216.73.216.6

ShadowRoot Ransomware Targeting Turkish Businesses

· Published 15/07/2024 15:25 · Modified 15/07/2024 15:54

Export JSON

Essential information

Published
15/07/2024 15:25
Modified
15/07/2024 15:54
Tags
2024-07-15 ransomware türkiye
Related entities
3 observables, 9 techniques (mitre), 1 malware, 1 others

Description

An analysis reveals a basic campaign targeting Turkish enterprises. The attack commences with a malicious PDF attachment delivered via email, containing a link that downloads an executable payload. This executable then drops further components, including a .NET binary obfuscated with dotnet confuser. The malware recursively encrypts files with the .shadowroot extension and communicates with a Russian SMTP server. While exhibiting fundamental functionality, this campaign appears to be the work of an inexperienced actor aiming to extort victims through ransom demands.

External references