FBI says Ragnar ransomware gang hit 52 critical US orgs
(2022/03/09)
- Reference: 1646791541
- News link: https://www.theregister.co.uk/2022/03/09/fbi_says_ragnar_locker_ransomware/
- Source link:
The Ragnar Locker ransomware gang has so far infected or compromised at least 52 critical infrastructure organizations in America across sectors including manufacturing, energy, financial services, government, and information technology, according to an FBI alert this week.
The Feds [1]said [PDF] they became aware of the ransomware crew in early 2020 and the miscreants' preferred tactic: double extortion. The crooks steal sensitive data, encrypt a victim's systems, and threatens to leak the stolen documents if the ransom to restore the files isn't paid.
To date, the Ragnar Locker criminals have [2]posted stolen data from at least ten organizations on their publicity website, according to Acronis. In its latest cyber-crime spree, the gang hit entities across nearly a dozen critical sectors as of January, according to the FBI flash alert, which also provides technical details about how the ransomware attacks work:
RagnarLocker is identified by the extension ".RGNR_<ID>," where <ID> is a hash of the computer's NETBIOS name. The actors, identifying themselves as "RAGNAR_LOCKER," leave a .txt ransom note, with instructions on how to pay the ransom and decrypt the data. RagnarLocker uses VMProtect, UPX, and custom packing algorithms and deploys within an attacker's custom Windows XP virtual machine on a target's site.
The Ragnar Locker malware uses Windows API GetLocaleInfoW to identify the infected machine's location. If the victim's locale is one of a dozen European and Asian countries, including Russia, Ukraine, and other states, the infection process terminates.
As the ransomware is deployed, it kills services commonly used by managed service providers to remotely control networks and attempts to silently delete all shadow copies of documents so that users can't recover encrypted files.
[3]
And finally, Ragnar Locker encrypts organizations' data. But instead of choosing which files to encrypt, it selects folders not to encrypt. "Taking this approach allows the computer to continue to operate 'normally' while the malware encrypts files with known and unknown extensions containing data of value to the victim," the FBI explained.
[4]Lapsus$ extortionists dump Samsung data online, chaebol confirms security breach
[5]Conti ransomware gang's source code leaked
[6]Second data-wiping malware found in Ukraine, says ESET
[7]Insurance giant Aon confirms it has suffered 'cyber incident'
For example, if the logical drive being processed is the C: drive, the malware does not encrypt files in folders names Windows, Windows.old, Mozilla, Mozilla Firefox, Tor browser, Internet Explorer, $Recycle.Bin, Program Data, Google, Opera, or Opera Software.
The FBI urged victims to report ransomware attacks to their local field office. And while it "does not encourage paying a ransom to criminal actors," it acknowledged that this can be a tricky business decision. Executives should "evaluate all options to protect their shareholders, employees, and customers," before deciding whether to pay, it added. ®
Get our [8]Tech Resources
[1] https://www.ic3.gov/Media/News/2022/220307.pdf
[2] https://www.acronis.com/en-us/articles/ragnar-locker/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yig0djDaKbAZmUDir4sEcAAAANg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.theregister.com/2022/03/07/samsung_lapsus_data_theft/
[5] https://www.theregister.com/2022/03/02/conti-source-code-leaked/
[6] https://www.theregister.com/2022/03/01/ukraine_wiper_apple_visa_mastercard/
[7] https://www.theregister.com/2022/03/01/aon_cyber_incident/
[8] https://whitepapers.theregister.com/
The Feds [1]said [PDF] they became aware of the ransomware crew in early 2020 and the miscreants' preferred tactic: double extortion. The crooks steal sensitive data, encrypt a victim's systems, and threatens to leak the stolen documents if the ransom to restore the files isn't paid.
To date, the Ragnar Locker criminals have [2]posted stolen data from at least ten organizations on their publicity website, according to Acronis. In its latest cyber-crime spree, the gang hit entities across nearly a dozen critical sectors as of January, according to the FBI flash alert, which also provides technical details about how the ransomware attacks work:
RagnarLocker is identified by the extension ".RGNR_<ID>," where <ID> is a hash of the computer's NETBIOS name. The actors, identifying themselves as "RAGNAR_LOCKER," leave a .txt ransom note, with instructions on how to pay the ransom and decrypt the data. RagnarLocker uses VMProtect, UPX, and custom packing algorithms and deploys within an attacker's custom Windows XP virtual machine on a target's site.
The Ragnar Locker malware uses Windows API GetLocaleInfoW to identify the infected machine's location. If the victim's locale is one of a dozen European and Asian countries, including Russia, Ukraine, and other states, the infection process terminates.
As the ransomware is deployed, it kills services commonly used by managed service providers to remotely control networks and attempts to silently delete all shadow copies of documents so that users can't recover encrypted files.
[3]
And finally, Ragnar Locker encrypts organizations' data. But instead of choosing which files to encrypt, it selects folders not to encrypt. "Taking this approach allows the computer to continue to operate 'normally' while the malware encrypts files with known and unknown extensions containing data of value to the victim," the FBI explained.
[4]Lapsus$ extortionists dump Samsung data online, chaebol confirms security breach
[5]Conti ransomware gang's source code leaked
[6]Second data-wiping malware found in Ukraine, says ESET
[7]Insurance giant Aon confirms it has suffered 'cyber incident'
For example, if the logical drive being processed is the C: drive, the malware does not encrypt files in folders names Windows, Windows.old, Mozilla, Mozilla Firefox, Tor browser, Internet Explorer, $Recycle.Bin, Program Data, Google, Opera, or Opera Software.
The FBI urged victims to report ransomware attacks to their local field office. And while it "does not encourage paying a ransom to criminal actors," it acknowledged that this can be a tricky business decision. Executives should "evaluate all options to protect their shareholders, employees, and customers," before deciding whether to pay, it added. ®
Get our [8]Tech Resources
[1] https://www.ic3.gov/Media/News/2022/220307.pdf
[2] https://www.acronis.com/en-us/articles/ragnar-locker/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yig0djDaKbAZmUDir4sEcAAAANg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.theregister.com/2022/03/07/samsung_lapsus_data_theft/
[5] https://www.theregister.com/2022/03/02/conti-source-code-leaked/
[6] https://www.theregister.com/2022/03/01/ukraine_wiper_apple_visa_mastercard/
[7] https://www.theregister.com/2022/03/01/aon_cyber_incident/
[8] https://whitepapers.theregister.com/
IF we start saving our data in c:\windows\$USERNAME to defeat this, will they change their application and just make it a wiper if it finds we've done this?