Threat Advisory

Kasseika Ransomware Exploits BYOVD Trick to Disable Security Pre-Encryption on Windows Systems

Threat: Ransomware
Criticality: High
[subscribe_to_unlock_form]

Summary:

 The Kasseika ransomware group has recently adopted a sophisticated attack technique known as Bring Your Own Vulnerable Driver (BYOVD), aligning with other notorious ransomware groups like Akira, AvosLocker, BlackByte, and RobbinHood. This method strategically disarms security-related processes on compromised Windows systems, facilitating the seamless deployment of ransomware. Researcher analysis, reveals striking parallels between Kasseika and the now-defunct BlackMatter, hinting at a potential connection or acquisition of expertise. The attack vectors involve phishing emails for initial access, followed by the use of remote administration tools and the exploitation of Microsoft's Sysinternals PsExec utility to execute malicious scripts.[/subscribe_to_unlock_form]

Summary:

 The Kasseika ransomware group has recently adopted a sophisticated attack technique known as Bring Your Own Vulnerable Driver (BYOVD), aligning with other notorious ransomware groups like Akira, AvosLocker, BlackByte, and RobbinHood. This method strategically disarms security-related processes on compromised Windows systems, facilitating the seamless deployment of ransomware. Researcher analysis, reveals striking parallels between Kasseika and the now-defunct BlackMatter, hinting at a potential connection or acquisition of expertise. The attack vectors involve phishing emails for initial access, followed by the use of remote administration tools and the exploitation of Microsoft's Sysinternals PsExec utility to execute malicious scripts.[emaillocker id="1283"]

The Kasseika ransomware employs advanced tactics, starting with targeted phishing for initial access, followed by credential harvesting and the use of remote administration tools (RATs) for lateral movement. Notably, the ransomware utilizes PsExec, a legitimate Windows RAT, for malicious file execution. A key element is the abuse of the Martini driver, terminating antivirus processes effectively. The attack involves a batch script checking and terminating Martini.exe, leveraging Martini.sys to exploit vulnerabilities, creating a service, and communicating with the driver to terminate numerous processes. Kasseika demonstrates a nuanced understanding of its environment, employing techniques like string comparison to evade security and analysis tools.

The Kasseika ransomware poses a significant threat with its adoption of advanced techniques, particularly the BYOVD attack method. The observed overlaps with BlackMatter suggest a level of sophistication, possibly involving the acquisition or purchase of expertise from the defunct group. Kasseika's attack chain, starting with phishing emails and progressing to the deployment of ransomware with defense evasion tactics, showcases a multifaceted threat landscape. As cybercriminals continue to refine their tactics, organizations must remain vigilant and implement robust security measures to safeguard against evolving ransomware threats like Kasseika.

Threat Profile:

References:

The following reports contain further technical details:

https://thehackernews.com/2024/01/kasseika-ransomware-using-byovd-trick.html

[/emaillocker]
crossmenu