1. Executive summary
Modern software is assembled, not written. A single application routinely draws on hundreds of third-party components, pulled in on demand and updated continuously as part of normal process. That convenience has quietly become a dependable initial-access route that bypasses traditional perimeter and endpoint defenses. Rather than breaching a hardened production perimeter, adversaries increasingly compromise the developer, the maintainer account, the build pipeline, or the p
Modern software is assembled, not written. A single application routinely draws on hundreds of third-party components, pulled in on demand and updated continuously as part of normal process. That convenience has quietly become a dependable initial-access route that bypasses traditional perimeter and endpoint defenses. Rather than breaching a hardened production perimeter, adversaries increasingly compromise the developer, the maintainer account, the build pipeline, or the package registry — and let trusted automation carry their code the rest of the way.
RDS | Investigação Defensiva & Perícia OSINT — Rogério Souza (@RDSWEB)
RDS · @RDSWEB · Investigação Digital Defensiva
Prova digital que resiste ao contraditório.
"Quem não controla a informação, vira alvo dela." Investigação defensiva, OSINT, CTI e SOCMINT aplicados à defesa técnica — para advogados, departamentos jurídicos e compliance corporativo.
Falar no WhatsApp
Ver no LinkedIn
Perfil
Sobre Rogério
"Quem não controla a informação, vira alvo dela." Investigação defensiva, OSINT, CTI e SOCMINT aplicados à defesa técnica — para advogados, departamentos jurídicos e compliance corporativo.
Toda decisão estratégica nasce da mesma pergunta: quem sabe mais, decide primeiro. Rogério Souza atua na linha de frente da ciberinteligência, cibersegurança e contraespionagem, transformando dados dispersos em vantagem decisória para quem não pode se dar ao luxo de ser surpreendido.
Com especialização em Segurança da Informação pela ULT Grupo América, construiu sua trajetória em parceria com a MPSafe CyberSecurity & CounterEspionage e com atuação junto ao CIASC — Centro de Informática e Automação do Estado de Santa Catarina, somando-se a diversos cases de sucesso em investigação digital, due diligence e proteção de marca para clientes corporativos e jurídicos. Opera como Analista de Open Source Intelligence (OSINT) — planejando e conduzindo operações de coleta de informação, mitigação de risco e produção de inteligência estratégica nas frentes política, militar, econômico-financeira, criminal, social e de contrapropaganda. Para o C-level, isso se traduz em cenários antecipados antes de virarem crise, leitura profunda do ambiente competitivo e decisões blindadas por inteligência verificável — não por achismo.
Sua trajetória inclui vivência em cyber comando privado, com estágio internacional e participação em operações globais de caráter cibernético, antecipando e neutralizando anormalidades, crimes cibernéticos e ataques, com identificação de agentes e grupos. Atua na instrução de fontes abertas (OSINT) e, a convite, apoia ações de polícia e agências governamentais nacionais e internacionais — um nível de confiança que poucos profissionais do mercado carregam.
Faz parte do time de instrutores do Criminal Player, a maior comunidade de direito criminal do Brasil, formando advogados e profissionais do direito em investigação digital, prova técnica e metodologia OSINT aplicada ao processo penal. É autor de curso e apresentação técnica sobre Open Source Intelligence (OSINT), utilizada como material de referência para formação de investigadores e defensores técnicos.
Sua atuação é construída em rede: parcerias recorrentes com advogados criminalistas, peritos e demais profissionais de cybersecurity, CTI, InfoSec e SOCMINT para a resolução conjunta de casos complexos — combinando profundidade técnica investigativa com defensibilidade jurídica em cada entrega.
Tem experiência consolidada em compliance e mitigação de risco, apoiando empresas e escritórios na antecipação de exposições reputacionais, regulatórias e probatórias antes que se tornem contencioso. Atendimento 100% virtual, para todo o Brasil.
Atuação
Frentes de Investigação Defensiva
Processo Penal
Investigação defensiva
Coleta e análise técnica de provas favoráveis à defesa, com metodologia documentada e rastreável, pronta para o contraditório.
Perícia
Cadeia de custódia digital
Preservação e documentação de evidências digitais com integridade probatória, do primeiro contato ao laudo final.
Inteligência
OSINT, CTI & SOCMINT
Inteligência de fontes abertas, ciclo formal de inteligência e Diamond Model aplicados a investigações e due diligence.
