HomeSecurityCrypt Ghouls targets Russian businesses with LockBit 3.0 and... ransomware

Crypt Ghouls targets Russian businesses with LockBit 3.0 and Babuk ransomware

A new group called Crypt Ghouls has been linked to a series of attacks targeting Russian businesses and government agencies with the LockBit 3.0 and Babuk ransomware. The hackers appears to be to disrupt victims' business activities and make financial gain.

Crypt Ghouls ransomware LockBit 3.0 and Babuk

“The group under investigation has a toolkit that includes utilities such as Mimikatz, XenAllPasswordPro, PingCastle, Localtonet, resocks, AnyDesk, PsExec and others,” Kaspersky said. “As a final payload, the group used the well-known ransomware LockBit 3.0 and Babuk.”

As we mentioned earlier, the targets of the attacks are Russian government agencies, as well as businesses, such as mining, energy, and financial and retail companies.

See also: Cicada3301 Ransomware targets critical sectors in US and UK

Kaspersky said it was only able to detect the initial attack method in two cases. The Crypt Ghouls attackers used a contractor's login credentials to connect to internal systems via VPN.

The VPN connections are said to originate from IP addresses associated with a Russian hosting provider's network and a contractor's network, in order to avoid detection. The contractors' networks are believed to be compromised through services or unpatched security vulnerabilities.

After the initial access, the hackers Crypt Ghouls use the helper programs NSSM and Localtonet to maintain remote access. Subsequently, other tools are also used for further exploitation:

  • XenAllPasswordPro for collecting authentication data
  • The CobInt backdoor
  • Mimikatz to extract victims' credentials
  • dumper.ps1 for copying Kerberos tickets from the temporary LSA memory
  • MiniDump for extracting login credentials from the lsass.exe memory
  • cmd.exe for copying credentials that are stored in the Google Chrome and Microsoft Edge browsers
  • PingCastle for network discovery
  • PAExec for executing remote commands
  • AnyDesk and resocks SOCKS5 proxy for remote access

See also: BianLian ransomware group threatens to leak BCHP files

Crypt Ghouls attacks are completed by encrypting system data using publicly available versions of LockBit 3.0 for Windows and Babuk for Linux/ESXi. Data in the Recycle Bin is also encrypted to prevent recovery.

“The attackers leave a ransom note with a link containing their identity on the Session messaging service,” Kaspersky said.

Russian businesses
Crypt Ghouls targets Russian businesses with LockBit 3.0 and Babuk ransomware

Ransomware protection

Back up your data: One of the most effective ways to protect yourself from a  attack  is to regularly back up your data. This ensures that even if your data is encrypted by ransomware, you will have a safe copy that can be restored without paying the ransom.

Update your operating system and software: Out-of-date operating systems and software are vulnerable to cyberattacks. It is important to regularly update your devices with the latest  security  and software updates to prevent any vulnerabilities that could be exploited by ransomware.

Beware of suspicious emails and links: Ransomware attacks often start with a phishing email or malicious link. It is important to be cautious when opening emails from unknown senders. Also, do not click on suspicious links. These could lead to ransomware being installed on your device.

See also: RansomHub surpasses LockBit as the most prolific Ransomware group

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Use antivirus software:  Installing reputable antivirus software on your devices can help you detect and prevent attacks  . Be sure to update your antivirus software to ensure it is equipped to handle new threats.

Education: One of the most important steps to protect against ransomware is education. It is important to stay up to date on the latest types of ransomware and how they work. Organizations should also train their employees on how to identify and avoid potential attacks.

Implement strong passwords: Weak or easy passwords can make it easier for hackers to gain access to your devices and install ransomware. It's important to use strong and unique passwords and enable two-factor authentication whenever possible.

Use a VPN: A VPN encrypts your internet connection and provides an extra layer of security against ransomware attacks. This is especially important when using public Wi-Fi networks, which are often unsecured and vulnerable to attacks.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS