Ransomware Prevention: Protecting against BlackCat Ransomware | Portal26

Ransomware Prevention: Protect your organization from BlackCat Ransomware attacks

Where there is value for organizations online, there will be a cybercriminal ready with a ransomware attack to exploit it.

Since they first emerged in December of 2021, BlackCat Ransomware has become another example of a ring of cybercriminals who practice the model of Ransomware-as-a-Service (RaaS) to wreak havoc on organizations. This article discusses who they are, what they do, how they perform their ransomware attacks, and what you can do to protect your organization from this form of ransomware.

What is BlackCat Ransomware?

The ALPHV group, or BlackCat, is a group of ransomware creators. Their “business model” is based on the deal that they give other attackers access to their infrastructure and malicious malware, and in turn, they receive a portion of the successfully traded ransom. Black cat ransomware gang members are likely in charge of the negotiations with the victims of their attacks. The majority of RaaS providers let their partners keep about 70% of their earnings. The commissioners, meanwhile, can expect to receive 80–90% profit with BlackCat.

This means the only thing lacking from their “one-stop shop” business model is access to the exact corporate environment they intend to attack. However, their malware has already been used in successful ransomware attacks around the globe. According to the FBI FLASH notice circa April 2022, the operation had infected more than 60 persons in six months.

How does BlackCat Ransomware work?

Along with its profit incentive, BlackCat has a loaded lineup of malicious tools, with features that make it difficult for victims to overcome a ransomware attack. For example, it’s written in Rust, and its ransomware attacks use different tools and strategies depending on the attack.

For one thing, BlackCat is the first ransomware written in Rust. The use of a new language for its payload means the ransomware can avoid detection. This is particularly evasive from traditional security solutions that may not be as updated in their capacity to analyze and interpret binaries generated in the new forms of these languages. This also yields BlackCat the ability to target a variety of hardware and operating systems. Microsoft has noted successful assaults on Linux devices, Windows, and VMware instances.

Secondly, BlackCat is thought to have been rebranded from a previous ransomware group. The Fendr utility is specifically what organizations must protect themselves from. This is what BlackCat uses to exfiltrate data from infected infrastructure. For lateral movement within the victim’s network, BlackCat also makes use of the PsExec tool, Mimikatz, an infamous hacker software, and Nirsoft software to steal network passwords and gain full access.

However, it is worth noting that depending on the partner player in each attack, the ransomware group will change the attack strategy.

On a technical level, BlackCat emphasizes and exploits the following five vulnerabilities:

CVE-2021-34473 and CVE-2021-34523, found in Microsoft Exchange Server, both require immediate remediation. They are more dangerous due to the way these cause potential use in vulnerability chaining attacks.

Why is it important to have ransomware protection in my organization?

In the event of a ransomware attack, a company without any protection in place can find itself facing many negative effects. Paying its ransom will mean company resources will be spent to retrieve critical business data from attackers. Additionally, this can show attackers that the organization is a vulnerable target and may lead to repeated negotiation attempts if attacked again.

Even if the organization decides to cooperate and pay the ransom, there is still no guarantee that the systems will be released. With all of these uncertain scenarios, it is essential to have a mitigative cybersecurity plan. With the proper tools in place, organizations can avoid being in a position where they must make such choices.

How can I protect my organization from BlackCat Ransomware and other ransomware attacks?

While there is no guarantee, certain tools can grant immunity from a ransomware attack. A proactive ransomware strategy should include prevention/detection solutions, backup/recovery solutions, and data security that prevents exfiltration of unencrypted data.

Cybersecurity tools, such as Portal26 Suite, offer effective solutions in reducing the impact of ransomware attacks.

Portal26 products that can aid in BlackCat protection include:

Portal26 FileShare Security: Provides always-on encryption for file servers ensuring that all files are secured against unauthorized access.

Portal26 Object Store Proxy: Provides transparent application-level encryption for cloud object stores to ensure ransomware protection and complete data security.

Portal26 Vault: A stand-alone data vault that stores and analyzes structured and unstructured data while retaining strong encryption.

Portal26 Plugin: Protects sensitive data inside major enterprise search platforms without limiting search capabilities.

Portal26 API/Translation service: Offers integration with other Portal26 products for a high-performing data translation service.

Portal26 Studio: An interface for managing other Portal26 products, providing dashboards, reports, and compliance certifications in the event of a successful attack.

Protect your organization from BlackCat Ransomware attacks Today

Do not wait until it is too late; allow Portal26 to help you!