Threat Advisory

Rancoz Ransomware Spread by Exploiting Vice Society's Codebase

Threat: Ransomware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Custom-branded ransomware has become more prevalent as threat actors modify existing code to create tailored variants that target specific industries or regions. The use of leaked source codes allows for easier and faster development of new ransomware families. Researcher has discovered a new ransomware variant named Rancoz, which uses a double extortion technique that involves encrypting victim data and threatening to release stolen data on a leak site. This technique increases the likelihood of payment from victims. Rancoz shows similarities to the Vice Society ransomware.[/subscribe_to_unlock_form]

Summary:

Custom-branded ransomware has become more prevalent as threat actors modify existing code to create tailored variants that target specific industries or regions. The use of leaked source codes allows for easier and faster development of new ransomware families. Researcher has discovered a new ransomware variant named Rancoz, which uses a double extortion technique that involves encrypting victim data and threatening to release stolen data on a leak site. This technique increases the likelihood of payment from victims. Rancoz shows similarities to the Vice Society ransomware.[emaillocker id="1283"]

A console-based executable file compiled using MingGW (GCC) is a sample of the Rancoz ransomware. The ransomware is manually activated upon gaining access to the victim's computer and meticulously records all its actions, reporting its behavior in real-time. It starts by inspecting the command line arguments and verifies them before proceeding with the encryption process. If the arguments do not match the predefined ones or none are passed, the ransomware proceeds with its default execution. It imports a hardcoded NTRU Public Key and displays the progress of the encryption process in real-time on the command prompt window.

The Rancoz ransomware uses a console-based binary executable file to infect the victim's system. It uses the ShellExecuteW() function to execute destructive commands that delete Shadow Copies, Registry values related to Remote Desktop Connection, and Windows event logs. The ransomware uses a multi-threading strategy to encrypt files and modifies the desktop background image of the infected system. It excludes particular folder names and file extensions from the encryption process and drops a ransom note titled "HOW_TO_RECOVERY_FILES.txt" within all the enumerated directories. The ransom note provides guidance to the victims on how to reach out to the TAs to recover their encrypted files/pay the ransom.

The continuous emergence of new ransomware variants indicates the adaptability and skills of threat actors, who can tailor their attacks to circumvent security measures. The development of customized ransomware highlights the persistent danger that ransomware groups pose to various entities. It also serves as a reminder that the risk of ransomware attacks remains a prevalent threat in the digital landscape.

Threat Profile:

 

References:

The following reports contain further technical details:

https://blog.cyble.com/2023/05/11/dissecting-rancoz-ransomware/

[/emaillocker]
crossmenu