Kasseika Ransomware Linked to BlackMatter in BYOVD Attack
ID: a733a5f9-971e-5b4c-a22d-7ca74d7e3b33
STIX ID: report--a733a5f9-971e-5b4c-a22d-7ca74d7e3b33
Feed Name: Dark Reading
Date Published: 2024-01-24
Date Updated: 2026-05-05
Author: Elizabeth Montalbano, Contributing Writer
Trend Micro researchers observed the Kasseika ransomware — apparently using BlackMatter-derived code — employing a bring-your-own-vulnerable-driver (BYOVD) attack that abuses the Martini.sys driver to terminate antivirus/security processes and facilitate ransomware deployment. The attack chain included phishing for credentials, remote administration tools and PsExec for lateral movement and payload execution, a Themida-packed 32-bit PE that encrypts files with ChaCha20 and RSA, drops a CBhwKBgQD.README.txt ransom note, changes the wallpaper, and clears Windows event logs; recommended defenses include least privilege, updated security products, regular backups, phishing protections, and user training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
