SSEへのジャーニーを加速します。 RSAでNetskopeブースにお越しください

  • セキュリティサービスエッジ製品

    高度なクラウド対応の脅威から保護し、あらゆるベクトルにわたってデータを保護します。

  • Borderless SD-WAN

    すべてのリモートユーザー、デバイス、サイト、クラウドへの安全で高性能なアクセスを自信を持って提供します。

  • プラットフォーム

    世界最大のセキュリティプライベートクラウドでの比類のない可視性とリアルタイムデータおよび脅威保護。

ネットスコープ、2022年Gartner社のセキュリティ・サービス・エッジ(SSE)のマジック・クアドラントでリーダーの1社と位置付けられる

レポートを読む 製品概要に移動
Netskope Gartner マジック・クアドラント 2022 SSEリーダー
Gartner® Quick Answer:NetskopeのInfiot買収はSD-WAN、SASE、SSEプロジェクトにどのような影響を与えますか?

レポートを読む
Gartner quick answer
Netskope は、データと脅威の保護、および安全なプライベートアクセスを実現するための機能を統合した、最新のクラウドセキュリティスタックを提供します。

プラットフォームを探索する
大都市の俯瞰図
  • 変身

    デジタルトランスフォーメーションを保護します。

  • セキュリティの近代化

    今日と明日のセキュリティの課題に対応します。

  • フレームワーク

    サイバーセキュリティを形作る規制の枠組みを採用する。

  • 業界ソリューション

    Netskopeは、クラウドに安全に移行するためのプロセスを世界最大規模の企業に提供しています。

最小の遅延と高い信頼性を備えた、市場をリードするクラウドセキュリティサービスに移行します。

詳しくはこちら
Lighted highway through mountainside switchbacks
シングルパスSSEフレームワークを使用して、他のセキュリティソリューションを回避することが多い脅威を防止します。

詳しくはこちら
Lighting storm over metropolitan area
SSEおよびSASE展開のためのゼロトラストソリューション

詳しくはこちら
Boat driving through open sea
Netskopeは、クラウドサービス、アプリ、パブリッククラウドインフラストラクチャを採用するための安全でクラウドスマートかつ迅速な旅を可能にします。

詳しくはこちら
Wind turbines along cliffside
  • 導入企業

    Netskopeは、フォーチュン100の25以上を含む世界中の2,000以上の顧客にサービスを提供しています。

  • カスタマーソリューション

    お客様のため、Netskopeでお客様の成功を確実にすべく、あらゆるステップを共に歩んでまいります。

  • トレーニングと認定

    Netskope training will help you become a cloud security expert.

私たちは、お客様が何にでも備えることができるように支援します

お客様を見る
Woman smiling with glasses looking out window
Netskopeの有能で経験豊富なプロフェッショナルサービスチームは、実装を成功させるための規範的なアプローチを提供します。

詳しくはこちら
Netskopeプロフェッショナルサービス
Netskopeトレーニングで、デジタルトランスフォーメーションの旅を保護し、クラウド、ウェブ、プライベートアプリケーションを最大限に活用してください。

詳しくはこちら
Group of young professionals working
  • リソース

    クラウドへ安全に移行する上でNetskopeがどのように役立つかについての詳細は、以下をご覧ください。

  • ブログ

    Netskopeがセキュリティサービスエッジ(SSE)を通じてセキュリティとネットワークの変革を可能にする方法を学びましょう。

  • イベント&ワークショップ

    最新のセキュリティトレンドを先取りし、仲間とつながりましょう。

  • 定義されたセキュリティ

    サイバーセキュリティ百科事典で知っておくべきことすべて。

セキュリティビジョナリーポッドキャスト

エピソード 10: 透明性によるセキュリティ関係の構築
In this episode, Mike and Andreas discuss aligning with works councils, forging business relationships through transparency, and embedding security into value streams.

ポッドキャストを再生する
Building Security Relationships Through Transparency
Netskopeがセキュリティサービスエッジ(SSE)機能を介してゼロトラストおよびSASEジャーニーを実現する方法に関する最新情報をお読みください。

ブログを読む
Sunrise and cloudy sky
RSAのネツコペ

今年のRSAカンファレンスでNetskopeブースにお越しいただき、SASEとゼロトラストに関するお話をお聞きください。サウスホールのブースにお立ち寄りいただき、エキスパートとの情報交換や、講演セッションへの登録など、ぜひイベントにご参加ください!

詳しくはこちら
RSA logo
セキュリティサービスエッジとは何ですか?

SASEのセキュリティ面、ネットワークとクラウドでの保護の未来を探ります。

詳しくはこちら
Four-way roundabout
  • 会社概要

    クラウド、データ、ネットワークセキュリティの課題の先取りをサポート

  • ネットスコープが選ばれる理由

    クラウドの変革とどこからでも機能することで、セキュリティの機能方法が変わりました。

  • リーダーシップ

    ネットスコープの経営陣はお客様を成功に導くために全力を尽くしています。

  • パートナー

    私たちはセキュリティリーダーと提携して、クラウドへの旅を保護します。

Netskopeは仕事の未来を可能にします。

詳しくはこちら
Curvy road through wooded area
Netskopeは、組織がゼロトラストの原則を適用してデータを保護できるように、クラウド、データ、およびネットワークのセキュリティを再定義しています。

詳しくはこちら
Switchback road atop a cliffside
思想家、建築家、夢想家、革新者。 一緒に、私たちはお客様がデータと人々を保護するのを助けるために最先端のクラウドセキュリティソリューションを提供します。

当社のチーム紹介
Group of hikers scaling a snowy mountain
Netskopeのパートナー中心の市場開拓戦略により、パートナーは企業のセキュリティを変革しながら、成長と収益性を最大化できます。

詳しくはこちら
Group of diverse young professionals smiling

Netskope Threat Coverage: BlackSnake Ransomware

Mar 16 2023

Summary

BlackSnake is a ransomware-as-a-service (RaaS) group that first appeared in a hacking forum in August 2022, where the operators were seeking affiliates and stating that they would take 15% of the profit, which is below the typical average of 20-30%. On February 28, 2023, a new variant of BlackSnake was spotted, and is notable for having a clipper module that targets cryptocurrency users. This is an additional attempt to directly steal the victim’s money, while also encrypting files and asking for a ransom. 

BlackSnake operators seeking affiliates in a hacking forum.

BlackSnake is apparently targeting only home users at this point. This is due to the low ransom value demanded by this variant and the fact that the group does not have a website for publishing stolen data, often named the “wall of shame”, which is a common practice among RaaS groups that targets large organizations. Also, unlike other ransomware groups, like BlackCat or LockBit, BlackSnake does not provide a website as a contact point. The communication between attackers and victims occurs exclusively through emails.

Additionally, there is evidence that shows that BlackSnake was based on the Chaos ransomware, sharing similarities across its source code. In this blog post, we will show how BlackSnake ransomware works.

Analysis 

BlackSnake ransomware is developed in .NET and, although this information can be tampered with, the new variant was likely compiled on February 19, 2023.

BlackSnake ransomware binary details.

BlackSnake obfuscates its important strings using a simple technique common in .NET malware. We released a script that can be used to deobfuscate these strings in our GitHub repository.

Once running, the ransomware exits its process if the victim is located in Azerbaijan or Turkey, by checking if the OS language is equal to “az-Latn-AZ” or “tr-TR”.

BlackSnake checking the OS language.

BlackSnake checks if the file is being executed from the Windows AppData folder with the name “svchost.exe” and if there’s a ransom note at the same path. If this is true, it ends the process to  avoid re-infecting the system. If these conditions aren’t met, the ransomware then checks if there’s another BlackSnake process running by comparing the processes’ IDs.

BlackSnake compares the process ID to avoid instances running at the same time.

When BlackSnake identifies that the system wasn’t previously infected and there isn’t another instance running, it then checks again if the ransomware was executed from the Windows AppData folder as “svchost.exe”’. If that’s not the case, it copies itself to that location and starts a new process.

BlackSnake copying itself to Windows AppData as “svchost.exe”

BlackSnake establishes a very simple persistence through Windows registry.

BlackSnake persistence via Windows registry key.

BlackSnake stands out for having an additional functionality that attempts to steal Bitcoin from cryptocurrency users. It monitors the victim’s clipboard and when a Bitcoin address is identified, it replaces the address with the attacker’s wallet address.

BlackSnake replaces the Bitcoin address with the attacker’s wallet number.

This Bitcoin address is also associated with other ransomware families, like Phreaker, Sirattacker, Magnus, Baal, Helphack, and Bettercallsaul.  At this point, it is unclear if they are all sourced from the same attacker or if this address is being copied across source codes, especially because this Bitcoin address is not the same as the one used by BlackSnake in its ransomware note, as we will see later. 

Different ransomware families sharing the same Bitcoin address.

Like other ransomware, BlackSnake has a list of directories that it will skip the encryption to avoid corrupting the OS:

  • Program Files
  • Program Files (x86)
  • Windows
  • $Recycle.Bin
  • MSOCache
  • Documents and Settings
  • Intel
  • PerfLogs
  • Windows.old
  • AMD
  • NVIDIA
  • ProgramData
  • appdata\local
  • appdata\locallow
  • users\all users
  • \ProgramData
List of directories BlackSnake skips the encryption.

