Target Industry

RansomHub targets IT, government services and facilities, healthcare, emergency services, food and agriculture, financial services, commercial properties, critical manufacturing, transportation, and communications infrastructure

Overview

Cyber threat researchers at Symantec have discovered that a RansomHub affiliate is using a new malware tool to enhance its ransomware attacks. Betruger is a custom backdoor designed specifically for ransomware, featuring keylogging, network scanning, privilege escalation, credential dumping, screenshotting, and file uploads to a command and control (C2) server. 

Impact

The Betruger backdoor malware significantly enhances ransomware attacks by consolidating multiple functions into a single tool, making detection and mitigation more challenging. It disguises itself as legitimate applications, allowing threat actors to gather extensive information through keylogging, network scanning, and credential dumping. The potential damage is increased as Betruger can gain higher-level access within networks using privilege escalation capabilities. The sophisticated tool used by RansomHub affiliates highlights the growing threat of custom malware in ransomware attacks, underscoring the need for robust cyber security measures.  

Exploitation

RansomHub affiliates utilise a variety of tools, including the Betruger backdoor malware, to carry out their attacks. The following tools have been observed in use by RansomHub: 

 

  • Atera: an all-in-one IT management platform that leverages AI for remote monitoring, management, and helpdesk services  
  • Impacket: an open-source collection of Python modules for constructing and manipulating network protocols, often used for tasks like remote service execution, credential dumping, and packet sniffing 
  • Mimikatz: a tool for extracting passwords and other authentication data from memory on Windows systems 
  • NetScan: a lightweight software tool for scanning network IPs and ports 
  • Rclone: a command-line tool for managing and synchronising files across various cloud storage services 
  • ScreenConnect: a remote support and access tool that allows technicians to connect to and control devices remotely 
  • Splashtop: a remote access and support tool that allows threat actors to connect to and control computers 
  • Stowaway Proxy Tool: a multi-hop proxy tool designed for security researchers and pentesters to route traffic through multiple nodes 
  • SystemBC: creates a proxy on infected systems to facilitate remote access and control by threat actors 
  • TightVNC: a free, cross-platform remote desktop software that allows users to control computers remotely.  

Containment, Mitigations & Remediation

For mitigation please refer to Custom Betruger backdoor deployed by RansomHub affiliate 

Indicators of Compromise

For Indicators of Compromise please refer to RansomHub: Attackers Leverage New Custom Backdoor | Symantec Enterprise Blogs 

Threat Group

RansomHub is a ransomware group that emerged in February 2024 and quickly became a major player in the ransomware landscape. It operates in a decentralized manner, often using the dark web for communication, making it difficult to pinpoint its location. Some experts believe RansomHub may be a rebrand of the Knight ransomware gang due to similarities in their malware code. Since its inception, RansomHub has targeted over 210 organisations. 

Knight, which evolved from Cyclops in August 2023, was a Ransomware-as-a-Service (RaaS) provider using double extortion tactics. It targeted sectors like healthcare and retail, using phishing and malware such as Remcos and Qakbot. Cyclops, emerging in mid-2023, also operated as a RaaS provider and developed ransomware for all major operating systems, along with an information stealer targeting sensitive data. 

Tactics, Techniques and Procedures

  • T1003: OS Credential Dumping  
  • T1018: Remote System Discovery 
  • T1521: Encrypted Channel 
  • T1567.002: Exfiltration Over Web Service: Exfiltration to Cloud Storage 
  • T1486: Data Encrypted for Impact 

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content