Casa > cibernético Notícias > Large-Scale Mamba Ransomware Attacks on the Rise Again
CYBER NEWS

Ataques Mamba ransomware em grande escala na ascensão outra vez

imagem caracterizada Mamba ransomware

O ransomware Mamba notório que paralisou a Agência Municipal de Transporte San Francisco volta 2016 ressurgiu. Desta vez, os criminosos por trás dos ataques de grande escala têm reorientado a sua atenção sobre corporações ao redor do mundo.

Mamba Ransomware Reactivated Once Again

One of the well-known viruses that has resurfaced in a new large-scale attack campaign is the infamous Mamba ransomware. Security experts noticed the incoming wave in a series of intrusion attempts against corporations worldwide. The shifted focus seems to be a new strategy devised by the criminals behind the campaign. It is not known if the current attack is backed by the same criminals as before or a new collective has emerged. The Mamba ransomware known primarily for its malware HDDCRyptor was able to cause devastating attacks San Francisco’s subway last year.

Story relacionado: SF Metro Atingido por Cryptom HDDCryptor ransomware - Passageiros andar de graça

The first major attacks associated with the threat happened in September 2016 when experts from Morphus Labs alerted that the virus samples were discovered on systems owned by a major energy company in Brazil that also has branches in the United States and India.

Mamba Ransomware Attacks Corporations Worldwide

The security experts reveal that the main victims of the attacks seem to be large corporations and company offices located in Brasil e Arábia Saudita. It is expected that the list may grow to other countries and regions as well.

Mamba ransomware follows the well-known attack vectors associated with prior versions. It uses a two-stage infection pattern that seeks to infiltrate the computer network first. Quando isso é feito, o psexec utility is used to execute the malware on the target hosts. The full analysis shows that the Mamba ransomware samples set up the environment on the system as defined by the hackers:

  1. o preparation stage creates a folder on the main system partition (C:) chamado “xamppand a subdirectory called “http”. This is a reference to the famous web hosting package used frequently by system administrators. Setting up a path like this may indicate a legitimate XAMPP installation with a web server. As the target hosts probably have services installed this would not raise suspicion.
  2. o DiskCryptor utility is then copied to the new folder and the specialized Windows driver is installed on the victim computer. A service is registered as a system service called DefragmentService. Once this is done the machine is rebooted and the Mamba ransomware service is initiated.
  3. Next the criptografia process is started. As the DiskCryptor service is started at boot service it is able to misconfigure the bootloader and affect all available system partitions.

During the infection phase the virus harvests detailed information about the host computer. Depending on the hardware components and software configuration a 32 or 64-bit version is chosen. The analysts discovered that the Mambo ransomware samples grant the DiskCryptor utility privileges for accessing all critical operating system components.

Once all steps have been made the bootloader is erased and the operating system is no longer accessible. The Mamba ransomware message is hardcoded into the overwritten loader itself. One of the captured samples reads the following note:

Your Data Encrypted, Contct For Key ( мсrypt2017@yandex.com OR citrix2234@protonмail.com) Sua identificação: 721, Tecla Enter:

The captured samples reveal that the users are using two email addresses: one of the hosted on Yandex and the other one on Protonmail. The images showcase that some of the letters are actually from the Cyrillic alphabet, combined with the fact that an inbox is hosted on Yandex, reveals the fact that the criminals may be Russian-speaking.

Story relacionado: TrickBot Banking Trojan Atualizado: WannaCry-Inspirado Módulo Agora Ativo

To find out more and effectively prevent infections read our complete removal guide.

Avatar

Martin Beltov

Martin formou-se na publicação da Universidade de Sofia. Como a segurança cibernética entusiasta ele gosta de escrever sobre as ameaças mais recentes e mecanismos de invasão.

mais Posts

Me siga:
Twitter

Deixe um comentário

seu endereço de e-mail não será publicado. Campos obrigatórios são marcados *

limite de tempo está esgotado. Recarregue CAPTCHA.

Compartilhar no Facebook Compartilhar
Carregando...
Compartilhar no Twitter chilrear
Carregando...
Compartilhar no Google Plus Compartilhar
Carregando...
Partilhar no Linkedin Compartilhar
Carregando...
Compartilhar no Digg Compartilhar
Compartilhar no Reddit Compartilhar
Carregando...
Partilhar no StumbleUpon Compartilhar
Carregando...