pwshub.com

New Morphisec report finds links between emerging Cicada3301 ransomware and BlackCat

A new report out today from endpoint security firm Morphisec Inc. details a recently discovered form of ransomware that may have links to the infamous BlackCat ransomware family.

Called Cicada3301, the new threat was identified in a Morphisec customer environment recently and was first reported around two months ago. Written in the Rust programming language and named after the Cicada puzzle, a complex, cyber-related problem-solving puzzle, who exactly is behind Cicada3301 remains, in the words of Morphisec’s researchers, “shrouded in mystery.”

The report does a deep dive into the technical details of the ransomware, including the executables used in its deployment. Additional tools being used by those behind the ransomware campaign were also uncovered, such as EDRSandBlast, which is used to tamper with endpoint detection and response tools. Cicada3301 was also found to primarily target small to medium-sized businesses through opportunistic attacks that exploit vulnerabilities as the initial access vector.

Ransomware is a dime a dozen, but considering where Cicada3301 comes from assists in understanding those behind it and how to protect against it. The main takeaway is that the ransomware shares several core characteristics with BlackCat.

BlackCat ransomware, also known as ALPHV, first emerged in late 2021 and quickly gained prominence for being its versatile ransomware strain. Written in the Rust programming language, like Cicada3301, BlackCat became infamous for its ability to evade traditional security measures by employing advanced techniques such as self-propagation, data exfiltration and multithreaded encryption processes. Notable BlackCat attacks include those against Seiko Group Corp., Reddit Inc. and MGM Resorts International Inc.

Cicada3301 was found to feature a well-defined configuration interface and registers as a vector exception handler — as BlackCat does — along with employing similar methods for shadow copy deletion and tampering. However, there are some key differences: Cicada3301 shows significant innovations, such as how it executes and integrates compromised credentials.

The report emphasizes the critical need for organizations to stay vigilant and proactive in their cybersecurity efforts, particularly as threats like Cicada3301 continue to evolve.

The ransomware’s approach, particularly in its integration of compromised credentials and use of advanced tools, is said to signal a new level of sophistication that echoes the tactics of BlackCat but pushes them further. As Morphisec’s researchers note, Cicada3301 is not just a reiteration of past threats but a clear indication that ransomware developers are constantly refining their methods to bypass existing defenses. Businesses, particularly small to medium-sized ones, must bolster their security measures and remain agile in responding to emerging threats such as Cicada3301.

Source: siliconangle.com

Related stories
1 week ago - A new report out today from Palo Alto Networks Inc.’s Unit 42 details a new ransomware-as-a-service group with a multi-extortion operation that’s actively recruiting new affiliates. Called “Repellent Scorpius,” the RaaS group first...
2 weeks ago - Investors have had to contend with a lot of ups and downs in the economy over the last few years. Even though a bull market is now well underway,...
2 weeks ago - A new chip manufacturing process from Intel Corp. failed to meet Broadcom Inc.’s expectations in a recent evaluation, Reuters reported today. The development may mark a setback for Intel’s foundry business. The unit uses the company’s...
1 week ago - On only his second day on the job, the former Chipotle CEO singled he will initially devote the bulk of his attention to problems in the U.S. operations.
1 week ago - Annual inflation cooled to its lowest level in three years, but the stock market still isn't happy.
Other stories
33 minutes ago - Shares of Truth Social’s parent company fell Thursday, extending the latest round of declines for Trump Media & Technology Group.
1 hour ago - European Union officials are taking new steps to ensure that Apple Inc. complies with the bloc’s DMA tech industry regulation. The European Commission, the EU’s executive arm, announced the initiative today. The DMA is a piece of...
1 hour ago - Shares in automotive chip maker Mobileye Global Inc. jumped nearly 15% today after its majority shareholder, Intel Corp., said that it has no plans to divest its interest in the company. Reports earlier this month suggested that Intel...
1 hour ago - Cybersecurity risk management is becoming more critical than ever as industries adapt to an increasingly digital landscape. The rapid growth of artificial intelligence, combined with complex cyber threats, is pushing companies to rethink...
1 hour ago - Nike named a new CEO as Wall Street has questioned the company's plan to reinvigorate sales growth.