Threat Advisory

Hello XD ransomware now drops a backdoor while encrypting

Threat: Ransomware
Criticality: High
[subscribe_to_unlock_form]

Summary:
As recently detected Hello XD ransomware activities have been increasing in numbers lately, the malware operators are now launching an improved sample that features greater encryption. Ransomware was discovered first time in Nov 2021. It is based on stolen source code of Babuk, and participated in limited number of double-extortion assaults. Its roots are traced to Russian speaking threat actor X4KME

Description:
Hello XD ransomware operation is not currently using a tor payment site to extort victim but instead instructs victims to enter negotiations directly through a TOX chat service. In the latest version, the malware operators have added an onion site link on the dropped ransom note, but unit 42 says the site is offline, so it might be under construction.[/subscribe_to_unlock_form]

Summary:
As recently detected Hello XD ransomware activities have been increasing in numbers lately, the malware operators are now launching an improved sample that features greater encryption. Ransomware was discovered first time in Nov 2021. It is based on stolen source code of Babuk, and participated in limited number of double-extortion assaults. Its roots are traced to Russian speaking threat actor X4KME

Description:
Hello XD ransomware operation is not currently using a tor payment site to extort victim but instead instructs victims to enter negotiations directly through a TOX chat service. In the latest version, the malware operators have added an onion site link on the dropped ransom note, but unit 42 says the site is offline, so it might be under construction.[emaillocker id="1283"]

In addition to Ransomware payload , Hello XD operators were utilizing an open-source backdoor called MicroBackdoor in order to explore the infected systems, remove files, delete traces. This MicroBackdoor is hidden from view by encrypting it with WinCript API and embedding it into the ransomware payload as a result it gets downloaded in to the system as soon as the system is compromised.

As soon as the Hello XD is executed it attempts to disable shadow copied to prevent easy system recovery and then encrypts the file adding .hello extension to file names, the most interesting part of Hello XD is the author is using Rabit cypher and curve25519-Donna and file marker in new version is using random bytes making cryptographic result more powerful.

Best Practices:
Prompt system upgrades and software updates
Regular testing and validation
Implement zero trust model
Keeping regular backup of sensitive data
Train employees in security principles to identify phishing and social engineering tactics.

Threat Assessment:
Ransomware attacks have grown significantly over the past years and remain the preferred method of threat actors aiming to maximize profits. It may potentially harm an organization's reputation, disrupt regular operations and lead to temporary, and possibly permanent, loss of sensitive data.

At this time Hello XD is a dangerous early-stage ransomware project, even though its infection is not largely spread yet but its active and targeted development lays the ground for more dangerous status.

[/emaillocker]
crossmenu