A new custom backdoor, named Betruger, is being used in several recent ransomware attacks and has been linked to at least one affiliate of the RansomHub.

Symantec researchers have dubbed the malware Betruger. They describe it as a “ rare example of a multi-function backdoor ,” likely designed for use in ransomware attacks .
The backdoor includes several capabilities that are typically seen in malicious tools used before deploying ransomware payloads: keylogging, network scanning, privilege escalation, credential theft, taking screenshots, and uploading files to a command and control (C2) server.
See also: Lotus Panda targets governments with Sagerunex backdoor
" The functionality of the Betruger backdoor suggests that it may have been developed to minimize the number of new tools installed on a targeted network while preparing for a ransomware attack ," Symantec's Threat Hunter team said
"The use of custom malware instead of encrypting payloads is relatively uncommon in ransomware attacks. Most attackers rely on legitimate tools, living off the land, and publicly available malware such as Mimikatz and Cobalt Strike," the researchers added.
Attackers using the Betruger backdoor install it using the file names "mailer.exe" and "turbomailer.exe" to camouflage it as a legitimate application.
See also: Iranian hackers target UAE aviation sector with Golang backdoor
RansomHub ransomware
The RansomHub ransomware-as-a-service (RaaS) operation appeared in February 2024 and has been primarily associated with extortion and data theft rather than data encryption.
Since its emergence, the ransomware gang has claimed responsibility for numerous attacks: Halliburton, auction house Christie's, Frontier Communications, Rite Aid, Bologna Football Club, and many others.

Most recently, it was claimed to be behind the breach of BayMark Health Services, the largest addiction treatment provider in North America.
The FBI says RansomHub ransomware affiliates have compromised over 200 victims in critical US infrastructure, including government and healthcare.
See also: New Auto-Color Linux backdoor targets universities
Protection against backdoors and ransomware
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to your network
- Keep sensitive data encrypted
- Update all your devices and systems with the latest security patches
- Conduct regular security audits and penetration testing
- Use strong, unique passwords and change them regularly.
- Limit user access to only necessary systems and information
- Consider using solutions email security for additional protection against phishing attacks
- Have a recovery plan to quickly restore systems in the event of an attack
- Back up your data regularly
- Stay informed
Source: www.bleepingcomputer.com
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