Formação
Treinamento jurídico e institucional
Capacitação de advogados e forças de aplicação da lei em investigação digital, via Criminal Player e programas próprios.
Corporativo
Compliance & mitigação de risco
Due diligence, identificação de exposição digital e planos de mitigação antes da judicialização ou crise reputacional.
Colaboração
Rede multidisciplinar
Atuação conjunta com advogados, peritos e especialistas em cybersecurity/infosec para casos de alta complexidade.
Impacto Organizacional
Por que investigação defensiva importa para a empresa
CEO / BoardContinuidade e risco reputacional sob controle antes de virar manchete.
JurídicoProvas tecnicamente defensáveis e aderentes à LGPD.
ComplianceDue diligence e evidência estruturada para decisões regulatórias.
CFOExposição financeira mapeada antes da escalada do litígio.
AuditoriaRastreabilidade de evidências e cadeia de custódia documentada.
RHIdentificação de risco interno com abordagem discreta e legal.
Credenciais
Formação e Trajetória
› Especialização em Segurança da Informação — ULT Grupo América
› Ciberinteligência, Cibersegurança e Contraespionagem — em parceria com a MPSafe CyberSecurity & CounterEspionage
› Atuação junto ao CIASC — Centro de Informática e Automação do Estado de Santa Catarina
› Diversos cases de sucesso em investigação digital, due diligence e proteção de marca para clientes corporativos e jurídicos
› Instrutor de investigação digital — Criminal Player (maior comunidade de direito criminal do Brasil)
› Autor de curso e apresentação técnica sobre OSINT (RDSWEB)
› Estágio internacional em cyber comando privado e operações globais de inteligência proativa
› Rede de colaboração com advogados, peritos e especialistas em CTI/InfoSec/SOCMINT
Dúvidas
Perguntas Frequentes
O que é investigação defensiva?
É a coleta, análise e documentação técnica de provas digitais e de fontes abertas a favor da defesa em processos judiciais, administrativos ou de compliance, sempre observando cadeia de custódia e legalidade probatória.
Como o OSINT é usado como prova técnica em um processo?
Dados publicamente disponíveis são coletados, correlacionados e documentados com metodologia rastreável, permitindo que o laudo seja submetido ao contraditório e resista a questionamentos técnicos da parte contrária.
O atendimento é presencial?
Não. O atendimento é 100% virtual, para advogados, escritórios e empresas em todo o Brasil, via WhatsApp e videochamada.
The EclecticIQ AI features have already been helping you work faster and smarter, from using AI assistant as your on-demand research partner, to querying complex data sets using NLP search, aligning requirements with Intelligence Compass, and extracting key entities with AI entity extraction. With the upcoming 3.6 release of Intelligence Center, we’re expanding the EclecticIQ AI Suite with the productivity-boosting features: Summarization , Content generation with templates and Translation. The
The EclecticIQ AI features have already been helping you work faster and smarter, from using AI assistant as your on-demand research partner, to querying complex data sets using NLP search, aligning requirements with Intelligence Compass, and extracting key entities with AI entity extraction. With the upcoming 3.6 release of Intelligence Center, we’re expanding the EclecticIQ AI Suite with the productivity-boosting features: Summarization , Content generation with templates and Translation. These tools are built to help you move faster, go broader, and stay focused on what matters most.
The cybersecurity landscape isn’t slowing down, and neither should your security operations. With EclecticIQ Intelligence Center 3.5, we’re delivering a breakthrough release that enhances AI-embedded investigations, enables streamlined intelligence management, and unlocks precision threat prioritization. Analysts can now navigate the platform more efficiently, extract insights faster, and provide actionable intelligence for decision-makers - all in one seamless experience.
The cybersecurity landscape isn’t slowing down, and neither should your security operations. With EclecticIQ Intelligence Center 3.5, we’re delivering a breakthrough release that enhances AI-embedded investigations, enables streamlined intelligence management, and unlocks precision threat prioritization. Analysts can now navigate the platform more efficiently, extract insights faster, and provide actionable intelligence for decision-makers - all in one seamless experience.
Introduction
This blog is
part of a cyber threat intelligence (CTI) blog series called Tracking
Adversaries that investigates prominent or new threat groups.
