Threat Advisory

BlackSuit Ransomware Targeting Windows and Linux Users

Threat: Ransomware
Criticality: High
[subscribe_to_unlock_form]

Summary:

There has been a rise in the use of Linux variants by ransomware groups, such as Cylance and Royal ransomware, possibly due to the widespread adoption of Linux as an operating system in various industries. A newly discovered ransomware group called BlackSuit has been identified by researchers. Threat actors are utilizing the BlackSuit ransomware to attack users of both Windows and Linux operating systems. Researchers have noted similarities in the code of the Linux version of BlackSuit ransomware and the Royal ransomware.[/subscribe_to_unlock_form]

Summary:

There has been a rise in the use of Linux variants by ransomware groups, such as Cylance and Royal ransomware, possibly due to the widespread adoption of Linux as an operating system in various industries. A newly discovered ransomware group called BlackSuit has been identified by researchers. Threat actors are utilizing the BlackSuit ransomware to attack users of both Windows and Linux operating systems. Researchers have noted similarities in the code of the Linux version of BlackSuit ransomware and the Royal ransomware.[emaillocker id="1283"]

BlackSuit ransomware is written in C/C++ and is a 32-bit executable. Once executed, BlackSuit ransomware aquires the command-line arguments and then matches them against a list of pre-set strings. The strings serve as parameters for the ransomware's runtime operations and can be specified through command-line inputs. To run the ransomware binary, the " -name" parameter is required, as it is a unique 32-character identifier assigned to each targeted victim. When the ransomware is run with the "-noprotect" parameter, it can initiate numerous instances concurrently. In the absence of the "-noprotect" parameter, the ransomware generates a mutex with a name that corresponds to the value of the "-name" parameter. After establishing the mutex, the ransomware checks for the existence of a similarly named mutex by examining the error value. The ransomware will end its operation if it discovers a mutex with a matching name that is already active. If -local parameter is not set, then the ransomware will start enumerating network devices. After acquiring the roster of network shares, the ransomware connects to the administrative (ADMIN$) and interprocess communication (IPC$) shares, enabling it to propagate laterally and infect other systems that are part of the same network. Afterwards, the ransomware goes through the files and directories and starts the encryption process. As it encrypts files, the ransomware leaves a ransom note called "README.BlackSuit.txt" in each directory it visits. The ransomware also renames the encrypted files by adding the ".BlackSuit" extension. If the parameter for disabling safe boot is present then it will disable the safe boot mode. At last if the delete parameter is set then it will delete itself from the system.

In conclusion, ransomware attacks continue to increase, with new groups emerging regularly. BlackSuit is one of the latest ransomware strains that has come to light, and although it shares some code similarities with Royal ransomware, their connection has not been officially confirmed yet. So far, there is no information available regarding BlackSuit's victims, but there is a possibility that the group may disclose this information in the future. By targeting multiple operating systems, BlackSuit has expanded its attack surface, making it a growing concern for organizations and individuals alike.

Threat Profile:

References:

The following reports contain further technical details:

https://blog.cyble.com/2023/05/12/blacksuit-ransomware-strikes-windows-and-linux-users/

[/emaillocker]
crossmenu