Security News > 2022 > November > Russia-based RansomBoggs Ransomware Targeted Several Ukrainian Organizations

Russia-based RansomBoggs Ransomware Targeted Several Ukrainian Organizations
2022-11-26 04:28

Ukraine has come under a fresh onslaught of ransomware attacks that mirror previous intrusions attributed to the Russia-based Sandworm nation-state group.

Slovak cybersecurity company ESET, which dubbed the new ransomware strain RansomBoggs, said the attacks against several Ukrainian entities were first detected on November 21, 2022.

"While the malware written in.NET is new, its deployment is similar to previous attacks attributed to Sandworm," the company said in a series of tweets Friday.

The development comes as the Sandworm actor, tracked by Microsoft as Iridium, was implicated for a set of attacks aimed at transportation and logistics sectors in Ukraine and Poland with another ransomware strain called Prestige in October 2022.

The RansomBoggs activity is said to employ a PowerShell script to distribute the ransomware, with the latter "Almost identical" to the one used in the Industroyer2 malware attacks that came to light in April.

ESET's analysis of the new ransomware shows that it generates a randomly generated key and encrypts files using AES-256 in CBC mode and appends the ".


News URL

https://thehackernews.com/2022/11/russia-based-ransomboggs-ransomware.html