The focus of
this blog is EvilCorp, a sanctioned Russia-based cybercriminal enterprise known
for launching ransomware attacks, and RansomHub, a prominent ransomware as a
service (RaaS) operation run by Russian-speaking cybercriminals.These two threat groups have been linked together through cooperation on intrusions and IOCs and TTPs sha
This blog is
part of a cyber threat intelligence (CTI) blog series called Tracking
Adversaries that investigates prominent or new threat groups.
The focus of
this blog is EvilCorp, a sanctioned Russia-based cybercriminal enterprise known
for launching ransomware attacks, and RansomHub, a prominent ransomware as a
service (RaaS) operation run by Russian-speaking cybercriminals.
These two threat groups have been linked together through cooperation on intrusions and IOCs and TTPs shared by multiple CTI sources. The implication of this link is critical due to RansomHub being the most active ransomware gang and is working with a well-known sanctioned affiliate.
Who is RansomHub?
Active since
February 2024, RansomHub
is a RaaS operation formerly known as Cyclops and
Knight and is run by Russian-speaking adversaries. It is currently used by more and more cybercriminals that are ex-affiliates
of other RaaS operations. This includes the ALPHV/BlackCat RaaS and the LockBit
RaaS, which have since shutdown or disappeared. This has made the RansomHub RaaS one
of the most widespread ransomware families as of early 2025.
Due to
having a high number of affiliates, the tools and TTPs observed before the
final RansomHub payload is deployed can vary significantly.
Each affiliate may have their own set of tools and TTPs to achieve the final
objectives of data exfiltration and ransomware deployment.
Who is EvilCorp?
Evil Corp is
an international cybercrime network sanctioned for
orchestrating large-scale financial cyberattacks led by Maksim Yakubets. EvilCorp’s operations have evolved over time, expanding from Dridex
banking trojan campaigns into developing
ransomware like BitPaymer, WastedLocker, Hades, PhoenixLocker, and MacawLocker.
Notably,
Aleksandr Ryzhenkov, was identified
by the National Crime Agency (NCA) as a high-ranking member of EvilCorp and
also LockBit affiliate. Ryzhenkov became a LockBit affiliate around 2022, contributing to over 60
LockBit ransomware builds and attempting to extort more than $100 million from
victims. This discovery aligns with Mandiant’s previous reporting
on EvilCorp shifting to LockBit as well.
The NCA also
found that EvilCorp maintains close ties with Russian intelligence agencies
through Yakubets' father-in-law, Eduard Bendersky, a former FSB officer, who is
suspected of using his influence to shield the group from prosecution in Russia.
One of the
TTPs that makes EvilCorp standout from the rest of the RaaS affiliates is their
own affiliation
to the SocGholish
JavaScript malware (aka FAKEUPDATES). If ransomware deployment takes place
following a SocGholish infection, then the attackers responsible for the attack
will be affiliated with EvilCorp.
Reported Connections Between EvilCorp and RansomHub
On 15 July
2024, Microsoft shared a post on X stating that RansomHub was
observed being deployed in post-compromise activity by Manatee Tempest (which is Microsoft’s name for
EvilCorp) following initial access via SocGholish (aka FakeUpdates) infections
(which Microsoft tracks as Mustard Tempest).
On 15
January 2025, Guidepoint wrote a blog on a new Python backdoor used by an
affiliate of RansomHub. Notably, the new Python backdoor was delivered by
SocGholish. Therefore, this Python backdoor is another potential artifact worth
monitoring for its connection to known EvilCorp-related malware.
The next
day, on 16 January 2025, Google shared a report on EvilCorp (which Google tracks as
UNC2165) that disclosed numerous tools and malware families they have been using to deliver RansomHub, including a Python
backdoor dubbed VIPERTUNNEL (see the image below). The presence of a Python
backdoor following a SocGholish infection is notable TTP that overlaps with the
Guidepoint blog on RansomHub.
On 14 March
2025, Trend Micro disclosed further details that also confirmed the
SocGholish malware is leading to the deployment of RansomHub ransomware. The
operators of SocGholish are tracked as Water Scylla by Trend Micro. The
operators distribute SocGholish via the Keitaro Traffic Direction System (TDS), a legitimate service used for marketing campaigns. Trend Micro
also observed SocGholish dropping the same custom Python backdoor (aka
VIPERTUNNEL) as well.
So What?
EvilCorp has been under US sanctions since 2019, making it
illegal for affected organisations to pay ransoms to them without facing
potential fines from the US Treasury’s Office of Foreign Assets Control (OFAC).
Despite these sanctions, EvilCorp has continued its cybercriminal activities by
adapting its tactics to include rebranding their ransomware and becoming an affiliate of RaaS operations, such as LockBit and RansomHub.
The key indicator of EvilCorp's involvement in ransomware attacks continues to be the
use of the SocGholish malware, which employs drive-by downloads masquerading as web browser software updates to gain initial access to systems.
EvilCorp’s affiliation with RansomHub raises the
possibilities that RansomHub may soon face sanctions similar to those imposed
on EvilCorp. Consequently, any victim that pays a ransom to RansomHub could
become significantly riskier for cyber insurance organisations, incident
responders, and ransomware negotiators, as they may inadvertently violate
sanctions and face legal repercussions.
Given EvilCorp's prominence as a target for international
law enforcement, its association with RansomHub is likely to draw increased
scrutiny. This could result in RansomHub becoming the focus of future law
enforcement actions, including potential takedowns and additional sanctions,
further complicating the landscape for entities involved in ransomware response
and mitigation.
There is also the increased likelihood that RansomHub will
now rebrand. As we saw in the BlackBasta
Leaks, ransomware groups pay close attention to the news, CTI reports, and
even posts on X and even blogs by researchers. This association to EvilCorp and
threat of sanctions is an issue for ransomware groups as it impacts their
business model and makes earning harder. Therefore, by linking the two entities together CTI analysts can impose cost on these cybercriminals.
Europe faces a critical juncture. Geopolitical tensions are rising, and cyber threats are growing more sophisticated. This reality has made cybersecurity a vital part of Europe’s defense strategy, along with the defense strategies of the entire world. The European Commission’s ReArm Europe/Readiness 2030 initiative, which proposes a €150 billion investment in defense (including a dedicated €3.5 billion cybersecurity fund as noted in President von der Leyen’s 3 March statement), demonstrates that
Europe faces a critical juncture. Geopolitical tensions are rising, and cyber threats are growing more sophisticated. This reality has made cybersecurity a vital part of Europe’s defense strategy, along with the defense strategies of the entire world. The European Commission’s ReArm Europe/Readiness 2030 initiative, which proposes a €150 billion investment in defense (including a dedicated €3.5 billion cybersecurity fund as noted in President von der Leyen’s 3 March statement), demonstrates that there is unprecedented opportunity for unified action.
Now is the time for European cybersecurity companies to come together, strengthen the industry and protect our shared future. The reason is straightforward: Europe can no longer afford to view cybersecurity separately from traditional defense measures.
The BlackBasta ransomware group’s leaked chat logs have proven
to already be another unique and fascinating opportunity for researchers to
better understand the internal operations of a Russia-based organised
cybercrime enterprise. These leaks followed a major leak of Conti chat logs in
2022, which also proved to be a treasure trove of intelligence on the cybercrime
enterprise. The BlackBasta gang consists of former Conti ransomware members and
it should come as no surprise that their operations
The BlackBasta ransomware group’s leaked chat logs have proven
to already be another unique and fascinating opportunity for researchers to
better understand the internal operations of a Russia-based organised
cybercrime enterprise. These leaks followed a major leak of Conti chat logs in
2022, which also proved to be a treasure trove of intelligence on the cybercrime
enterprise. The BlackBasta gang consists of former Conti ransomware members and
it should come as no surprise that their operations are similar in nature and
structure.
Ransomware researchers have several valuable resources to
conduct investigations with nowadays. This includes ransomware.live, which contains several
resources including ransomch.at, a
collection of negotiation chats between ransomware gangs and their victims, as
well as the ransomware
tool matrix and ransomware
vulnerability matrix. These resources allow to deeply understand the
capabilities and motivations of these ransomware gangs. However, leaked chat logs
are the final missing piece of the puzzle and offer a deeper understanding from
the cybercriminal’s very own perspective and organisational structure.
Active since
April 2022, BlackBasta is one of the top-tier ransomware gangs and one of
the largest cybercrime enterprises in the world. According to the US
Cybersecurity Infrastructure and Security Agency (CISA), BlackBasta impacted
up to 500 different businesses and critical infrastructure in North America,
Europe, and Australia as of May 2024.
The importance of the Ascension Health incident
This blog shall dive deep into the Ascension Health attack
by BlackBasta. It is a step-by-step extraction of the conversation between the
BlackBasta members while they decide how to handle the attack.
The new insights around how BlackBasta and other ransomware
gangs perceive being involved with incidents at healthcare sector victim should
prove useful for incident responders, law enforcement, and governments that have
to resolve these types of attacks on the healthcare sector on an alarmingly
regularly basis.
Background
On 9 May 2024, mainstream news organisations in the US
reported about a cyberattack and significant disruption of services of
Ascension Health, one of the largest healthcare providers in the country. On 11
May 2024, BleepingComputer
reported that BlackBasta was to blame for the attack on Ascension Health and
that ambulances had been disrupted and patients were being redirected to other
hospitals.
How the Incident Began
The BlackBasta attack on Ascension Health began many months
before the ransomware was deployed on their network. Reconnaissance of
Ascension Health by members of BlackBasta began around 3 November 2023. They shared
14 email addresses of Ascension Health employees, which we can only assume were
used for phishing or password guessing. Ransomware gangs often used Zoominfo to
profile their targets to determine whether it is worth it for them to attack
and get a ransom from them.
The ransomware gang themselves wrote in their Matrix chat
that CBS
News had written about a cyberattack on Ascension Health on 9 May 2024 and
exclaimed that “it looks like one of the largest attacks of the year.”
Another BlackBasta member “gg” confirmed in the chat that it
was them and appeared to be surprised that the news was writing about it.
Later, “gg” appeared to feel bad about the attack and
concerned that cancer patients were suffering. However, at this stage it is
hard to tell if they are serious or being sarcastic.
One member of BlackBasta who used the moniker “tinker” then
stated that he wanted to be the negotiator for the BlackBasta team and began to
strategize how to extract a ransom payment.
“gg” says they encrypted Ascension Health’s network using
the Windows Safe Mode Boot
technique, which is a function that BlackBasta
is well-known to do.
The negotiator, “tinker” begins to weigh up their options.
He states he believes the FBI and CISA will be involved, as well as Mandiant
and begins to compare the incident to the Change
Healthcare attack by ALPHV/BlackCat (and later RansomHub) who received a 22
million USD ransom payment.
“gg” shares that all the stolen data was put on a server
named “ftp8” and tagged as “ALBIR_DS” and says to “tinker” that he should “look
at the folder name, everything we downloaded from them is there."
The operator, “gg” also shared a summary of the target
environment of Ascension Health. This includes number of servers being over
12,000, what security tools they use such as Cylance, Tanium, and McAfee. Plus,
“gg” said they downloaded over 1.4TB of data to "ftp8" and used
BlackBasta ransomware version 4.0 and attacked them on 8 May 2024.
Interestingly, “gg” appears to have also recommended to
bluff to the victim that they stole more than 1.5TB and say to the victim that
they stole 3TB instead.
Negotiation Strategizing
After having established the details of the incident, Tinker
(the negotiator) began to wonder about the likelihood of getting a ransom
payment as well as estimate how much Ascension Health is likely losing per day.
Tinker (negotiator) then explains to the rest of the BlackBasta members involved in the attack what course of action they should take to get the ransom from Ascension Health. Tinker says they would normally set a 3% of the annual revenue and negotiate from there. They note that there are clear problems with the victim being a hospital and that this attack followed the Change Health attack by ALPHV/BlackCat. They also noted that they are worried as they believe the US National Security Agency (NSA) attacked TrickBot's servers four years ago and that the FBI took down Qakbot more recently. Tinker is also worried that one of Ascension Health’s patients will die and they will be blamed and labelled as a terrorist attack.
Tinker also noted that when BlackSuit attacked Octapharma that it was labelled by the news as "hostile actions by Russia" and they warned that Conti was already under sanctions and that because they are tied to Conti they may not get paid.
Tinker, ransomware negotiator for BlackBasta, ultimately recommended giving the decryptor for free to Ascension Health and resorting to data theft extortion. This is notable, as it is a similar situation to the Irish HSE ransomware attack by Conti, who also provided the decryptor for free.
Healthcare Impact
The fact Ascension Health is a major medical organisation
with many patients appeared to take its toll on the BlackBasta members. Tinker
wrote in the BlackBasta chat they he found a post on Reddit by a doctor that
works for Ascension Health who described the damage of the attack.
Another member of BlackBasta, “nn” also found out that
Ascension Health is a group of hospitals. He immediately recommends giving them
a decryptor for free.
Interestingly, “gg” compares the attack on Change Health and
also recognises Mandiant and warns that the FBI and CISA will be involved.
Plus, “gg” noted that they did not encrypt via virtualization (such as vCenter,
ESXi or Hyper-V) and reconfirmed they used Safe Mode Boot. Further, “gg” was
also inclined to give Ascension the decryptor for free too.
Another BlackBasta member, “nickolas” comments about the
situation. He warned and was particularly concerned about law enforcement
retaliation, such as hacking back, sanctions, indictments. He recommended
auditing the entire infrastructure and having a rebrand of the BlackBasta name,
which means changing the ransomware, leak site, and other personas.
Tinker (negotiator) is aware however of the risk of someone
dying and how it will impact their chances of getting the ransom.
Tinker also discussed the politics of the scenario. He
compared the situation to the colonial pipeline incident of 2021. He mentioned
how Russia reacted and arrested ransomware operators. He also brought up the
war in Ukraine and how ransomware attacks on the US impact the politics with
Russia.
Tinker highlighted that the ransomware was used to encrypt
patient data and how it caused the hospital management system to crash. He was
particularly concerned about the ambulances being unable to operate but also
tries to minimize the severity of the incident. Nevertheless, he asked to see
the stolen data himself to get a better understanding of what data BlackBasta
operators have that they can leverage against Ascension Health.
By the end of deliberations, Tinker recommends giving a free
decryptor and then demand a ransom for the stolen data.
tinker edited his message to then clarify that he reckons
they should demand a ransom in the 10s of millions USD or over 100 million USD.
Ransomware Negotiations
The operator “gg” then shared the opening message to
Ascension Health shared via the Black Basta negotiation portal:
The negotiator for Ascension Health (who BlackBasta believes
is Mandiant) replied to the negotiation chat portal:
“gg” then clarified the terms of the ransom demand. A
payment will be needed to delete and share the stolen data He maintains the
offer to provide a free decryptor:
The negotiator for Ascension Health asked for the decryption
tool:
The decryptor was then provided to Ascension Health:
Later, “gg” then shares a file tree for
""DS"" (which is equal to Ascension Health). The file is
added to a ZIP and shared via a temp[.]sh link and is password protected:
The operator “gg” then uses Privat (a screenshot sharing
site) to show the proof that they have deleted the data of Ascension Health:
From these messages, it appears no ransom was paid and
BlackBasta returned the data and deleted it.
Change of Heart
The most interesting part of this engagement with Ascension
Health by BlackBasta was that the members deliberated back and forth about
whether to provide a free decryption tool but all appeared to be fine with demanding
a ransom for the victim data.
The operator “gg” appears to have a change of heart. He
exclaims that they (the members of the BlackBasta ransomware gang) are "pentesters"
and not "killers" and claims he “held a meeting in the office” which
is interesting as it further proves they are a cybercrime enterprise,
potentially with full-time employees.
The operator “gg” decided to help Ascension Health and requests
not to work on hospitals anymore.
He also said “the software will fly to the trash” which
likely means the group was thinking of ditching the brand of BlackBasta and
rebrand to another name. Finally, “gg” warns other BlackBasta members not to
target hospitals any more:
The Impact of the BlackBasta Attack on Ascension Health
According to the HIPAA Journal,
the personal data of up to 5.6 million patients was exposed and Ascension
confirmed that some patient data was stolen during the attack. Ascension said that
it found no evidence that the ransomware group gained access to electronic
health records or other clinical systems, so full medical histories have not
been stolen. During the attack, however, Ascension was forced to divert
ambulances, close pharmacies, take critical IT systems offline and resort to
pen and paper to record patient information. The attack affected a large
percentage of its 136 hospitals across the US and took Ascension around 6 weeks
to restore access to its electronic medical record system and resume normal
operations. The ransomware attack reportedly caused delays in revenue cycle
processes, claims submission, and payment processing, in addition to
significant remediation costs.
Lessons Learned
This chat log confirms that BlackBasta attacked Ascension Health
using version 4.0 of their ransomware and used the Safe Mode Boot technique on 12,000
endpoints of the healthcare system.
If reconnaissance began on 3 November 2023 and the attack happened on the 8 May 2024, that would make the amount of time they took to gain access and deploy the ransomware was up to 187 days long or around six months. Due to this, cybercriminal campaign appears to be comparable to a more focused state-sponsored level intrusion where months of planning and numerous attempts are made to infiltrate a target.
