Threat Advisory

Spacecolon: Unveiling the Tools and Tactics of CosmicBeetle's Ransomware Campaigns

Threat: Ransomware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Researchers discuss Spacecolon, a toolset used to deploy variants of the Scarab ransomware to victims worldwide, and the enigmatic group behind it, known as CosmicBeetle. Spacecolon primarily serves as a vehicle for deploying the notorious Scarab ransomware and acts as a backdoor, providing extensive access to compromised systems. CosmicBeetle remains a shadowy presence in the cyber threat landscape, eluding attribution to any known threat actor group. CosmicBeetle's victims exhibit no discernible pattern in terms of industry or size. Their targets range from hospitals and tourist resorts to insurance companies and governmental institutions worldwide.[/subscribe_to_unlock_form]

Summary:

Researchers discuss Spacecolon, a toolset used to deploy variants of the Scarab ransomware to victims worldwide, and the enigmatic group behind it, known as CosmicBeetle. Spacecolon primarily serves as a vehicle for deploying the notorious Scarab ransomware and acts as a backdoor, providing extensive access to compromised systems. CosmicBeetle remains a shadowy presence in the cyber threat landscape, eluding attribution to any known threat actor group. CosmicBeetle's victims exhibit no discernible pattern in terms of industry or size. Their targets range from hospitals and tourist resorts to insurance companies and governmental institutions worldwide.[emaillocker id="1283"]

CosmicBeetle employs various methods for initial access. They compromise vulnerable web servers and brute force RDP credentials. Additionally, they may exploit the CVE-2020-1472 (ZeroLogon) vulnerability, and there are indications of potential FortiOS vulnerability abuse. These methods grant them a foothold into their victims' environments. Spacecolon comprises three Delphi components: ScHackTool, ScInstaller, and ScService. ScHackTool serves as the orchestrator, enabling the deployment of additional tools. ScInstaller's role is to install ScService, a backdoor that allows CosmicBeetle to execute commands, download payloads, and gather system information from compromised machines. Spacecolon operators have an arsenal of third-party tools at their disposal, both legitimate and malicious, which they can deploy on-demand, enhancing their capabilities.

In a striking revelation, researcher observed a new ransomware family, ScRansom, likely developed by the same entity as Spacecolon. This ransomware shares Turkish code strings, uses the IPWorks library, and bears a similar GUI. ScRansom, however, seems to still be in the developmental stage, with no observed deployments at the time of writing. Spacecolon deploys a variant of the Scarab ransomware, characterized by code overlaps with other ransomware families. It also includes a ClipBanker component that monitors and alters cryptocurrency wallet addresses on the clipboard. The primary component, ScHackTool, features a GUI interface. It orchestrates attacks, downloads additional tools, and communicates with a C&C server. It employs a simple string encryption algorithm. ScInstaller installs ScService and is part of the toolset. While it had a GUI in earlier versions, recent builds suggest it may no longer be actively used. ScService operates as a Windows service, acting as a backdoor. It communicates with C&C servers, executes commands, and underwent notable changes in March 2023, adopting HTTP communication and enhancing string encryption.

Spacecolon, orchestrated by the enigmatic CosmicBeetle group, is a multifaceted threat toolset used to deploy Scarab ransomware and establish backdoor access to compromised systems. Despite its extensive capabilities, CosmicBeetle operates with little effort to conceal their actions, leaving traces of their presence on compromised systems. The toolset has evolved since its inception in 2020, with significant efforts to evade detection in 2023, following public scrutiny. CosmicBeetle's victims span various industries and geographic locations, indicating an opportunistic approach rather than targeted attacks. This analysis sheds light on the intricate workings of Spacecolon, providing valuable insights into the operations of this elusive threat actor group.

 

Threat Profile:

 

References:

The following reports contain further technical details:

https://thehackernews.com/2023/08/spacecolon-toolset-fuels-global-surge.html

[/emaillocker]
crossmenu