Ausnahme gefangen: SSL certificate problem: certificate is not yet valid 📌 Meet Rorschach: The Fastest Ransomware Strain Yet Discovered

🏠 Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeiträge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden Überblick über die wichtigsten Aspekte der IT-Sicherheit in einer sich ständig verändernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch übersetzen, erst Englisch auswählen dann wieder Deutsch!

Google Android Playstore Download Button für Team IT Security



📚 Meet Rorschach: The Fastest Ransomware Strain Yet Discovered


💡 Newskategorie: Hacking
🔗 Quelle: blackhatethicalhacking.com

Meet Rorschach: The Fastest Ransomware Strain Yet Discovered

Premium Content

Patreon
Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes

Check Point researchers have identified a new ransomware strain, which they have named Rorschach, that they say comes with technically unique features. The malware was discovered following a cyberattack on a US-based company, and researchers found that Rorschach would be the fastest ransomware threat on the market based on their tests.

Rorschach details

Rorschach’s encryption process, which includes the curve25519 and eSTREAM cipher hc-128 algorithms, is intermittent, meaning that it encrypts files only partially, leading to increased processing speed. In addition, the ransomware’s encryption routine indicates “a highly effective implementation of thread scheduling via I/O completion ports.”

Rorschach was deployed on the victim network using the DLL side-loading technique via a signed component in Cortex XDR, the extended detection and response product from Palo Alto Networks. The malware then used the Cortex XDR Dump Service Tool to sideload the Rorschach loader and injector. The loader file features UPX-style anti-analysis protection, while the main payload is protected against reverse engineering and detection by virtualizing parts of the code using VMProtect software.

Attack chainAttack chain (Check Point)

See Also: So you want to be a hacker?
Offensive Security, Bug Bounty Courses

Rorschach’s Advanced Propagation and Record-Wiping Abilities Revealed

Check Point reports that Rorschach creates a Group Policy when executed on a Windows Domain Controller to propagate to other hosts on the domain. After compromising a machine, the malware erases four event logs to wipe its trace. While it comes with hardcoded configuration, Rorschach supports command-line arguments that expand functionality. The options are hidden and can’t be accessed without reverse engineering the malware.

 

Arguments decoded by Check PointArguments decoded by Check Point

Rorschach’s encryption process

During testing, Check Point set up a test with 220,000 files on a 6-core CPU machine and found that it took Rorschach 4.5 minutes to encrypt the data, whereas LockBit v3.0, considered the fastest ransomware strain, finished in 7 minutes.

Rorschach encryption schemeRorschach encryption scheme (Check Point)

After locking the system, Rorschach drops a ransom note similar to the format used by the Yanlowang ransomware. According to the researchers, a previous version of malware used a ransom note similar to what DarkSide used. Check Point assesses that Rorschach has implemented the better features from some of the leading ransomware strains leaked online, including Babuk, LockBit v2.0, and DarkSide. The malware “raises the bar for ransom attacks” and comes with self-propagating capabilities.

Latest ransom note dropped by RorschachLatest ransom note dropped by Rorschach (Check Point)

At present, the operators of the Rorschach ransomware remain unknown, and there is no branding, something that is rarely seen in the ransomware scene.

Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com

Source: bleepingcomputer.com

Source Link

Merch

Offensive Security & Ethical Hacking Course

Begin the learning curve of hacking now!


Information Security Solutions

Find out how Pentesting Services can help you.

The post Meet Rorschach: The Fastest Ransomware Strain Yet Discovered first appeared on Black Hat Ethical Hacking. ...



📌 Meet Rorschach: The Fastest Ransomware Strain Yet Discovered


📈 92.23 Punkte

📌 Rorschach – Fastest Encryption Ransomware Ever Found in Ransomware History


📈 47.38 Punkte

📌 Rorschach Ransomware: Fastest encryption and most dangerous ransomware of the history


📈 47.38 Punkte

📌 New Rorschach ransomware is the fastest encryptor seen so far


📈 42.92 Punkte

📌 Rorschach ransomware has the fastest file-encrypting routine to date


📈 42.92 Punkte

📌 New Threat Uncovered: Rorschach Ransomware – The Fastest Encryptor


📈 42.92 Punkte

📌 Google Meet Meets Duo Meet, With Meet in Duo But Duo Isn't Going Into Meet


📈 36.64 Punkte

📌 New Strain of Ransomware Discovered


📈 33.91 Punkte

📌 Meet Rhysida, a New Ransomware Strain That Deletes Itself


📈 32.13 Punkte

📌 New Strain of ATM Jackpotting Malware Discovered


📈 29.45 Punkte

📌 Third malware strain discovered in SolarWinds supply chain attack


📈 29.45 Punkte

📌 ATMJackpot, a new strain of ATM Malware discovered by experts


📈 29.45 Punkte

📌 Fourth malware strain discovered in SolarWinds incident


📈 29.45 Punkte

📌 Self-Propagating, Fast-Encrypting ‘Rorschach’ Ransomware Emerges


📈 29.32 Punkte

📌 Rorschach Ransomware Emerges: Experts Warn of Advanced Evasion Strategies


📈 29.32 Punkte

📌 New "Rorschach" Ransomware Spread Via Commercial Product


📈 29.32 Punkte

📌 Mysterious 'Rorschach' Ransomware Doubles Known Encryption Speeds


📈 29.32 Punkte

📌 An Analysis of the BabLock (aka Rorschach) Ransomware


📈 29.32 Punkte

📌 New Rorschach ransomware hits with unique features and very fast encryption


📈 29.32 Punkte

📌 Rorschach ransomware deployed by misusing a security tool


📈 29.32 Punkte

📌 Chilean telecom giant GTD hit by the Rorschach ransomware gang


📈 29.32 Punkte

📌 Meet HiddenWasp, The New Malware Strain Targeting Linux Systems


📈 27.66 Punkte

📌 Meet the Great Duke of... DLL: Microsoft shines light on Astaroth, a devilishly sneaky strain of fileless malware


📈 27.66 Punkte

📌 Free decrypter released for STOP ransomware, today's most popular ransomware strain


📈 27.43 Punkte

📌 Experts warn of a new strain of ransomware, the PXJ Ransomware


📈 27.43 Punkte

📌 The fastest rm command and one of the fastest cp commands


📈 27.19 Punkte

📌 Microsoft: We Have the Fastest Pen; Apple: No, We Have the Fastest Pen


📈 27.19 Punkte

📌 Rorschach: Eine der schnellsten Ransomwares aller Zeiten


📈 24.86 Punkte

📌 Unraveling Rorschach


📈 24.86 Punkte

📌 Rorschach, QNAP, We Got Hacked, SystemD, UTF-8, & Grub2 Music - PSW #779


📈 24.86 Punkte

📌 Astronomers Discovered the Fastest-Growing Black Hole Ever Seen


📈 24.54 Punkte

📌 'Butterfly bot' is fastest swimming soft robot yet


📈 24.31 Punkte











matomo