The BlackBasta negotiator, Tinker, believed that they were
going to get a very high ransom payment in the 10s of millions or up to 100
million USD and compared the attack to the Change Health incident by ALPHV/BlackCat
who got 22 million USD.
The high ransom payment by Change Health has appeared
to be like a dinner bell for ransomware gangs to go after other healthcare sector
victims. Paying the ransom as a healthcare organisation clearly has significant
downstream impact on the rest of the industry and it should be an absolute last
resort and default to be to never pay the ransom.
There was an interesting change of heart and moment where
the operator “gg” decided to give up on the Ascension Health attack, provide
them a decryptor, provide the data back to them, and share proof that they
deleted it. The members of BlackBasta were clearly concerned about hack-backs
from law enforcement or intelligence services, as well as sanctions and
deanonymization. The BlackBasta team also mentioned several times during this
incident that they were going to have to rebrand because of the attack.
Overall, this incident goes to show that even Russia-based cybercrime
enterprises with dozens of members remain paranoid about being attack by law
enforcement and intelligence services. It is really interesting that they themselves
admit that their actions warrant such a response.
One of the key lessons to learn from this engagement is that
if a healthcare organisation is attacked by a ransomware gang, then it would be
a valid strategy to tell the news about the incident. News about patients lives
being at risk and dying will get the attention of these ruthless cybercriminals
who will realise the mistakes they made and are potentially likely to at least provide a free decryptor and may give up entirely on their ransom payment pursuit and move on to the next target.
Lastly, these chat logs appear to prove that the West’s
policies aimed at increasing pressure on Russia-based ransomware gangs is evidently
working. These organised cybercrime enterprises are beginning to alter their
targeting behaviour as a result to avoid the wrath of law enforcement
retaliation.
Introduction to Infrastructure Pivoting
Pivoting on infrastructure is a handy skill for cyber threat
intelligence (CTI) analysts to learn. It can help to reveal the bigger picture
when it comes to malware, phishing, or network exploitation campaigns. Infrastructure
pivoting essentially is the act of looking for more systems an adversary has
created. The main benefit of this pursuit is the identification of additional
targets or victims, more tools or malware samples, and ultimately new insigh
Pivoting on infrastructure is a handy skill for cyber threat
intelligence (CTI) analysts to learn. It can help to reveal the bigger picture
when it comes to malware, phishing, or network exploitation campaigns. Infrastructure
pivoting essentially is the act of looking for more systems an adversary has
created. The main benefit of this pursuit is the identification of additional
targets or victims, more tools or malware samples, and ultimately new insights
about the adversary’s capabilities.
If done correctly, being able to pivot on adversary
infrastructure will be very useful during incident response (IR) engagements. For
example, it may lead to being able to attribute the intrusion to a known
adversary. This will help others during an IR engagement understand the level
of threat posed to the victim organisation.
Receiving Threat Data
To be able to pivot on adversary infrastructure, threat data
is needed such as the intelligence shared by threat reports put out
by various researchers from public and private sector organisations. This
scenario, however, involves relying on the analysis skills of other researchers to explain
what the infrastructure is and when they observed it in use.
This blog will examine threat data provided by public sector
organisations such as the Computer Emergency Response Team of Ukraine (CERT-UA)
as well as cybersecurity vendors such as Deep Instinct, Cyble, and Fortinet.
These organisations have shared indicators of compromise (IOCs) uncovered
following analysis of adversary intrusion activities or upload to online
malware sandboxes, such as VirusTotal, among others.
Introduction to the Ghostwriter Campaign
On 3 June 2024, Fortinet shared a report
on malicious XLS macro documents leading to Cobalt Strike Beacons. Analysis of
the XLS documents showed that they appeared to be targeting the Ukrainian
military and linked to a known Belarusian state-sponsored APT group tracked as Ghostwriter
(aka UNC1151, UAC-0057, TA445). On 4 June 2024, Cyble also shared a report
on a similar campaign.
In both reports, if the XLS was opened and the macros were executed
by the target, a malicious DLL file was downloaded from an adversary-created domain.
In Fortinet’s report, two similar “.shop” domains were mentioned. In Cyble’s
report another “.shop” domain was also called out.
