The U.S. Federal Bureau of Investigation (FBI) is sounding the alarm on the BlackCat ransomware-as-a-service (RaaS), which it said victimized at least 60 entities worldwide between March 2022 since its emergence last November.
Also called ALPHV and Noberus, the ransomware is notable for being the first-ever malware written in the Rust programming language that’s known to be memory safe and offer improved performance.
“Many of the developers and money launderers for BlackCat/ALPHV are linked to DarkSide/BlackMatter, indicating they have extensive networks and experience with ransomware operations,” the FBI said in an advisory published last week.
The disclosure comes weeks after twin reports from Cisco Talos and Kasperksy uncovered links between BlackCat and BlackMatter ransomware families, including the use of a modified version of a data exfiltration tool dubbed Fender that’s been previously only observed in BlackMatter-related activity.
“Aside from the developing advantages Rust offers, the attackers also take advantage of a lower detection ratio from static analysis tools, which aren’t usually adapted to all programming languages,” AT&T Alien Labs pointed out earlier this year.
Like other RaaS groups, BlackCat’s modus operandi involves the theft of victim data prior to the execution of the ransomware, with the malware often leveraging compromised user credentials to gain initial access to the target system.
In a BlackCat ransomware incident analyzed by Forescout’s Vedere Labs, an internet-exposed SonicWall firewall was penetrated to gain initial access to the network, before moving to and encrypting a VMware ESXi virtual farm. The ransomware deployment is said to have taken place on March 17, 2022.
The law enforcement agency, besides recommending victims to promptly report ransomware incidents, also said it doesn’t encourage paying ransoms as there is no guarantee that this will enable the recovery of encrypted files. But it did acknowledge that victims may be compelled to heed such demands to protect shareholders, employees, and customers. Read more: https://bit.ly/3vcZDrR
You can also read this: FBI Investigating More than 100 Ransomware Variants