Summary:
A newly discovered strain of ransomware dubbed HavanaCrypt. First observed in June 2022 in the wild, HavanaCrypt masquerades as a legitimate Google Chrome update in order to gain access to a system and encrypt files for impact.[/subscribe_to_unlock_form]
Summary:
A newly discovered strain of ransomware dubbed HavanaCrypt. First observed in June 2022 in the wild, HavanaCrypt masquerades as a legitimate Google Chrome update in order to gain access to a system and encrypt files for impact.[emaillocker id="1283"]
It contains sophisticated anti-analysis techniques and uses open-source cryptographic functions to operate. However, its lack of a ransom note renders it unprofitable for its author. Other functionality that may be used for data exfiltration and privilege escalation, as well as file decryption capabilities, ostensibly used upon the victim meeting the attacker’s demands has been observed. HavanaCrypt continues the recent trend of malware attempting to masquerade as legitimate tools or processes in this case as a Google Chrome installation update in order to convince users to begin execution. HavanaCrypt leverages functionalities from the open-source password software KeePass for file encryption. HavanaCrypt utilizes anti-analysis techniques including code obfuscation, virtual machine reconnaissance, and process killing to ensure that it is not easily detected by typical security measures and hard to reverse engineer. HavanaCrypt establishes C2 communications via an exploited Microsoft hosting address. However, no ransom note has been observed.
References:
The following reports contain further technical details:
https://www.cybereason.com/blog/threat-alert-havanacrypt-ransomware-masquerading-as-google-update
[/emaillocker]