Threat Advisory

New Go-Based JKwerlo Ransomware poses a risk to French and Spanish Users

Threat: Ransomware
Criticality: High
[subscribe_to_unlock_form]

Summary:

The investigation into the JKwerlo ransomware campaign, conducted by researcher has revealed a sophisticated and multi-faceted operation aimed at infecting and encrypting the files of targeted individuals. This ransomware utilizes a Telegram channel for communication with threat actors, indicating a level of organization and coordination within the malicious campaign. Initial findings suggest that the ransomware infiltrates systems through spam emails, targeting individuals with legal notice-themed messages in French and Spanish languages. Threat actor deploy HTML file which gives warning to recipients to review critical information via Google Drive.[/subscribe_to_unlock_form]

Summary:

The investigation into the JKwerlo ransomware campaign, conducted by researcher has revealed a sophisticated and multi-faceted operation aimed at infecting and encrypting the files of targeted individuals. This ransomware utilizes a Telegram channel for communication with threat actors, indicating a level of organization and coordination within the malicious campaign. Initial findings suggest that the ransomware infiltrates systems through spam emails, targeting individuals with legal notice-themed messages in French and Spanish languages. Threat actor deploy HTML file which gives warning to recipients to review critical information via Google Drive.[emaillocker id="1283"]

Upon investigation, two distinct campaigns were uncovered—one in French and the other in Spanish—each employing unique infection vectors and execution methodologies. In the Spanish campaign, simplicity is key, with direct infection facilitated by the execution of a JavaScript code embedded within the HTML file. This code automatically drops a zip file containing the ransomware payload onto the system. On the other hand, the French campaign employs a more intricate approach, utilizing a PowerShell script to download a DLL file from a Dropbox link. This DLL file then initiates the execution of another PowerShell script, ultimately leading to the deployment of the ransomware. The complexity of the French campaign highlights the attackers' adaptability and sophistication in evading detection and maximizing their impact. Upon execution, the ransomware performs a series of malicious activities, including deleting shadow copies, disabling Windows Defender and Windows Firewall, modifying registry settings, and terminating critical system processes. These actions effectively cripple the system's defenses and hamper the user's ability to mitigate the attack. The ransomware employs AES-GCM encryption to encrypt files within specific directories, appending no file extensions or changing file icons to avoid detection by unsuspecting victims.

The discovery of the JKwerlo ransomware campaign underscores the evolving and dynamic nature of the modern threat landscape. The operation's complexity and adaptability demonstrate the agility of threat actors in circumventing cybersecurity defenses and evading detection. As organizations continue to confront increasingly sophisticated cyber threats, it is imperative to enhance proactive threat intelligence capabilities and implement comprehensive security measures to mitigate risks effectively. The detailed analysis of the JKwerlo ransomware operation provides valuable insights into the tactics, techniques, and procedures employed by threat actors, empowering organizations to bolster their defenses and safeguard against emerging cyber threats. Do not open untrusted links and email attachments without first verifying their authenticity. Conduct regular backup practices and keep those backups offline or in a separate network. Turn on the automatic software update feature on your computer, mobile, and other connected devices wherever possible and practical.

Threat Profile:

             

References:

The following reports contain further technical details:

https://cyble.com/blog/new-go-based-jkwerlo-ransomware-poses-a-risk-to-french-and-spanish-users/

[/emaillocker]
crossmenu