5 ms·
> Each sample of the malware contains a hardcoded name of the victim organization. > Apart from encrypting the files and leaving ransom notes, the sample has n
by Memosyne 6y ago
> Each sample of the malware contains a hardcoded name of the victim organization.
> Apart from encrypting the files and leaving ransom notes, the sample has none of the additional functionality that other threat actors tend to use in their Trojans: no C&C communication, no termination of running processes, no anti-analysis tricks, etc.
> Curiously, the ELF binary contains some debug information, including names of functions, global variables and source code files used by the malware developers.
Seems pretty amateurish...
- Drakim 6y agoMaybe it's for debugging the software out in the wild?
- teruakohatu 6y ago> Seems pretty amateurish... It is for manually targeted attacks. Once it is deployed, the damage is done and the victim is notified. They don't need C&C. The hardcoded victim name is probably just a big FU. You can have excellent perimeter security but this organisation might just bribe an employee to gain access. It is far more scary than some automated bot scanning for ports.
- Memosyne 6y agoI'm not denying its effectiveness, just remarking on its technical merit as a topic of discussion. Once the system is already compromised it becomes less about the payload and more about the attack vector involved. If the payload in question was using novel techniques then it would be a different story but the analysis shows the program to be relatively rudimentary.
- cutemonster 6y agoKeeping things simple can be a good judgement decision? (This time in a weird context) > ELF binary contains some debug information But that sounds weird to me
- Memosyne 6y agoHm, I possibly misused the term "amateurish" when I meant "simple". My apologies for the confusion.
- jlgaddis 6y agoWell, no point in over-engineering a solution, right? To put it another way, sounds like they moved fast (and maybe broke a few things?), put together an MVP that meets their needs, rolled it out, and are now likely learning and gathering feedback for their next iteration... sounds like they fit right in around here! (This thread reminded me of something a cow-orker used to say: "If it's stupid but it works, it's not stupid".)
- deleted 6y ago[deleted]
- stevefan1999 6y agoFU in terms of Fear & Uncertainty or f*ck you?
- jand 6y agoI read it as f* up.
- nostoc 6y agoMost ransomwares don't do C&C. They don't need to, and it's stealthier that way. Actors that do exfil typically have other malware in their toolkit to do just that.
- mobilio 6y agoSeems that they forgot to strip debug information. Clearly this is lack of *nix dev skills.