to stay up to date on the latest types of ransomware and how they work. Organizations should also train their employees on how to identify and avoid potential attacks.
Implement strong passwords: Weak or easy passwords can make it easier for hackers to gain access to your devices and install ransomware. It's important to use strong and unique passwords and enable two-factor authentication whenever possible.
Use a VPN: A VPN encrypts your internet connection and provides an extra layer of security against ransomware attacks. This is especially important when using public Wi-Fi networks, which are often unsecured and vulnerable to cyberattacks.
Source: www.bleepingcomputer.com
