One Article Review

Accueil - L'article:
Source Fortinet.webp Fortinet ThreatSignal
Identifiant 8020779
Date de publication 2022-11-14 21:53:31 (vue: 2022-11-15 06:05:59)
Titre Somnia Ransomware Targets Ukraine
Texte FortiGuard Labs is aware of a report that a new ransomware "Somnia" was observed in attacks against Ukraine. Somnia ransomware was deployed as a final payload in multiple staged attacks involving a fake IP scanner, Vidar stealer, and Cobalt Strike. The attack was attributed to FRwL (aka Z-Team, UAC-0118).Why is this Significant?This is significant because Somnia is the latest ransomware that reportedly targets Ukrainian interests. Other ransomware variants that previously targeted Ukraine include are but not restricted to Prestige, AcidRain, DoubleZero, CaddyWiper, IssacWiper, HermeticWiper, and WhisperGate.How was Somnia Ransomware Distributed?Somnia ransomware was reportedly distributed in an attack chain that goes through multiple stages. First, the attacker creates a fake Advanced IP Scanner Web site in an attempt to trick Ukrainian organizations into downloading and installing Vidar stealer disguised as "Advanced IP Scanner" installer. Once a victim's machine is compromised by Vidar stealer, it tries to steal Telegram's session data, which is then used to compromise VPN connections giving the attacker access to the victim's network. Cobalt Strike was seen deployed to the compromised network. Reportedly Rсlone, Anydesk, and Ngrok were observed for data exfiltration. Finally, Somnia ransomware deployed to encrypt files on the compromised machines.What is Somnia Ransomware?Somnia is a ransomware that encrypts files on compromised machines. According to CERT-UA, there are two different types of Somnia ransomware; the one uses 3DES algorithm for file encryption and the other uses the AES algorithm. The affected files have a ".somnia" file extension.Somnia ransomware targets and encrypts files with the following extensions:File extensions targeted by Somnia ransomware (screenshot taken from a CERT-UA report)Since Somnia ransomware does not drop any ransom note and attacker's contact information, victims will likely will not be able to decrypt the encrypted files.What is the Status of Protection?While Somnia ransomware samples are not publicly available, FortiGuard Labs detect the fake Advanced IP Scanner used as initial infection vector with the following AV signature:• W32/PossibleThreatReported network IOCs are blocked by Webfiltering.
Envoyé Oui
Condensat 0118 3des able access according acidrain advanced aes affected against algorithm any anydesk are attack attacker attacks attempt attributed available aware because blocked but caddywiper cert chain cobalt compromise compromised connections contact creates data decrypt deployed detect different disguised distributed does doublezero downloading drop encrypt encrypted encryption encrypts exfiltration extension extensions extensions:file fake file files final finally first following fortiguard from frwl giving goes have hermeticwiper how include infection information initial installer installing interests involving iocs issacwiper labs latest likely machine machines multiple network new ngrok not note observed once one organizations other payload prestige previously protection publicly ransom ransomware ransomware; report reportedly restricted rсlone samples scanner screenshot seen session signature:• significant since site somnia staged stages status steal stealer strike taken targeted targets team telegram then through trick tries two types uac ukraine ukrainian used uses variants vector victim victims vidar vpn w32/possiblethreatreported web webfiltering what which whispergate why will
Tags Ransomware
Stories
Notes
Move


L'article ne semble pas avoir été repris aprés sa publication.


L'article ne semble pas avoir été repris sur un précédent.
My email: