
Threat actors behind the early stages buhti Ransomware evaded custom payloads in favor of the leaked LockBit and Babuk ransomware families to attack Windows and Linux systems.
“The group does not develop its own ransomware, but utilizes what appears to be a custom-developed tool, an information-stealing tool designed to search for and archive specific file types,” Symantec said. said in a report shared with HackerNews.
Cybersecurity firms track cybercriminal groups under the following names: black tail. Buhti was first brought to the attention of Palo Alto Networks Unit 42 in February 2023. Description This is Golang ransomware targeting the Linux platform.
Later that month, Bitdefender revealed the use of a Windows variant deployed against the Zoho ManageEngine product vulnerable to a critical remote code execution flaw (CVE-2022-47966).
Operators then quickly exploited other critical bugs affecting IBM’s Aspera Faspex file exchange application (CVE-2022-47986) and PaperCut (CVE-2023-27350) to drop ransomware. It has been observed that there are
Recent findings from Symantec indicate that Blacktail’s modus operandi may be changing, with the attackers leveraging modified versions of the leaked LockBit 3.0 and Babuk ransomware source code to compromise Windows, respectively. and Linux.
Both Babuk and LockBit released their ransomware source code online in September 2021 and September 2022, spawning multiple copycats.
One notable cybercriminal group already using the LockBit ransomware builder is the Bl00dy ransomware gang. The group was recently brought to the attention of a US government agency for exploiting vulnerable PaperCut servers in an attack against the domestic education sector.
Despite the rebranding change, Blacktail utilizes a custom data extraction utility written in Go designed to steal files with specific extensions in the form of ZIP archives before encrypting them. is observed.
“Although reuse of leaked payloads is often a hallmark of low-skilled ransomware operations, we recognize Blacktail’s overall ability to execute attacks and the usefulness of newly discovered vulnerabilities. Capabilities suggest that it should not be underestimated,” Symantec said.
Ransomware continues to pose a persistent threat to businesses. Fortinet FortiGuard Labs earlier this month detailed a Go-based ransomware family called Maori that was specifically designed to run on Linux systems.
Zero Trust + Deception: Learn How to Outsmart Attackers!
See how Deception can detect advanced threats, stop lateral movement, and strengthen your Zero Trust strategy. Join us for an insightful webinar!
Reserve your seat!
The use of Go and Rust shows that some attackers are interested in developing “adaptive” cross-platform ransomware and maximizing their attack surface, but at the same time new techniques are emerging. It is also a sign of a cybercrime ecosystem that continues to adopt and evolve. .
In its 2023 Ransomware Trends report, Kaspersky said, “Major ransomware criminal organizations are borrowing functionality from leaked or purchased code from other cybercriminals, thereby increasing the functionality of their own malware. could improve,” he said.
In fact, according to Cyble, a new ransomware family called Obsidian ORB is a departure from Chaos, which is also the basis for other ransomware strains such as BlackSnake and Onyx.
What makes this ransomware stand out is that it employs a rather unique ransom payment method, requiring victims to pay the ransom via gift cards instead of cryptocurrency payments.
“This approach is effective and convenient for attackers (TAs) because they can modify and customize the code to their liking,” said the cybersecurity firm.