• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Experts Find Some Affiliates of BlackMatter Now Spreading BlackCat Ransomware

You are here: Home / General Cyber Security News / Experts Find Some Affiliates of BlackMatter Now Spreading BlackCat Ransomware
March 18, 2022

BlackMatter and BlackCat Ransomware

An evaluation of two ransomware attacks has discovered overlaps in the practices, tactics, and methods (TTPs) involving BlackCat and BlackMatter, indicating a robust link between the two groups.

Though it truly is regular of ransomware groups to rebrand their functions in reaction to improved visibility into their attacks, BlackCat (aka Alphv) marks a new frontier in that the cyber criminal offense cartel is constructed out of affiliates of other ransomware-as-a-service (RaaS) operations.

✔ Approved Seller From Our Partners
Malwarebytes Premium 2022

Protect yourself against all threads using Malwarebytes. Get Malwarebytes Premium with 60% discount from a Malwarebytes official seller SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


BlackCat very first emerged in November 2021 and has since targeted a number of organizations around the world above the previous few months. It has been referred to as out for being similar to BlackMatter, a limited-lived ransomware loved ones that originated from DarkSide, which attracted notoriety for its superior-profile attack on Colonial Pipeline in May 2021.

Automatic GitHub Backups

In an interview with Recorded Future’s The Record previous month, a BlackCat agent dismissed rumors that it’s a rebranding of BlackMatter, even though noting that it truly is created up of affiliates related with other RaaS teams.

“In part, we are all related to gandrevil [GandCrab / REvil], blackside [BlackMatter / DarkSide], mazegreggor [Maze / Egregor], lockbit, and so forth., since we are adverts (aka affiliates),” the unnamed consultant was quoted as indicating. “We borrowed their advantages and eliminated their shortcomings.”

Prevent Data Breaches

“BlackCat appears to be to be a circumstance of vertical enterprise expansion,” Cisco Talos scientists Tiago Pereira and Caitlin Huey stated. “In essence, it is really a way to manage the upstream provide chain by producing a service that is important to their enterprise (the RaaS operator) superior suited for their demands and introducing a different source of income.”

What is a lot more, the cybersecurity company said it noticed a variety of commonalities involving a BlackMatter attack in September 2021 and that of a BlackCat attack from December 2021, including the applications and the file names utilized as perfectly as a area employed to preserve persistent accessibility to the goal network.

This overlapping use of the same command-and-management tackle has elevated the likelihood that the affiliate that applied BlackMatter was possible one particular of the early adopters of BlackCat, with each the attacks having much more than 15 times to arrive at the encryption stage.

“As we have observed a number of periods in advance of, RaaS services come and go. Their affiliate marketers, even so, are most likely to just move on to a new support. And with them, a lot of of the TTPs are very likely to persist,” the scientists reported.

The conclusions occur as BlackBerry detailed a new .NET-primarily based ransomware spouse and children termed LokiLocker that not only encrypts the information but also incorporates an optional wiper operation which is made to erase all non-program files and overwrite the master boot history (MBR) ought to a victim refuse to fork out up inside a specified timeframe.

“LokiLocker will work as a limited-accessibility ransomware-as-a-support scheme that appears to be offered to a fairly small quantity of meticulously vetted affiliates guiding shut doorways,” the researchers said. Active due to the fact at the very least August 2021, a bulk of victims detected so considerably are concentrated in Eastern Europe and Asia.

Uncovered this report intriguing? Observe THN on Facebook, Twitter  and LinkedIn to browse additional special information we put up.


Some parts of this posting are sourced from:
thehackernews.com

Previous Post: «it pro news in review: job losses at arm, warnings IT Pro News In Review: Job losses at Arm, warnings over Kaspersky software, Microsoft using ads

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Experts Find Some Affiliates of BlackMatter Now Spreading BlackCat Ransomware
  • IT Pro News In Review: Job losses at Arm, warnings over Kaspersky software, Microsoft using ads
  • Google exposes ‘uniquely personal’ access broker behind worst Conti, FIN12 ransomware attacks
  • NCSC Launches Awareness Campaign to Strengthen Password Practices
  • Cyclops Blink Malware Expands to Target Asus
  • Aircraft Disrupted by Satellite Jamming Following Russian Invasion
  • Cloud-Based Email Threats Surge 50% in 2021
  • Google Uncovers ‘Initial Access Broker’ Working with Conti Ransomware Gang
  • New Variant of Russian Cyclops Blink Botnet Targeting ASUS Routers
  • Dev Sabotages Popular NPM Package to Protest Russian Invasion

Copyright © TheCyberSecurity.News, All Rights Reserved.