20/11/2021
NEW ransomware actor uses password-protected archives to bypass encryption protection...
Calling themselves "Memento team", these threat actors use Python-based ransomware that they reconfigured after setbacks.NEW ransomware actor uses password-protected archives to bypass encryption protection
Calling themselves "Memento team", actors use Python-based ransomware that they reconfigured after setbacks...
In late October, Sophos MTR’s Rapid Response Team encountered a new ransomware group with an interesting approach to holding victims’ files hostage. The ransomware used by this group, who identify themselves as “Memento Team,” doesn’t encrypt files. Instead, it copies files into password-protected archives, using a renamed freeware version of the legitimate file utility WinRAR—and then encrypts the password and deletes the original files.
This was a retooling by the ransomware actors, who initially attempted to encrypt files directly—but were stopped by endpoint protection. After failing on the first attempt, they changed tactics, and re-deployed, as evidenced by the multiple versions of the ransomware payload compiled at different times found on the victim’s network. They then demanded $1 million US to restore the files, and threatened data exposure if the victim did not comply.
There were some other twists to the “Memento” attack as well. The ransomware itself is a Python 3.9 script compiled with PyInstaller. And in a ransom note that largely cribs the format used by REvil (including the “[-] What’s Happen [-]” introduction), the criminals behind the ransomware instructed the victims to contact them via a Telegram account. The attackers also deployed an open-source Python-based keylogger on several machines as they moved laterally within the network using Remote Desktop Protocol.
The Memento actors also waited a long time before executing their attack (6 months dwell time)—so long that at least two different cryptocurrency miners were dropped onto the server they used for initial access during the course of their dwell time by different intruders using similar exploits.
Thanks to backups, the targeted organization was able to restore most of their data. For systems running InterceptX, the endpoint detection and response system logged the commands used by the attack to archive files, along with the unencrypted passwords for the files.
SophosLabs and Sophos Rapid Response were able to recover select files for the victim and provide a method for recovering any files not backed up.
A list of the IOCs for the Memento attack and the miner attacks from this incident is available on SophosLabs’ GitHub page.
Read the full story from Sean Gallagher and team: https://news.sophos.com/en-us/2021/11/18/new-ransomware-actor-uses-password-protected-archives-to-bypass-encryption-protection/?cmp=30728