Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Maze attackers adopt Ragnar Locker virtual machine technique
#1
Quote:[Image: of04ADz.png]

While conducting an investigation into an attack in July in which the attackers repeatedly attempted to infect computers with Maze ransomware, analysts with Sophos’ Managed Threat Response (MTR) discovered that the attackers had adopted a technique pioneered by the threat actors behind Ragnar Locker earlier this year, in which the ransomware payload was distributed inside of a virtual machine (VM).

In the Maze incident, the threat actors distributed the file-encrypting payload of the ransomware on the VM’s virtual hard drive (a VirtualBox virtual disk image (.vdi) file), which was delivered inside of a Windows .msi installer file more than 700MB in size. The attackers also bundled a stripped down, 11 year old copy of the VirtualBox hypervisor inside the .msi file, which runs the VM as a “headless” device, with no user-facing interface.

[Image: B0j9gB8.png]

The Maze-delivered virtual machine was running Windows 7, as opposed to the Windows XP VM distributed in the Ragnar Locker incident. A threat hunt through telemetry data initially indicated the attackers may have been present on the attack target’s network for at least three days prior to the attack beginning in earnest, but subsequent analysis revealed that the attackers had penetrated the network at least six days prior to delivering the ransomware payload.

The investigation also turned up several installer scripts that revealed the attackers’ tactics, and found that the attackers had spent days preparing to launch the ransomware by building lists of IP addresses inside the target’s network, using one of the target’s domain controller servers, and exfiltrating data to cloud storage provider Mega.nz.

The threat actors initially demanded a $15 million ransom from the target of the attack. The target did not pay the ransom.

Continue reading HERE
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Update Babuk Locker is the first new enterprise ransomware of 2021 tarekma7 0 981 01-06-2021 , 07:50 AM
Last Post: tarekma7
  Techniques: Current Use of Virtual Machine Detection Methods sidemoon 0 1,371 05-08-2020 , 09:21 PM
Last Post: sidemoon
  Update Maze Ransomware Was Discovered.. guardian 0 1,394 05-01-2020 , 03:59 AM
Last Post: guardian

Forum Jump:


Users browsing this thread: 1 Guest(s)