27/09/2023
09:20

Hacker group spreading Rhysida Ransomware, strikes again


WARNING! Italian institutions and companies are targeted by cyber criminals...
Rhysida ransomware, which had already been reported in the press in the first decade of last July, is back to hit Italian institutions and companies. Like all ransomware, this is a type of malware that, once introduced into an organization, encrypts the data, requiring the victim to pay a ransom in order to decrypt it.

TG Soft Cyber Security Specialist's CRAM researchers could test their Heuristic Behavioral technologies to combat even the variants of this family type of Ransomware attacks. Again these technologies, developed since 2014 and made available since 2015, proved to be effective and efficient in blocking the cyber attack, started in any mode, automatically within 100 milliseconds {1 tenth of a second => a blink of an eye} from the start of the encryption process.
It is worth to point out that the file encryption process was locked automatically without the signature of the file initiating the process...if the signature had been loaded, the encrypted files would have been 0 {zero}!

Below is the brief payload analysis performed by TGSoft's CRAM Analysts on Rhysida Ransomware.

Rhysida ransomware encrypted file structure:

[ORIGINAL_FILENAME].[original_extension].rhysida

As you can see, the ransomware adds the extension ''rhysida'', to the original file name.

The ransom instructions, that we show below, are in the form of a PDF file named: CriticalBreachDetected.pdf

"Funny" / ironic that they call themselves "cybersecurity team Rhysida."
Clicca per visualizzare l'immagine della richiesta di riscatto generata da Rhysida Ransomware
From the attack we simulated in our own real infrastructure with a sample retrieved from an actual attack, the heuristic-behavioral protection of VirITeXplorerPRO AntiRansomware CryptoMalware protection intervened in 100 milliseconds {1/10th of a second} from the start of the encryption process, when the ransomware managed to encrypt only 16 files (by the way, all decoy files).
The computer where the malicious process was initiated  (simulating a HumanOperatedRansomware Attack), was automatically isolated  from the rest of the network by our technologies, so as to prevent the ransomware attack from propagating to the entire infrastructure and thus saving 100% of the user's working files on that machine (client or server indifferently).

Vir.IT Anti-Ransomware Crypto-Malware Protection


TG Soft has been developing and integrating since May 2015 in the Vir.IT eXplorer PRO suite - THE ONLY product with proprietary engine developed 100% in Italy - AntiVirus, AntiSpyware and AntiMalware, AntiRansomware Crypto-Malware protection technologies that, through the heuristic-behavioral approach, block the encryption process in the initial phase of the attack saving, on average, at least 99.63% of the data files otherwise potentially encrypted.

In addition, as a last parachute, you can restore from Vir.IT BackUp, which is built in Vir.IT eXplorer PRO suite, data files that cannot be restored or recovered using other restore/recovery tools.
 

For more info on these technologies, 100% developed in Italy, you can contact the administrative office of TG Soft Cyber Security Specialist by writing to segreteria@tgsoft.it or by calling the direct number 049.8977432. 



C.R.A.M.
TG Soft's Anti-Malware Research Center
 
Any information published on our site may be used and published on other websites, blogs, forums, facebook and/or in any other form both in paper and electronic form as long as the source is always and in any case cited explicitly “Source: CRAM by TG Soft www.tgsoft.it” with a clickable link to the original information and / or web page from which textual content, ideas and / or images have been extrapolated.
It will be appreciated in case of use of the information of C.R.A.M. by TG Soft www.tgsoft.it in the report of summary articles the following acknowledgment/thanks “Thanks to Anti-Malware Research Center C.R.A.M. by TG Soft of which we point out the direct link to the original information: [direct clickable link]”

Vir.IT eXplorer PRO is certified by the biggest international organisation: