216.73.217.22

THREAT ANALYSIS: Beast Ransomware

· Published 19/10/2024 14:59 · Modified 21/10/2024 09:53

Export JSON

Essential information

Published
19/10/2024 14:59
Modified
21/10/2024 09:53
Tags
2024-10-19 beast ransomware encryption esxi file-targeting geofencing linux monster multithreading raas self-propagation windows
Related entities
1 intrusion sets (apt), 13 techniques (mitre), 2 malware, 3 others

Description

The group, active since 2022, offers a Ransomware-as-a-Service () platform with constant updates. It supports , , and systems, providing affiliates with customizable binary options. Beast employs advanced methods, including Elliptic-curve and ChaCha20, and features multithreaded file , process termination, shadow copy deletion, and subnet scanning. The ransomware avoids encrypting data in CIS countries and uses SMB scans for . It targets various file formats and creates a unique mutex to prevent multiple instances. The Cybereason Defense Platform offers advanced detection and prevention features against .

External references