#byovd

6 posts · Last used 12d

---------------- 🦠 Malware Analysis =================== Settra is a ransomware operation first identified in June 2026 that has already claimed 50-70+ enterprise victims across technology, manufacturing, financial services, healthcare, and retail sectors. The group operates double-extortion: data exfiltration followed by encryption and ransom negotiation via Tox and darknet portals. 🔹 Intrusion Methodology Human-operated intrusions begin through compromised VPNs or valid accounts. Credential dumping uses Mimikatz and ProcDump. Lateral movement relies on dual-use tools including PAExec and NetExec. Durable remote access is established via Mesh Agent. Before encryption, operators abuse signed STProcessMonitor drivers via BYOVD to blind endpoint defenses. 🔹 Encryptor Architecture The encryptor is a two-stage design recovered through offline static reverse engineering by Cynet Research Labs. Outer loader (win64.exe): • Password-gated entry • PEB export hashing for API resolution • Anti-debugging gates • ~200,000-round SHA-256 KDF for key derivation • AES-256-CTR decryption of inner payload • Custom LP77 decompression • Process hollowing into a suspended self-copy Inner PE payload executes systematic anti-forensics: • Wipes 12 targeted event logs via wevtutil • Purges Windows Prefetch • Deletes PowerShell command history • Wipes USN change journals • Disables Windows Recovery (reagentc, bcdedit, wbadmin, Disable-ComputerRestore) • Resizes VSS shadow storage stealthily • Powers down Hyper-V VMs via WMI (ROOT\virtualization\v2) to release .vhdx file locks 🔹 Cryptography Files encrypted using Windows CNG (BCryptGenRandom, BCryptEncrypt) with unique symmetric keys wrapped by an embedded 4096-bit RSA-1 public key. Files renamed to .locked (preceded by temporary .locked_wip). The RSA private key is never present on the victim host. The encryptor contains zero C2 network communication stacks, making it fully offline. 🔹 Detection Claims Cynet claims proactive interception within 1 second of detonation via kernel-level driver decoy traps. This is a vendor claim from the same organization that performed the analysis, so treat with appropriate skepticism. 🔹 Key Takeaways The encryptor design is notable for its complete lack of network communication, heavy anti-forensics targeting recovery infrastructure, and deliberate Hyper-V shutdown to access locked virtual disks. The BYOVD approach using signed STProcessMonitor drivers is increasingly common in ransomware operations. 🔹 ransomware #malware #threatintelligence #BYOVD #reverseengineering 🔗 Source: https://www.cynet.com/settra-ransomware-inside-a-new-enterprise-grade-extortion-threat/
0
0
0
0
You've seen all posts