Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

The new visa rule in the US requires from applicants to set privacy in social media for the public

June 24, 2025

Hackers focus on over 70 Microsoft Exchange servers to steal credentials via Keyloggers

June 24, 2025

Researchers find a way to close Cryptominer companies using bad stocks and Xmrogue

June 24, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » The new Rust-based Cicada3301 ransomware targets Windows and Linux systems
Global Security

The new Rust-based Cicada3301 ransomware targets Windows and Linux systems

AdminBy AdminSeptember 3, 2024No Comments3 Mins Read
Rust-Based Ransomware
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


September 3, 2024Ravi LakshmananEndpoint Security / Malware

Rust-based ransomware

Cybersecurity researchers have unpacked the inner workings of a new ransomware variant called Cicada3301 that bears similarities to the now-defunct Black Cat (aka ALPHV) operation.

“The Cicada3301 ransomware appears to primarily target small and medium-sized businesses (SMBs), likely through opportunistic attacks that use vulnerabilities as an initial access vector,” cybersecurity firm Morphisec said. said in a technical report shared with The Hacker News.

Written in Rust and able to target both Windows and Linux/ESXi hosts, Cicada3301 first appeared in June 2024 inviting potential partners to join their ransomware-as-a-service (RaaS) platform through an advertisement on the underground RAMP forum.

A distinctive aspect of ransomware is that the compromised user’s credentials are embedded in the executable, which is then used to launch PsExeca legitimate tool that allows you to run programs remotely.

Cyber ​​security

Cicada3301’s similarity to BlackCat also extends to the use of ChaCha20 for encryption, on fsut to evaluate symbolic links and encrypt redirected files, and IISReset.exe to stop IIS services and encrypt files that might otherwise be locked for modification or deletion.

Other coincidences with BlackCat include steps taken to remove shadow copies, disable System Restore by manipulating bcdedit usefulness, increase art MaxMpxCt value to support large amounts of traffic (such as SMB PsExec requests) and clear all event logs with the webutil utility.

Cicada3301 also noticed the termination of locally deployed virtual machines (VMs), a behavior that previously Megazord ransomware and Yanluowan ransomware, as well as stopping various backup and recovery services and a hard-coded list of dozens of processes.

Besides maintaining a built-in list of excluded files and directories during the encryption process, the ransomware targets 35 file extensions – sql, doc, rtf, xls, jpg, jpeg, psd, docm, xlsm, ods, ppsx, png , raw, dotx, xltx , pptx, ppsm, gif, bmp, dotm, xltm, pptm, odp, webp, pdf, odt, xlsb, ptox, mdf, tiff, docx, xlsx, xlam, potm and txt.

Morphisec said its research also revealed additional tools such as EDRSandBlast that use a vulnerable signed driver to bypass EDR detection, a technique also adopted BlackByte ransomware group in the past.

Cyber ​​security

The findings come from a Truesec analysis of Cicada3301’s version of ESXi, and also reveal signs that the group may have colluded with carriers Brutus botnet gain initial access to corporate networks.

“Whether Cicada3301 is a rebrand of ALPHV, they have ransomware written by the same developer as ALPHV, or they simply copied parts of ALPHV to create their own ransomware, the graph points to the demise of BlackCat and the appearances of the first Brutus botnet and then the Cicada3301 ransomware operation may be linked,” the company said in a statement. noted.

Attacks against VMware ESXi systems also involve the use of batch encryption to encrypt files larger than a specified threshold (100MB) and a parameter called “no_vm_ss” to encrypt files without powering down virtual machines running on the host.

The emergence of Cicada3301 also spawned an eponymous “non-political movement” that dealt with the “mysterious” cryptographic puzzlesissue a statement that he is not connected to the extortion scheme.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

The new visa rule in the US requires from applicants to set privacy in social media for the public

June 24, 2025

Hackers focus on over 70 Microsoft Exchange servers to steal credentials via Keyloggers

June 24, 2025

Researchers find a way to close Cryptominer companies using bad stocks and Xmrogue

June 24, 2025

APT28 uses signal chat to expand malicious Beardhell ​​and Testament software in Ukraine

June 24, 2025

Talk CTEM we all need

June 24, 2025

Hackers operate incorrectly configured API Docker to hand over cryptocurrency via Tor Network

June 24, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

The new visa rule in the US requires from applicants to set privacy in social media for the public

June 24, 2025

Hackers focus on over 70 Microsoft Exchange servers to steal credentials via Keyloggers

June 24, 2025

Researchers find a way to close Cryptominer companies using bad stocks and Xmrogue

June 24, 2025

APT28 uses signal chat to expand malicious Beardhell ​​and Testament software in Ukraine

June 24, 2025

Talk CTEM we all need

June 24, 2025

Hackers operate incorrectly configured API Docker to hand over cryptocurrency via Tor Network

June 24, 2025

US House forbids WhatsApp on official security and protection devices

June 24, 2025

Salt Typhoon associated with China

June 24, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

The new visa rule in the US requires from applicants to set privacy in social media for the public

June 24, 2025

Hackers focus on over 70 Microsoft Exchange servers to steal credentials via Keyloggers

June 24, 2025

Researchers find a way to close Cryptominer companies using bad stocks and Xmrogue

June 24, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.