RansomHouse upgrades encryption with multi-layered data processing
ID: 9b088d04-3afa-5f5a-bdb5-2efe71ab8632
STIX ID: report--9b088d04-3afa-5f5a-bdb5-2efe71ab8632
Feed Name: Bleeping Computer
Unit 42 reports that the RansomHouse RaaS operation upgraded its encryptor (called 'Mario') to a two-stage transformation using a 32-byte primary and 8-byte secondary key, dynamic chunk sizing (with an 8GB threshold), intermittent encryption, improved memory/buffer layout, and expanded file processing telemetry. The variant targets VM files (renaming encrypted files with a .emario extension and dropping a “How To Restore Your Files.txt” ransom note), has been used alongside tools like MrAgent to impact VMware ESXi environments, and has been linked to extortion activity against victims including Askul Corporation; researchers warn the changes increase encryption entropy, complicate static analysis and decryption efforts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
