spot_img

Researchers Link White Rabbit Ransomware To FIN8 Hackers

Share post:

A new ransomware “White Rabbit” was discovered by ransomware expert Michael Gillespie.

Based on a sample analyzed from one of its attacks in December 2021, Trend Micro researchers shared some details about ransomware.

This includes the fact that the ransomware executable is a small payload that weighs in at 100 KB file. It requires a password that must be entered during command-line execution to decrypt the malicious payload.

Once executed with the correct password, the ransomware scan all the folders on the device and encrypts targeted files, while it creates ransom notes for each encrypted file.

In the process of encrypting a device, removable network drives are also targeted. However, Windows system folders are excluded from encryption to prevent the operating system from becoming unusable.

Trend Micro’s report linked the ‘White Rabbit’ operation to the FIN8 ransomware group, a financially motivated group that uses POS malware to steal credit card data.

According to researchers, ‘White Rabbit’ uses a never-before-seen version of Badhatch. Badhatch (aka Sardonic) is a backdoor associated with FIN8.

For more information, read the original story in BleepingComputer.

spot_img

SUBSCRIBE NOW

Related articles

Cyber Security Today, March 22, 2023 – ChatGPT4 is out, poorly-protected Linux servers are exploited, and more

ChatGPT4 is out, poorly-protected Linux servers are exploited, and more. Welcome to Cyber Security Today. It’s Wednesday, March 22nd, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S. The new version of ChatGPT has been released. But if you were hoping that version 4 has made this tool safer

Only 9 per cent of Canadian firms are cyber mature: Cisco report

Only 15 per cent of companies around the world would have a mature cyber readiness, according to survey

Ferrari notifies customers of ransom demand

Exclusive car maker says some client contact information exposed in cy

Government backs down on document demand from Google, Facebook

Change meets criticism that demand for external communications is an invasion

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways