216.73.217.22

Embargo ransomware: Rock'n'Rust

· Published 23/10/2024 22:35 · Modified 24/10/2024 10:21

Export JSON

Essential information

Published
23/10/2024 22:35
Modified
24/10/2024 10:21
Tags
2024-10-23 byovd edr killer embargo ransomware mdeployer ms4killer raas ransomware rust safe mode abuse
Related entities
1 intrusion sets (apt), 14 techniques (mitre), 3 malware, 1 others

Description

ESET researchers have uncovered new -based tools used by the group. The toolkit includes , a loader that deploys and , and , an that exploits a vulnerable driver. Embargo, first observed in June 2024, is a relatively new player in the scene that targets both Windows and Linux systems. The group's tools are actively developed and customized for each victim. abuses Safe Mode to disable security solutions, while terminates security product processes using the Bring Your Own Vulnerable Driver technique. The analysis reveals ongoing development and adaptation of the tools during intrusions, suggesting the attackers can quickly modify and recompile their toolkit.

External references