Cyclops Ransomware Gang Offers Go-Based Info Stealer to Cybercriminals

June 6, 2023Ravi LakshmananEndpoint Security/Data Security

Cyclops ransomware

Threat actors associated with Cyclops ransomware It has been observed offering information-stealing malware designed to retrieve sensitive data from infected hosts.

“Threat actors behind this [ransomware-as-a-service] In a new report, Uptycs said it “advertises its offerings on forums,” where it “demands a share of the profits from those who engage in malicious activity using its malware. ‘ said.

Cyclops ransomware is known to target all major desktop operating systems including Windows, macOS and Linux. It is also designed to terminate potential processes that could interfere with encryption.

The macOS and Linux versions of Cyclops ransomware are written in Golang. Additionally, this ransomware employs a complex encryption scheme that combines asymmetric and symmetric encryption.

cyber security

The Go-based stealer is designed to target Windows and Linux systems, capturing details such as operating system information, computer name, process count, and targeted files matching specific extensions.

The collected data consists of .TXT, .DOC, .XLS, .PDF, .JPEG, .JPG and .PNG files and is uploaded to a remote server. The stealer component can be accessed by the customer through the admin panel.

This development further evolved the cybercriminal ecosystem into a more deadly threat, with a new breed of information thieves called Dot Net Stealers that siphon information from web browsers, VPNs, installed apps and cryptocurrency wallets. It took place in SonicWall detailing the perpetrators.

“These capabilities could allow attackers to obtain valuable information from a victim’s system, leading to large-scale financial fraud that results in significant financial losses for the victim,” SonicWall said.

Did you enjoy this article? Follow us twitter You can read more exclusive content we post on LinkedIn.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *