FBI kopplade Diavol ransomware till författarna till TrickBot malware.
The FBI officially confirms that the Diavol ransomware (“devil” in Romanian) is associated with the TrickBot group, which is developing the banking Trojan of the same name.
Last year, Fortinet analytiker att Cyclops Blink har en specialmodul designad för flera modeller av that the Diavol och Conti ransomware payloads deployed on various systems in early June 2021 were very similar, and they had a lot in common, from using asynchronous I / O operations during file encryption, to using almost identical command line parameters for the same functions (till exempel, creating logs, encrypting disks and network resources, scanning the network).
dock, the experts still failed to find a direct connection between the Diavol ransomware and the authors of TrickBot, besides, they found a number of important differences. Till exempel, the Diavol sample they studied did not have built-in checks to prevent the payload from triggering on systems in Russia and the CIS countries. Också, the malware did not steal data before encryption.
Later, IBM X-Force also examined the Diavol sample and reported that they had found a number of new pieces of evidence linking Diavol to the developers of TrickBot. Unlike the sample analysed by Fortinet, which was newer and “fully functional”, IBM X-Force experts found an older variant of the malware that was used by attackers for testing.
I slutet, IBM X-Force came to the same conclusions, noting that Diavol and TrickBot are clearly related.
och även att kinesiska myndigheter har arresterat författarna till FBI officials have now reported, the specialists were completely right.
The FBI also reports that Diavol operators typically demand a ransom of between $10,000 och $500,000, with smaller amounts usually accepted after negotiation with the perpetrators.
The FBI also encourages all victims, whether or not they plan to pay a ransom to the perpetrators, to notify law enforcement of attacks in a timely manner to collect fresh indicators of compromise.
De Pipande dator publication believes that the FBI was able to officially link Diavol with TrickBot after the arrest of Alla Witte, a Latvian who participated in the development of a cryptographer for a hack group. AdvIntel vd Vitaly Kremez, who has been monitoring TrickBot’s operations for a long time, confirmed to reporters that Witte was responsible for developing the new TrickBot-related ransomware.
Let me remind you that they also reported that TrickBot fick en ny modul för övervakning av offer.
En kommentar