BadRabbit: spread of new cryptolocker
ID: 6c42edca-7b86-542f-89f5-d5de4976057d
STIX ID: report--6c42edca-7b86-542f-89f5-d5de4976057d
Feed Name: Group-IB Blog
On 24 October a widespread BadRabbit ransomware campaign infected organizations across Ukraine, Russia and several other countries by compromising legitimate media sites and presenting a fake Flash Player update that downloaded install_flash_player.exe (MD5 FBBDC39AF1139AEBBA4DA004475E8839). Victims included critical infrastructure (Kiev metro, Ministry of Infrastructure, Odessa Airport) and media sites; the malware demands 0.05 BTC via a Tor-based payment site, contains SMB propagation capabilities, uses Mimikatz to harvest credentials for lateral movement, and shares code similarities with NotPetya. The report provides IOCs (domains such as 1dnscontrol.com and caforssztxqzf2nm.onion, IPs, bitcoin wallets), technical analysis, and mitigation guidance (create C:\windows\infpub.dat kill-switch, isolate infected hosts, block IOCs, update systems, back up data).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
