#1 Trending Cybersecurity News & Magazine
Tuesday, December 5, 2023
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    Vietnam Electricity data breach

    BlackCat Ransomware Strikes Ho Chi Minh City Power Corporation

    cybersecurity

    Emerging Trends and Challenges in Cybersecurity: Insights from Abul Kalam Azad

    Spyroid Rat Android RAT

    Unmasking Spyroid Rat: An In-Depth Look at the Menacing Android RAT

    MIRLE Group cyberattack

    MIRLE Group Targeted by Notorious LockBit Ransomware Group

    Cosmote Cyberattack

    Anonymous Collective Targets Greece’s Largest Mobile Operator Cosmote; Website Currently Down

    Colonial Pipeline Data Breach

    Colonial Pipeline Hit by ‘CyberNiggers’ Hacker Group, Sensitive Data for Sale on Dark Web

    KBEE cyberattack

    Koh Brothers Eco Engineering Limited Hit by Cyberattack, Prompting Immediate Response

    Tipalti Data Breach

    Cybersecurity Concerns Rise Amidst Tipalti Data Breach, X Might be Next!

    Cyberattack on First Abu Dhabi Bank

    Anonymous Arabia Targets UAE’s Largest Bank FAB in Cyberattack

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    AI Security Guidelines

    Rethinking AI For Cybersecurity: The UK & US Reveals New Guidelines For AI Security

    Cyber Insurance

    Cyber Insurance and Real-Time Threat Dashboard to Mend the Gaps in Near Future

    Pledge to Stop Ransom Payment

    Pledge to Stop Ransom Payment Awaits Consensus from all Members of the CRI

    Executive Order on Artificial Intelligence

    Biden Administration’s AI Directive: A Blueprint for Ethical Use and Enhanced Cybersecurity

    Cyber Resilience

    Towards Cyber Resilience: A Data-Centric Approach to Security

    CybleGrowCon

    Cyble Partner Network GrowCon 2023: Uniting Cybersecurity Leaders

    GRC, What is GRC

    What is GRC (Governance, Risk & Compliance): A Beginner’s Guide

    Facial Recognition Ban

    New York State Education Department Bans Facial Recognition Scans in Schools

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    InsureMO

    InsureMO Partners with Cyble to Revolutionize Cyber Insurance with Real-Time Threat Intelligence

    Countdown to TimeAI Summit 2023

    Countdown to TimeAI Summit 2023: Unveiling the Future of Artificial Intelligence in Dubai

    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin
SUBSCRIBE
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    Vietnam Electricity data breach

    BlackCat Ransomware Strikes Ho Chi Minh City Power Corporation

    cybersecurity

    Emerging Trends and Challenges in Cybersecurity: Insights from Abul Kalam Azad

    Spyroid Rat Android RAT

    Unmasking Spyroid Rat: An In-Depth Look at the Menacing Android RAT

    MIRLE Group cyberattack

    MIRLE Group Targeted by Notorious LockBit Ransomware Group

    Cosmote Cyberattack

    Anonymous Collective Targets Greece’s Largest Mobile Operator Cosmote; Website Currently Down

    Colonial Pipeline Data Breach

    Colonial Pipeline Hit by ‘CyberNiggers’ Hacker Group, Sensitive Data for Sale on Dark Web

    KBEE cyberattack

    Koh Brothers Eco Engineering Limited Hit by Cyberattack, Prompting Immediate Response

    Tipalti Data Breach

    Cybersecurity Concerns Rise Amidst Tipalti Data Breach, X Might be Next!

    Cyberattack on First Abu Dhabi Bank

    Anonymous Arabia Targets UAE’s Largest Bank FAB in Cyberattack

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    AI Security Guidelines

    Rethinking AI For Cybersecurity: The UK & US Reveals New Guidelines For AI Security

    Cyber Insurance

    Cyber Insurance and Real-Time Threat Dashboard to Mend the Gaps in Near Future

    Pledge to Stop Ransom Payment

    Pledge to Stop Ransom Payment Awaits Consensus from all Members of the CRI

    Executive Order on Artificial Intelligence

    Biden Administration’s AI Directive: A Blueprint for Ethical Use and Enhanced Cybersecurity