Overlapping IOCs
The first pivot on Ghostwriter APT infrastructure that will be
demonstrated involves finding indicators of compromise (IOCs) such as domains
and IP addresses that appear in multiple threat reports.
The fastest way to realize these overlaps is through
continuous collection of reported IOCs into a Threat Intelligence Platform
(TIP). This will reveal IOCs that appear in multiple threat reports through
tagging and sources of where IOCs come from. Eventually, one domain or IP
address will get reported by multiple entities and the connection will make
itself apparent.
In Figure 1 (see below) the domain “goudieelectric[.]shop”
appeared in both Cyble’s blog and Fortinet’s blog. Analysis of all three
domains found that they use the same generic top-level domain (gTLD),
registrar, and name servers, as well as have a robots.txt directory configured.
These common infrastructure characteristics indicate that all three domains
were created by the same adversary.
Figure 1. Three similar
domains appearing in two threat reports.
Domain Registration & Hosting Overlaps
When more IOCs are reported in other threat reports it is
possible to link them to other known domains, this is due to adversaries
reusing the same registrars, name servers, and gTLDs.
In Figure 2 (see below), Deep Instinct reported
two more domains that could also be linked to the previous three domains through
the mutual use of the PublicDomainsRegistry registrar, Cloudflare name servers,
and the robots.txt file.
Figure 2. Five
similar domains that appear across three threat reports.
Further, CERT-UA reported three more domains (see
Figure 3 below) that could be linked to the infrastructure cluster through this
same method as well. This pattern of behaviour is a strong indicator that these
domains were created by the same adversary.
Figure 3. Eight similar domains that appear across four threat reports.
Finding Unreported Domains
Since the domains from the above threat reports were
collected and linked together through overlapping attributes, it is now
possible to use these attributes to find more domains that had gone unreported.
Using a VirusTotal domain attribute query, additional domains
can be found by using the following registration pattern:
Name Servers: CLOUDFLARE
Registrar: PublicDomainRegistry
TLD: *.shop
This revealed up to 24 domains that matched this pattern
that were likely created by Ghostwriter, a state-sponsored APT group:
backstagemerch[.]shop
bryndonovan[.]shop
chaptercheats[.]shop
clairedeco[.]shop
connecticutchildrens[.]shop
disneyfoodblog[.]shop
eartheclipse[.]shop
empoweringparents[.]shop
foampartyhats[.]shop
goudieelectric[.]shop
ikitas[.]shop
jackbenimblekids[.]shop
kingarthurbaking[.]shop
lansdownecentre[.]shop
lauramcinerney[.]shop
medicalnewstoday[.]shop
moonlightmixes[.]shop
penandthepad[.]shop
physio-pedia[.]shop
semanticscholar[.]shop
simonandschuster[.]shop
thevegan8[.]shop
twisterplussize[.]shop
utahsadventurefamily[.]shop
Note: VirusTotal domain searches are only available
to VirusTotal Enterprise users. There are other providers which allow you to search
for domain registration patterns such as DomainTools, Validin, and Zetalytics. There
also some free OSINT sites such as nslookup.io
and viewdns.info that can be useful in
certain scenarios.
Finding Related Malware Samples
Using the list of similar domains that were uncovered
through the registration pattern search, it is then possible to find additional
malware samples communicating with them.
This can be achieved by looking at domains in VirusTotal and
checking the Relations tab can show communicating files as shown in
Figure 4 below.
Figure 4. Additional malware samples
uncovered via the VirusTotal relations tab
Using a VirusTotal graph can help to reveal every
communicating file with every domain discovered through the registration pattern
search, as shown in Figure 5 below.
Figure 5. All
communicating files with every additional domain identified.
In conclusion, it is important for CTI analysts to closer
inspect the attributes of the IOCs they come across. It is not uncommon for
state-sponsored APT groups to make such mistakes when creating their
infrastructure to launch attacks from. By exploiting this fact, CTI analysts
can learn much more about the adversary’s targets, capabilities, and the behaviours
of the humans themselves behind such campaigns.
The importance of this type of work was demonstrated in
December 2023 when the US Treasury
sanctioned members of the Russian APT group known as Callisto
(aka Star Blizzard, BlueCharlie, COLDRIVER, GOSSAMER BEAR). The real world
identity of Andrey Korinets was revealed after he was sanctioned for fraudulently
creating and registering malicious domain infrastructure for Russian federal
security service (FSB) spear phishing campaigns.