----------------
🦠 Malware Analysis
===================
Settra is a ransomware operation first identified in June 2026 that has already claimed 50-70+ enterprise victims across technology, manufacturing, financial services, healthcare, and retail sectors. The group operates double-extortion: data exfiltration followed by encryption and ransom negotiation via Tox and darknet portals.
🔹 Intrusion Methodology
Human-operated intrusions begin through compromised VPNs or valid accounts. Credential dumping uses Mimikatz and ProcDump. Lateral movement relies on dual-use tools including PAExec and NetExec. Durable remote access is established via Mesh Agent.
Before encryption, operators abuse signed STProcessMonitor drivers via BYOVD to blind endpoint defenses.
🔹 Encryptor Architecture
The encryptor is a two-stage design recovered through offline static reverse engineering by Cynet Research Labs.
Outer loader (win64.exe):
• Password-gated entry
• PEB export hashing for API resolution
• Anti-debugging gates
• ~200,000-round SHA-256 KDF for key derivation
• AES-256-CTR decryption of inner payload
• Custom LP77 decompression
• Process hollowing into a suspended self-copy
Inner PE payload executes systematic anti-forensics:
• Wipes 12 targeted event logs via wevtutil
• Purges Windows Prefetch
• Deletes PowerShell command history
• Wipes USN change journals
• Disables Windows Recovery (reagentc, bcdedit, wbadmin, Disable-ComputerRestore)
• Resizes VSS shadow storage stealthily
• Powers down Hyper-V VMs via WMI (ROOT\virtualization\v2) to release .vhdx file locks
🔹 Cryptography
Files encrypted using Windows CNG (BCryptGenRandom, BCryptEncrypt) with unique symmetric keys wrapped by an embedded 4096-bit RSA-1 public key. Files renamed to .locked (preceded by temporary .locked_wip). The RSA private key is never present on the victim host. The encryptor contains zero C2 network communication stacks, making it fully offline.
🔹 Detection Claims
Cynet claims proactive interception within 1 second of detonation via kernel-level driver decoy traps. This is a vendor claim from the same organization that performed the analysis, so treat with appropriate skepticism.
🔹 Key Takeaways
The encryptor design is notable for its complete lack of network communication, heavy anti-forensics targeting recovery infrastructure, and deliberate Hyper-V shutdown to access locked virtual disks. The BYOVD approach using signed STProcessMonitor drivers is increasingly common in ransomware operations.
🔹 ransomware #malware #threatintelligence #BYOVD #reverseengineering
🔗 Source: https://www.cynet.com/settra-ransomware-inside-a-new-enterprise-grade-extortion-threat/
#byovd
6 posts · Last used 11d
A Cambodia malware campaign hides SparkRAT in PNG files and abuses a vulnerable driver to kill antivirus, Acronis TRU reports.
#SparkRAT #BYOVD #Cambodia #Malware #CyberEspionage #SilverFox
http://securityonline.info/cambodia-malware-campaign-sparkrat/?utm_source=mastodon&utm_medium=jetpack_social
Cato CTRL details a new SilverFox ValleyRAT campaign in Japan using three BYOVD drivers and DLL sideloading to kill security tools.
#SilverFox #ValleyRAT #BYOVD #Winos40 #DLLSideloading #Malware #ThreatIntel #Cybersecurity
https://securityonline.info/silverfox-valleyrat-byovd-campaign/?utm_source=mastodon&utm_medium=jetpack_social
🤖 Cruciferra Crypter: China-linked cybercrime groups use BYOVD (Bring Your Own Vulnerable Driver) and Process Ghosting to deliver malware via tax-themed phishing targeting Indian taxpayers. The crypter deploys RATs and info-stealers while evading EDR.
🔗 https://thehackernews.com/2026/07/cruciferra-crypter-uses-byovd-and.html
#Malware #BYOVD #CyberSec #Windows #ReverseEngineering
Proofpoint details the Cruciferra crypter service that cloaks RATs and infostealers using BYOVD EDR tampering and 90+ custom encryption routines.
#Cruciferra #Crypter #MaaS #BYOVD #ProcessGhosting #Infostealer #RAT #Proofpoint
https://securityonline.info/cruciferra-crypter-service/?utm_source=mastodon&utm_medium=jetpack_social
🤖 GodDamn ransomware uses PoisonX kernel driver (BYOVD) to disable endpoint defenses. Microsoft-signed driver deployed mid-attack to kill EDR/AV. Rebrand of Beast ransomware, first spotted May 2026. Symantec details the defense evasion chain.
🔗 https://thehackernews.com/2026/07/goddamn-ransomware-uses-poisonx-driver.html
#Ransomware #Malware #BYOVD #ReverseEngineering #CyberSec
You've seen all posts