    Cyber Resilience

    Towards Cyber Resilience: A Data-Centric Approach to Security

    CybleGrowCon

    Cyble Partner Network GrowCon 2023: Uniting Cybersecurity Leaders

    GRC, What is GRC

    What is GRC (Governance, Risk & Compliance): A Beginner’s Guide

    Facial Recognition Ban

    New York State Education Department Bans Facial Recognition Scans in Schools

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    InsureMO

    InsureMO Partners with Cyble to Revolutionize Cyber Insurance with Real-Time Threat Intelligence

    Countdown to TimeAI Summit 2023

    Countdown to TimeAI Summit 2023: Unveiling the Future of Artificial Intelligence in Dubai

    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

BlackSnake Ransomware Slithers Out of Chaos’s Shadows

After Onyx and Yashma ransomware variants, BlackSnake has become the latest offshoot of the Chaos ransomware strain, reported cybersecurity firm Cyble.

Editorial by Editorial
March 10, 2023 - Updated on June 26, 2023
in Firewall Daily, Ransomware News
0
BlackSnake Ransomware
635
SHARES
3.5k
VIEWS
Share on LinkedInShare on Twitter

After Onyx and Yashma ransomware variants, BlackSnake has become the latest offshoot of the Chaos ransomware strain, reported cybersecurity firm Cyble.  

Extremely sophisticated and advanced, Blacksnake ransomware has already been used in several attacks, targeting a variety of organizations, including healthcare, finance, and government entities, according to Cyble. 

You might also like

TrickMo Banking Trojan Resurfaces with New Features, Targeting Android Devices this Time Around

BlackCat Ransomware Strikes Ho Chi Minh City Power Corporation

Emerging Trends and Challenges in Cybersecurity: Insights from Abul Kalam Azad

The ransomware is reportedly being distributed through phishing emails and social engineering tactics. 

Moreover, the peddlers of this malware were spotted selling it on data breach marketplaces too. 

BlackSnake ransomware doesn’t bite Turkey, Azerbaijan 

“The BlackSnake ransomware encryption process consists of several stages. In the first step, the malware employs a string_Builder() function to generate a 40-byte random string,” said the Cyble report.  

“Next, it retrieves a pre-defined RSA public key that is hard-coded within the malware file. This key encrypts the previously generated random string, producing a key suitable for AES encryption.” 

After obtaining the key, the malware utilizes the AES algorithm to encrypt all the files found in the directory, and then adds the generated key (encoded in base64) to the end of each encrypted file. 

The sample with the hash e4c2e0af462ebf12b716b52c681648d465f6245ec0ac12d92d909ca59662477b has been subjected to static analysis, revealing that it is a 32-bit PE binary compiled using .NET. This information is presented in a figure. 

Once executed, the BlackSnake Ransomware carries out an initial check to determine if the system’s current input language matches the language codes “az-Latn-AZ” or “tr-TR”.  

If there is a match, the ransomware ends its operation, suggesting that the creators of BlackSnake ransomware have no intention of targeting systems located in Turkey or Azerbaijan, found Cyble researchers. 

BlackSnake Ransomware
Image courtesy: Cyble

BlackSnake ransomware and choosy encryption 

BlackSnake is said to have a unique encryption mechanism, making it difficult to detect and decrypt files. The ransomware also has the capability to evade security measures and disable antivirus software on infected systems. 

Once a system is infected, the ransomware encrypts all files and demands a ransom in exchange for the decryption key.

The ransom note left behind by Blacksnake warns victims not to attempt to recover their files without paying the ransom, as doing so could result in the permanent loss of their data. 

Interestingly, it avoids infecting devices that it has already bitten. According to Cyble, it may be an attempt to limit the impact of the ransomware.   

“The BlackSnake ransomware has a method of detecting whether it has already infected a system. It does this by checking the location of the executing assembly with the path “C:\Users[user-name]\AppData\Roaming\svchost.exe”,” said the Cyble report. 

“If this path matches, the ransomware continues to search for the file named “UNLOCK_MY_FILES.txt” in the %appdata% directory. Once the file is found, the ransomware will terminate itself.” 

BlackSnake and Chaos: The origin story 

Threat actors find it convenient to build on pre-existing ransomware codes for developing new ransomware families, noted Cyble.   

“Onyx and Yashma ransomware families were already linked to the Chaos ransomware family, and the BlackSnake ransomware is another family now associated with the strain,” said the Cyble report.  

