Newsletter
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
    • CAMERA
  • COMPUTERS
    • LAPTOP
    • APPLICATIONS
    • AUDIO
  • WRITE FOR US
  • Advertise Here
No Result
View All Result
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
    • CAMERA
  • COMPUTERS
    • LAPTOP
    • APPLICATIONS
    • AUDIO
  • WRITE FOR US
  • Advertise Here
No Result
View All Result
REAL HACKER NEWS
No Result
View All Result
Home APPLICATIONS

New Linux Ransomware Strain BlackSuit Shows Striking Similarities to Royal

Real Hacker Staff by Real Hacker Staff
June 3, 2023
in APPLICATIONS
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Jun 03, 2023Ravie LakshmananEndpoint Security / Linux

An analysis of the Linux variant of a new ransomware strain called BlackSuit has covered significant similarities with another ransomware family called Royal.

Trend Micro, which examined an x64 VMware ESXi version targeting Linux machines, said it identified an “extremely high degree of similarity” between Royal and BlackSuit.

“In fact, they’re nearly identical, with 98% similarities in functions, 99.5% similarities in blocks, and 98.9% similarities in jumps based on BinDiff, a comparison tool for binary files,” Trend Micro researchers noted.

A comparison of the Windows artifacts has identified 93.2% similarity in functions, 99.3% in basic blocks, and 98.4% in jumps based on BinDiff.

BlackSuit first came to light in early May 2023 when Palo Alto Networks Unit 42 drew attention to its ability to target both Windows and Linux hosts.

Cybersecurity

In line with other ransomware groups, it runs a double extortion scheme that steals and encrypts sensitive data in a compromised network in return for monetary compensation. Data associated with a single victim has been listed on its dark web leak site.

The latest findings from Trend Micro show that, both BlackSuit and Royal use OpenSSL’s AES for encryption and utilize similar intermittent encryption techniques to speed up the encryption process.

The overlaps aside, BlackSuit incorporates additional command-line arguments and avoids a different list of files with specific extensions during enumeration and encryption.

“The emergence of BlackSuit ransomware (with its similarities to Royal) indicates that it is either a new variant developed by the same authors, a copycat using similar code, or an affiliate of the Royal ransomware gang that has implemented modifications to the original family,” Trend Micro said.

Given that Royal is an offshoot of the erstwhile Conti team, it’s also possible that “BlackSuit emerged from a splinter group within the original Royal ransomware gang,” the cybersecurity company theorized.

The development once again underscores the constant state of flux in the ransomware ecosystem, even as new threat actors emerge to tweak existing tools and generate illicit profits.

UPCOMING WEBINAR

🔐 Mastering API Security: Understanding Your True Attack Surface

Discover the untapped vulnerabilities in your API ecosystem and take proactive steps towards ironclad security. Join our insightful webinar!

Join the Session

This includes a new ransomware-as-a-service (RaaS) initiative codenamed NoEscape that Cyble said allows its operators and affiliates to take advantage of triple extortion methods to maximize the impact of a successful attack.

Related articles

iOS, macOS, Safari, and More Vulnerable

iOS, macOS, Safari, and More Vulnerable

September 22, 2023
Google releases new YouTube Create app: a mobile video editing app for content creators

Google releases new YouTube Create app: a mobile video editing app for content creators

September 22, 2023

Triple extortion refers to a three-pronged approach wherein data exfiltration and encryption is coupled with distributed denial-of-service (DDoS) attacks against the targets in an attempt to disrupt their business and coerce them into paying the ransom.

The DDoS service, per Cyble, is available for an added $500,000 fee, with the operators imposing conditions that forbid affiliates from striking entities located in the Commonwealth of Independent States (CIS) countries.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: BlackSuitLinuxRansomwareRoyalshowsSimilaritiesStrainStriking
Share76Tweet47

Related Posts

iOS, macOS, Safari, and More Vulnerable

iOS, macOS, Safari, and More Vulnerable

by Real Hacker Staff
September 22, 2023
0

Sep 22, 2023THNZero Day / Vulnerability Apple has launched yet one more spherical of safety patches to handle three actively...

Google releases new YouTube Create app: a mobile video editing app for content creators

Google releases new YouTube Create app: a mobile video editing app for content creators

by Real Hacker Staff
September 22, 2023
0

Google has launched a brand new video modifying app known as YouTube Create app on the Google Play Retailer geared toward...

Studio Bot expands to 170+ international markets!

Studio Bot expands to 170+ international markets!

by Real Hacker Staff
September 21, 2023
0

Apple Updates Keynote, Pages, Numbers for iOS/iPadOS 17

by Real Hacker Staff
September 21, 2023
0

Right here’s what’s new in Pages 13.2: • Deliver new dimension to your paperwork with 3D objects in USDZ format•...

Mysterious ‘Sandman’ Threat Actor Targets Telecom Providers Across Three Continents

Mysterious ‘Sandman’ Threat Actor Targets Telecom Providers Across Three Continents

by Real Hacker Staff
September 22, 2023
0

Sep 21, 2023THNTelecom Safety / Cyber Assault A beforehand undocumented risk actor dubbed Sandman has been attributed to a set...

Load More
  • Trending
  • Comments
  • Latest

OPPO’s European journey takes another hit as it ceases distribution in France

July 27, 2023

vivo Y11 (2023) unveiled with Helio P35 SoC and 5,000 mAh battery

April 1, 2023

US seizes Z-Library login domain, but secret URLs for each user remain active

May 5, 2023

How to change the audio output on Android

June 11, 2023

SmallRig P200 Bi-Color LED Light Panel

0

Pinterest brings shopping capabilities to Shuffles, its collage-making app

0

Microsoft Ends $1 Xbox Game Pass Offer For First Month of Use

0

Apple shows off upcoming mixed-reality headset to its top execs

0
Facebook now lets you have multiple profiles with a single account

Facebook now lets you have multiple profiles with a single account

September 22, 2023
Sudan army chief warns UN that war could spill over, engulf region | United Nations News

Sudan army chief warns UN that war could spill over, engulf region | United Nations News

September 22, 2023
X is shutting down its Circle feature in October

X is shutting down its Circle feature in October

September 22, 2023
China reiterates ceasefire, peace talks ‘only way’ to end Ukraine war | Politics News

China reiterates ceasefire, peace talks ‘only way’ to end Ukraine war | Politics News

September 22, 2023

Recent News

Facebook now lets you have multiple profiles with a single account

Facebook now lets you have multiple profiles with a single account

September 22, 2023
Sudan army chief warns UN that war could spill over, engulf region | United Nations News

Sudan army chief warns UN that war could spill over, engulf region | United Nations News

September 22, 2023

Categories

  • APPLICATIONS
  • AUDIO
  • CAMERA
  • COMPUTERS
  • GAMING
  • LAPTOP
  • REVIEWS
  • SECURITY
  • SMARTPHONES
REAL HACKER NEWS

We bring you the best news on Internet new gadgets hacking and technology from around the world

  • Contact
  • Cookie Privacy Policy
  • Terms and Conditions
  • Privacy Policy
  • Disclaimer
  • DMCA

© 2003 Real Hacker News

No Result
View All Result
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
    • CAMERA
  • COMPUTERS
    • LAPTOP
    • APPLICATIONS
    • AUDIO
  • WRITE FOR US
  • Advertise Here

© 2003 Real Hacker News