Ryuk Ransomware: Now with Worming Self-Propagation
#1
Information 
Quote:A new version of the Ryuk ransomware is capable of worm-like self-propagation within a local network, researchers have found.
 
The variant first emerged in Windows-focused campaigns earlier in 2021, according to the French National Agency for the Security of Information Systems (ANSSI). The agency said that it achieves self-replication by scanning for network shares, and then copying a unique version of the ransomware executable (with the file name rep.exe or lan.exe) to each of them as they’re found.
 
“Ryuk looks for network shares on the victim IT infrastructure. To do so, some private IP ranges are scanned: 10.0.0.0/8; 172.16.0.0/16; and 192.168.0.0/16,” according to a recent ANSSI report. “Once launched, it will thus spread itself on every reachable machine on which Windows Remote Procedure Call accesses are possible.”

The fresh version of Ryuk also reads through infected devices’ Address Resolution Protocol (ARP) tables, which store the IP addresses and MAC addresses of any network devices that the machines communicate with. Then, according to ANSSI, it sends a “Wake-On-LAN” packet to each host, in order to wake up powered-off computers.

“It generates every possible IP address on local networks and sends an ICMP ping to each of them,” according to ANSSI. “It lists the IP addresses of the local ARP cache and sends them a [wake-up] packet.”

Read more: https://threatpost.com/ryuk-ransomware-w...on/164412/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Ryuk Ransomware: Now with Worming Self-Propagation - by silversurfer - 02 March 21, 17:19

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.2.5  Moving th...Kool — 10:37
AxCrypt 3.0.0.66
AxCrypt 3.0.0.66: ...harlan4096 — 08:33
K-Lite Codec Pack 19.5.0 / 19.5.0 Update
Changes in 19.5.0:...harlan4096 — 08:31
Tor Browser 13.5.28 (ESR)
Tor Browser 13.5.28...harlan4096 — 08:27
Mozilla Thunderbird 147.0.2 & 140.7.2esr
Thunderbird Versio...harlan4096 — 16:52

[-]
Birthdays
Today's Birthdays
avatar (39)TranoTymn
Upcoming Birthdays
avatar (38)showercurtains
avatar (49)PeterWhink
avatar (46)dimaWeami
avatar (38)Michaelaburi
avatar (46)dpascoal
avatar (51)Ronaldduh
avatar (39)legalgauch
avatar (44)Baihu

[-]
Online Staff
There are no staff members currently online.

>