Site icon TheCyberThrone

Crysis Ransomware Exploits RDP to Distribute Venus Ransomware

Advertisements

Researchers have found that the operators of Crysis ransomware are actively utilizing the Venus ransomware in their operations.

Both Crysis and Venus are well-known for targeting remote desktop services that are externally exposed, and it has been revealed that the attacks are being launched via RDP by the security logs.

Apart from this, Crysis and Venus are not alone, as the threat actor also deployed several other tools like:-

While such malicious tools can also target the infected systems within the internal network of the company. 

Advertisements

Upon getting access, the attackers first attempted to encrypt the infected systems with Crysis ransomware. However, after failing to do so, the second attempt at encryption was done using the Venus ransomware.

If the Crysis ransomware encrypts the files, the victims are shown a ransom note with an onion email address to contact the threat actors. If the files are encrypted using Venus ransomware, a message stating that threat actors stole information from the system and urging the users to make contact within 48 hours is displayed.

Venus ransomware terminates various programs such as office, email clients, and databases during the encryption process.

Advertisements

Here below are the tools that are used in the attacks:

Threat actor copies files to the Download folder, including bild.exe_ for Venus ransomware, and to encrypt additional files it terminates the following things:-

On successful deployment, the Venus ransomware alters the desktop, and then it presents the user with a README file that warns info is stolen, files encrypted, and prompts users to establish contact within 48 hours.

Steps to ensure protection

Advertisements

As the use of RDP connections grow exponentially, hackers are relentlessly carrying remote desktop protocol attacks to access and exploit enterprise networks. Organizations must follow easy-to-implement methods to prevent such attacks. This involves implementing multi-factor authentication across all devices and systems, monitoring RDP server logs frequently, and changing default credentials with strong passwords.

Indicators of Compromise

Exit mobile version