Connect with us

Business

ARCrypt Ransomware Adapts TOR Communication Channels to Avoid detection

Published

on

A newly evolved linux variant of AR crypt malware developed with GO language started targeting worldwide.

The emergence of AR Crypt malware was seen in the year of  Aug 2022, able to target both Linux and Windows machines.

According to Cyble Research and Intelligence lab, the new variant updated its tactics and techniques to interact with victims to evade detections.

Analysis of New Variant

Unlike the old variant, the new variant communicates with victims through mirror sites, and threat actors create unique chat sites for each victim.

Also, it instructs victims to create a user profile on the TOX messaging page for communication and offers a discount if the ransom was paid in Monero.

Since the attack vector of the ransomware is unknown, once executed the payload the ransomware copies to the %TEMP% directory and assigns a random six-digit upper alphanumeric value.

Later, it deletes the original ransomware binary using the command “cmd /c DEL “%SAMPLEPATH%” &EXIT,” where A batch script was used to remove the initial executable file in old versions

In addition to that, it terminates processes related to anti-malware, backup, and recovery to accelerate encryption to evade detection from EDR.

Finally, this ransomware delivers a ransom note before encrypting the files; it encrypts the files with the extension “.crYpt”, whereas the older variant uses the “.crypt” extension.

The binaries in the ransom note direct the victims to different Tor sites for communication, which share the same user interface but have different URLs. 

Typically, ransomware TAs include all the mirror sites in the ransom note to ensure accessibility for victims. This approach allows victims to access an alternative site if one becomes inaccessible.

Source: https://cybersecuritynews.com/arcrypt-ransomware-tor/

Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Copyright © 2023 Cyber Reports Cyber Security News All Rights Reserved Website by Top Search SEO