logo

Kasseika Ransomware Linked to BlackMatter in BYOVD Attack

ID: a733a5f9-971e-5b4c-a22d-7ca74d7e3b33

STIX ID: report--a733a5f9-971e-5b4c-a22d-7ca74d7e3b33

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-01-24

Date Updated: 2026-05-05

Author: Elizabeth Montalbano, Contributing Writer

...
...

Trend Micro researchers observed the Kasseika ransomware — apparently using BlackMatter-derived code — employing a bring-your-own-vulnerable-driver (BYOVD) attack that abuses the Martini.sys driver to terminate antivirus/security processes and facilitate ransomware deployment. The attack chain included phishing for credentials, remote administration tools and PsExec for lateral movement and payload execution, a Themida-packed 32-bit PE that encrypts files with ChaCha20 and RSA, drops a CBhwKBgQD.README.txt ransom note, changes the wallpaper, and clears Windows event logs; recommended defenses include least privilege, updated security products, regular backups, phishing protections, and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.