Ransomware

FIN8 hackers linked to new ‘White Rabbit’ ransomware

0

A new ransomware strain called ‘White Rabbit’ has recently appeared in the wild and according to research findings, this could be a side-operation of the financially motivated FIN8 hacking group.

According to Trend Micro, the malware’s overlaps with Egregor, which was taken down by Ukrainian law enforcement authorities in February 2021.

The researchers noted that one of the most notable aspects of White Rabbit’s attack is how its payload binary requires a specific command-line password to decrypt its internal configuration and proceed with its ransomware routine. This method of hiding malicious activity is a trick that the ransomware family Egregor uses to hide malware techniques from analysis.

Egregor is believed to be a reincarnation of Maze, which has already shut down its criminal enterprise.

White Rabbit adheres to the double extortion scheme and is believed to have been delivered via Cobalt Strike, a post-exploitation framework used by threat actors to reconnoiter, infiltrate, and drop malicious payloads into the affected system.

Double extortion refers to an increasingly popular ransomware strategy in which valuable data from the targets is exfiltrated prior to launching the encryption routine, followed by pressurizing the victims into paying up to prevent the stolen information from being published online.

The ransom note displayed after the completion of the encryption process warns the victim that their data will be published or sold once the four-day deadline to meet their demands elapses.

The analysis of the ransomware samples dates back to August 2021 and shows that the malware is an updated version of the Sardonic backdoor.

Cybersecurity company Lodestone stated that the exact relationship between the White Rabbit group and FIN8 is currently unknown. It found a number of TTPs suggesting that White Rabbit, if operating independently of FIN8, has a close relationship with the more established threat group or is mimicking them.

So far, White Rabbit’s targets have been few, but it is considered as an emerging threat that could turn into a severe menace to companies in the future.

Image Credits : Wired

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Europol shuts down cybercriminal’s favorite VPN service

Previous article

Interpol busted 11 members of Nigerian BEC cybercrime gang

Next article

You may also like

More in Ransomware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *