Diavol ransomware linked to Trickbot botnet – IT PRO

Security researchers have made a connection between a new strain of ransomware and the cyber criminal gangbehind the Trickbot botnet.

Fortinet discovered the ransomware after it was blocked by the companys FortiEDR product on a customers system. Two files were isolated that were not found on VirusTotal:locker.exeandlocker64.dll. the two bits of malware were deployed a day apart.

While locker64.dll appeared to be a Conti (v3) ransomware, locker.exe was entirely different. The second ransomware was dubbed Diavol by researchers.

Researchers said that as part of a rather unique encryption procedure, Diavol operates using user-mode Asynchronous Procedure Calls (APCs) without a symmetric encryption algorithm.

Usually, ransomware authors aim to complete the encryption operation in the shortest amount of time. Asymmetric encryption algorithms are not the obvious choice as they are significantly slower than symmetric algorithms, said researchers.

The researchers said that asDiavol was deployed in conjunction with the Conti ransomware in this attack, albeit on different machines,they tried to see if there was any correlation between them. They found that command-line parameters used by Diavol are nearly identical to those of Conti and used for the same functionality: log file, encrypt local drives or network shares, and scan specific hosts for network shares.

In addition, Diavol and Conti both operate similarly with asynchronous I/O operations when queuing the file paths for encryption, said researchers.

The researchers said there might also be a link between Diavol and Egregor ransomware. Some lines in the ransom note are identical, they said. Although this is not reliable as it could simply be a red herring that Diavols authors planted.

Some have reported a link between Wizard Spider, the threat actor behind Conti, and Twisted Spider, the threat actor behind Egregor. Allegedly, these gangs cooperate on various operations. They are also both notoriously known for double ransoming their victims (data theft and encryption), researchers added.

Researchers said the source of the intrusion is unknown. The parameters used by the attackers, along with the errors in the hardcoded configuration, hint to the fact that Diavol is a new tool in the arsenal of its operators which they are not yet fully accustomed to.

As the attack progressed, we found more Conti payloads namedlocker.exein the network, strengthening the possibility the threat actor is indeed Wizard Spider. Despite a few similarities between Diavol, Conti, and other related ransomware, its still unclear, however, whether theres a direct link between them, the researchers added.

Spotlight: The state of the UK & Ireland mid-sized business and IT today 2021

The UK and Irelands mid market firms faced a difficult 2020 but have a strong platform for recovery

The secure cloud configuration imperative

The central role of cloud security posture management

Empowering the dynamic worker

How CIOs and IT teams can support a distributed workforce

A new trust model for the 5G era

Data-in-motion security through a 5G infrastructure

More:
Diavol ransomware linked to Trickbot botnet - IT PRO

Related Posts

Comments are closed.