And there’s also a list of files that it won’t encrypt:

  • boot.ini
  • bootfont.bin
  • iconcache.db
  • ntuser.dat
  • ntuser.dat.log
  • ntuser.ini
  • thumbs.db
  • autorun.inf
  • bootsect.bak
  • bootmgfw.efi
  • desktop.ini
List of files BlackSnake won’t encrypt.

BlackSnake also has a function that tries to stop specific services in the OS:

  • BackupExecAgentBrowser
  • BackupExecDiveciMediaService
  • BackupExecJobEngine
  • BackupExecManagementService
  • vss
  • sql
  • svc$
  • memtas
  • sophos
  • veeam
  • backup
  • GxVss
  • GxBlr
  • GxFWD
  • GxCVD
  • GxCIMgr
  • DefWatch
  • ccEvtMgr
  • SavRoam
  • RTVscan
  • QBFCService
  • Intuit.QuickBooks.FCS
  • YooBackup
  • YooIT
  • zhudongfangyu
  • stc_raw_agent
  • VSNAPVSS
  • QBCFMonitorService
  • VeeamTransportSvc
  • VeeamDeploymentService
  • VeeamNFSSvc
  • PDVFSService
  • BackupExecVSSProvider
  • BackupExecAgentAccelerator
  • BackupExecRPCService
  • AcrSch2Svc
  • AcronisAgent
  • CASAD2DWebSvc
  • CAARCUpdateSvc
  • TeamViewer
Function to stop specific services.

Although this sample didn’t execute this function in our tests, it also has a way to stop Windows Shadow Copies and disable boot recovery mode to avoid files being restored, through the following commands:

  • vssadmin delete shadows /all /quiet & wmic shadowcopy delete
  • bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no
  • wbadmin delete catalog -quiet

The encryption process is straightforward. Like other RaaS families, BlackSnake uses a combination of symmetric and asymmetric key encryptions throughout the process. First, it randomly generates an AES key and encrypts this value with a RSA hardcoded public key.

BlackSnake function that encrypts the AES key used to encrypt a file.

BlackSnake only encrypts files that are using specific extensions. The complete list can be found in our GitHub repository.

Then, it encrypts the file using the AES key and appends the encrypted key at the end of the file, so it’s possible to decrypt the data with the private RSA key.

BlackSnake ransomware encryption process.

This is what an encrypted file looks like, with the encrypted data at the beginning and the encrypted key at the end:

File encrypted by BlackSnake ransomware.

BlackSnake adds the extension “.pay2unlock” to encrypted files, and uses “UNLOCK_MY_FILES.txt”  as the name for the ransom note.

Files encrypted by BlackSnake ransomware and its ransom note.

It also changes the desktop wallpaper, like other ransomware families.

And finally, it displays the ransom note. There are two notable points here:

  1. BlackSnake is not demanding a high ransom value, indicating that it is likely targeting home users instead of large organizations.
  2. The Bitcoin address is not the same as the one observed earlier, which could indicate that the one used by the clipper module was simply copied from previous source codes, especially because we found the previous address being linked to other ransomware families.

So far, the Bitcoin address found in the clipper module has received $ 691.65 USD since June 2022, while the Bitcoin address in the BlackSnake ransom note has received $ 181.87 USD since May 2022.

BlackSnake ransom note.

The contact between BlackSnake attackers and victims are based on email. The ransom note provides a website link hosted on the deep web that victims can access, but the website contains the same instructions on the ransom note.

BlackSnake website hosted on the deep web.

The website also points to another URL, but it’s currently offline.

Conclusion

This new BlackSnake variant stands out as it has an additional way to steal money from victims, through the clipper module that targets cryptocurrency users. However, it seems that BlackSnake is perhaps still under development or that they don’t have affiliates at this point, given that it seems to be targeting home users and it doesn’t have a robust infrastructure like other families, such as BlackCat or LockBit.

Protection

Netskope Threat Labs is actively monitoring this campaign and has ensured coverage for all known threat indicators and payloads. 

  • Netskope Threat Protection
    • Win32.Ransomware.Blacksnake
  • Netskope Advanced Threat Protection provides proactive coverage against this threat.
    • Gen.Malware.Detect.By.StHeur indicates a sample that was detected using static analysis
    • Gen.Malware.Detect.By.Sandbox indicates a sample that was detected by our cloud sandbox

IOCs

All the IOCs related to this campaign, scripts, and a Yara rule can be found in our GitHub repository.

author image
Gustavo Palazolo
Gustavo Palazolo is an expert in malware analysis, reverse engineering and security research, working many years in projects related to electronic fraud protection. He is currently working on the Netskope Research Team, discovering and analyzing new malware threats.