Threat Advisory

Monti Ransomware Targets VMware ESXi Servers With New Linux Locker

Threat: Ransomware
Criticality: High
[subscribe_to_unlock_form]

Summary:

The Monti ransomware, known for its Windows and Linux-based versions, attracted attention due to its uncanny resemblance to the notorious Conti ransomware, both in nomenclature and tactics. Operating under the moniker "Monti," the group meticulously imitated Conti's tactics, techniques, and procedures (TTPs), even adopting Conti's leaked source code. The Monti group, since its discovery, has persistently targeted companies and exposed them on their leak site. After a hiatus of two months from exposing victims on their leak site, the Monti ransomware group resumed its malicious operations, now concentrating on legal and government sectors. Alongside this resurgence, a novel Linux-based variant of Monti surfaced, exhibiting considerable deviations from its Linux-based predecessors. Unlike its earlier counterpart that heavily relied on leaked Conti source code, this new iteration employs an alternative encryptor and introduces distinct behaviors.[/subscribe_to_unlock_form]

Summary:

The Monti ransomware, known for its Windows and Linux-based versions, attracted attention due to its uncanny resemblance to the notorious Conti ransomware, both in nomenclature and tactics. Operating under the moniker "Monti," the group meticulously imitated Conti's tactics, techniques, and procedures (TTPs), even adopting Conti's leaked source code. The Monti group, since its discovery, has persistently targeted companies and exposed them on their leak site. After a hiatus of two months from exposing victims on their leak site, the Monti ransomware group resumed its malicious operations, now concentrating on legal and government sectors. Alongside this resurgence, a novel Linux-based variant of Monti surfaced, exhibiting considerable deviations from its Linux-based predecessors. Unlike its earlier counterpart that heavily relied on leaked Conti source code, this new iteration employs an alternative encryptor and introduces distinct behaviors.[emaillocker id="1283"]

The fresh Linux variant introduces new command line arguments, omitting some while adding the --whitelist parameter. Notably, the new version uses the -type=soft parameter to terminate virtual machines, suggesting a strategic shift for evading immediate detection. Additionally, Monti's developers altered the /etc/motd and index.html files, replacing content with a ransom note announcing successful infiltration. This alteration of the Message of the Day (MOTD) holds relevance when users log into a Linux operating system. The new variant involves appending the bytes "MONTI" followed by 256 bytes linked to the encryption key.

Before initiating encryption, the ransomware assesses specific conditions. It checks if the file size is 261 bytes or smaller, corresponding to the appended infection marker size. Meeting this condition implies that the file remains unencrypted and warrants further processing. Should the condition not apply, Monti examines the last 261 bytes for the presence of the string "MONTI." Detection implies the file is already encrypted, while absence triggers the encryption process. Contrasting with its predecessor's Salsa20, the new ransomware variant employs AES-256-CTR encryption using OpenSSL's evp_enc. The sample features diverse encryption methods based on file size. Unlike the previous variant, which used a --size argument, the new variant solely relies on file size.

The new variant appends the .monti extension and drops the ransom note readme.txt in each directory. Interestingly, a decryption code in the sample suggests testing but remains ineffective due to missing private keys. While the new variant retains some elements from Conti's source code, considerable alterations, especially in encryption algorithms, underscore the group's aim to elude detection and intensify their activities.

Threat Profile:

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/monti-ransomware-targets-vmware-esxi-servers-with-new-linux-locker/

[/emaillocker]
crossmenu