Fake Zoom Ends in BlackSuit Ransomware
Essential information
- Published
- 31/03/2025 05:40
- Modified
- 31/03/2025 15:56
- Tags
- 2025-03-31 blacksuit brute ratel cobalt strike d3f@ckloader exfiltration lateral movement proxy qdoor ransomware sectoprat
- Related entities
- 32 techniques (mitre), 6 malware
Description
A malicious website mimicking Zoom led to the installation of a trojanized installer, initiating a multi-stage attack. The initial payload, d3f@ckloader, downloaded additional components, including SectopRAT. After nine days, the threat actor deployed Brute Ratel and Cobalt Strike beacons for lateral movement. They used various techniques for discovery and credential access, including LSASS memory dumping. The attacker employed QDoor for proxying RDP connections, facilitating data collection and exfiltration via the cloud service Bublup. The intrusion culminated in the deployment of BlackSuit ransomware across multiple systems using PsExec, with a total time to ransomware of 194 hours over nine days.