Threat Advisory

RTM Locker Group Develops Linux Ransomware for Targeting ESXi and NAS Hosts

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

The group responsible for RTM Locker ransomware has created a new strain of ransomware specifically designed to target Linux systems. This marks the first time the group has ventured into targeting the open-source operating system. The newly developed ransomware strain by RTM Locker can infect Linux-based systems, as well as NAS and ESXi hosts. It appears to have been influenced by the leaked source code of the Babuk ransomware. Earlier this month, RTM Locker ransomware was documented as a private RaaS provider. It has been traced back to a cybercrime group called “Read The Manual” (RTM), which has been active since 2015. For more information, check out the link given in reference below. The Linux ransomware variant has been tailored to target ESXi hosts by shutting down all virtual machines running on the compromised machine before initiating the encryption process. The method used to introduce the ransomware on the target system is not yet identified.[/subscribe_to_unlock_form]

Summary:

The group responsible for RTM Locker ransomware has created a new strain of ransomware specifically designed to target Linux systems. This marks the first time the group has ventured into targeting the open-source operating system. The newly developed ransomware strain by RTM Locker can infect Linux-based systems, as well as NAS and ESXi hosts. It appears to have been influenced by the leaked source code of the Babuk ransomware. Earlier this month, RTM Locker ransomware was documented as a private RaaS provider. It has been traced back to a cybercrime group called “Read The Manual” (RTM), which has been active since 2015. For more information, check out the link given in reference below. The Linux ransomware variant has been tailored to target ESXi hosts by shutting down all virtual machines running on the compromised machine before initiating the encryption process. The method used to introduce the ransomware on the target system is not yet identified.[emaillocker id="1283"]

Execution Flow

The ransomware appears to be designed for targeting ESXi, as indicated by the presence of ESXi commands at the beginning of the program. The binary is statically compiled and stripped to make reverse engineering harder, and to increase compatibility across different systems. However, the method used for the initial access vector is currently unknown. The binary has important functions such as name_threads, run_esxi_commands, and pthread_wrapper_main. The name_threads function names each thread to use later in the encryption process. The threads are named “Thread-pool-%d”. After naming each thread, the run_esxi_commands routine is called, but it is not called on the NAS variant of the binary.

Once the ransomware binary terminates all running ESXi virtual machines, it proceeds to initiate the encryption process by invoking a series of commands for optimal execution. The ransomware program acquires locks on specific threads to avoid race conditions and subsequently executes another function that encrypts individual files. Upon completion of the file encryption process, the ransomware adds the .RTM extension to the filename. Upon completing the encryption process, the victim is prompted to contact the support team within 48 hours via Tox, failing which their data will be made public. To unlock the encrypted files, the victim requires the public key which is appended to the end of the file and the attacker's private key.

Threat Profile:

References:

The following reports contain further technical details:

https://Eventus Security.com/advisory/rtm-locker-an-emerging-cybercrime-group-utilizing-ransomware-as-their-weapon-of-choice/

https://thehackernews.com/2023/04/rtm-lockers-first-linux-ransomware.html

[/emaillocker]
crossmenu