“The Threat Actor has tweaked the Chaos ransomware source code and added a clipper module directly into the file, which is different from the usual approach of having a separate file for the clipper.” 

A Breach Forum user with the alias “BlackSnakeTeam”, which joined the data breach forum in August 2022, has been found offering the ransomware strain, with a demand of only “15% of your profits”. 

This is the only post the user has made on the forum, as on 10 March, 2023. Interestingly, a thread on Chaos ransomware builder was listed as a possibly related thread to the post.   

Chaos was in the cybersecurity news recently, when a new, Go-based, multiplatform strain that bears no resemblance to its previous version came to light in September 2022.  

“While analyzing the IP address of a staging server hosting additional modules, we noted it had an abnormal self-signed certificate that displayed the organization name of “Chaos”,” said a threat assessment report by Black Lotus Labs, the threat intelligence division of Lumen Technologies. 

“We then searched for IP addresses with similar self-signed certificates that contained the word “Chaos” in the organization name and discovered 15 active nodes at the time.

The earliest certificate was generated on April 16, 2022; we assess this was when the Chaos activity cluster was first launched in the wild,” the report added.

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Tags: BlackSnake Ransomware
Previous Post

YouTube Vanced Android App Spoofed to Launch Nexus Malware to Steal Banking Data

Next Post

Online Platforms to Learn Cybersecurity in 2023 | Free and Paid

Editorial

Editorial

The Cyber Express is a publication that aims to provide the latest news and analysis about the information security industry. The news comes from a variety of sources and is updated regularly so that readers can stay up to date with the latest happenings in this rapidly growing field.

Related Posts

TrickMo Banking Trojan
Dark Web News

TrickMo Banking Trojan Resurfaces with New Features, Targeting Android Devices this Time Around

by Editorial
December 5, 2023
Vietnam Electricity data breach
Firewall Daily

BlackCat Ransomware Strikes Ho Chi Minh City Power Corporation

by Ashish Khaitan
December 4, 2023
cybersecurity
Firewall Daily

Emerging Trends and Challenges in Cybersecurity: Insights from Abul Kalam Azad

by Augustin Kurian
December 4, 2023
Spyroid Rat Android RAT
Dark Web News

Unmasking Spyroid Rat: An In-Depth Look at the Menacing Android RAT

by Ashish Khaitan
December 4, 2023
MIRLE Group cyberattack
Firewall Daily

MIRLE Group Targeted by Notorious LockBit Ransomware Group

by Ashish Khaitan
December 4, 2023
Next Post
Online Platforms to Learn Cybersecurity in 2023 Free and Paid

Online Platforms to Learn Cybersecurity in 2023 | Free and Paid

Latest Issue is Out. Subscribe Now

Cybersecurity Magazine



Follow Us On Google News

Latest Cyber News

Vietnam Electricity data breach
Firewall Daily

BlackCat Ransomware Strikes Ho Chi Minh City Power Corporation

December 4, 2023
cybersecurity
Firewall Daily

Emerging Trends and Challenges in Cybersecurity: Insights from Abul Kalam Azad

December 4, 2023
Spyroid Rat Android RAT
Dark Web News

Unmasking Spyroid Rat: An In-Depth Look at the Menacing Android RAT

December 4, 2023
MIRLE Group cyberattack
Firewall Daily

MIRLE Group Targeted by Notorious LockBit Ransomware Group

December 4, 2023

Categories

Web Stories

Top 10 CISOs to Follow in 2023
Top 10 CISOs to Follow in 2023
Top 10 Ransomware Gangs in 2023
Top 10 Ransomware Gangs in 2023
Top 5 IoT Security Risks in 2023
Top 5 IoT Security Risks in 2023
Top 10 CTF Platforms in 2023
Top 10 CTF Platforms in 2023
Types of Risks Covered by Cyber Insurance
Types of Risks Covered by Cyber Insurance

About

The Cyber Express by Cyble

#1 Trending Cybersecurity News and Magazine

The Cyber Express  by Cyble is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

For Events & Conferences related information: [email protected]

 

Quick Links

  • About Us
  • Advertise With Us
  • Contact Us
  • Editorial Calendar

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News
  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • Products
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Top 10 CISOs to Follow in 2023 Top 10 Ransomware Gangs in 2023 Top 5 IoT Security Risks in 2023 Top 10 CTF Platforms in 2023 Types of Risks Covered by Cyber Insurance