DIRECTORY

  • Alerts
  • APTs
  • Blog
  • Books
  • Certifications
  • Cheat Sheets
  • Courses
  • Cyber Briefing
  • CyberDecoded
  • CyberReview
  • CyberStory
  • CyberTips
  • Definitions
  • Domains
  • Entertainment
  • FAQ
  • Frameworks
  • Hardware Tools
  • Incidents
  • Malware
  • News
  • Papers
  • Podcasts
  • Quotes
  • Reports
  • Tools
  • Threats
  • Tutorials
No Result
View All Result
  • Login
  • Register
  • Cyber Citizens
  • Cyber Professionals
  • Institutions
CyberMaterial
Get Help
  • Cyber Citizens
  • Cyber Professionals
  • Institutions
CyberMaterial
No Result
View All Result
Get Help
CyberMaterial
Home Alerts

EXFILTRATOR-22: A New Ransomware Threat

March 1, 2023
Reading Time: 2 mins read
in Alerts

 

A new report from cybersecurity firm CYFIRMA warns of a new post-exploitation framework known as EXFILTRATOR-22 or EX-22, which aims to deploy ransomware in enterprise networks undetected.

The malware is designed to fly under the radar with a range of capabilities, making post-exploitation easy for anyone purchasing the tool. The malware is equipped with features such as launching ransomware to encrypt files, establishing a reverse shell with elevated privileges, and logging keystrokes.

EX-22 also enables criminals to start a live VNC session for real-time access, persist after system reboots, and generate cryptographic hashes of files.

The malware creators likely operate from North, East, or Southeast Asia and are former affiliates of the LockBit ransomware enterprise. CYFIRMA assessed with moderate confidence that the threat actors are behind the creation of the malware.

EX-22 is advertised as a fully undetectable malware on Telegram and YouTube and is available for $1,000 a month or $5,000 for lifetime access. Criminals purchasing the toolkit are provided with a login panel to access the EX-22 server and remotely control the malware.

The connections to LockBit 3.0 arise from technical and infrastructure overlaps, with both malware families utilizing the same domain fronting mechanism for hiding command-and-control (C2) traffic.

Since its first appearance on November 27, 2022, the malware authors have continuously iterated the toolkit with new features, indicating active development work. EX-22 has gained attention among cybercriminals due to its fully undetectable nature and its ability to deploy ransomware without detection.

In conclusion, EXFILTRATOR-22 or EX-22 is a new ransomware threat that poses a significant risk to enterprise networks. Its undetectable nature and range of capabilities make it easy for cybercriminals to deploy ransomware undetected.

As the malware creators continuously iterate the toolkit with new features, the threat of ransomware attacks continues to increase, emphasizing the need for robust cybersecurity measures to protect enterprise networks.

Read More

Tags: AlertsAlerts 2023EX-22EXFILTRATOR-22LockBitMalwareMarch 2023Ransomware
0
VIEWS
ADVERTISEMENT

Related Posts

OpenAI fixes vulnerabilities in ChatGPT

OpenAI fixes vulnerabilities in ChatGPT

March 30, 2023
Vendors Alert 3CX Supply Chain Attack

Vendors Alert 3CX Supply Chain Attack

March 30, 2023
Mozilla Fixes Thunderbird Vulnerability

Mozilla Fixes Thunderbird Vulnerability

March 30, 2023
Chinese state hackers target Linux servers

Chinese state hackers target Linux servers

March 30, 2023

More Articles

Jobs

Director, DevSecOps

January 2, 2023
Quotes

“Once the student clicks on a link…”

October 28, 2022
Document

2021 THREAT HUNTING REPORT: INSIGHTS FROM THE FALCON OVERWATCH TEAM

June 29, 2022
Alerts

IBM security advisory (AV22-105)

February 28, 2022

Security through data

Cybersecurity Domains

  • API Security
  • Business Continuity
  • Career Development
  • Compliance
  • Cryptography
  • HSM
  • KPIs / KRIs
  • Penetration Testing
  • Shift Left
  • Vulnerability Scan

Emerging Technologies

  • 5G
  • Artificial Intelligence
  • Blockchain
  • Cryptocurrency
  • Deepfake
  • E-Commerce
  • Healthcare
  • IoT
  • Quantum Computing

Frameworks

  • CIS Controls
  • CCPA
  • GDPR
  • NIST
  • 23 NYCRR 500
  • HIPAA

Repository

  • Books
  • Certifications
  • Definitions
  • Documents
  • Entertainment
  • Quotes
  • Reports

Threats

  • APTs
  • DDoS
  • Insider Threat
  • Malware
  • Phishing
  • Ransomware
  • Social Engineering

© 2023 | CyberMaterial | All rights reserved.

World’s #1 Cybersecurity Repository

  • About
  • Legal and Privacy Policy
  • Site Map
No Result
View All Result
  • Audience
    • Cyber Citizens
    • Cyber Professionals
    • Institutions
  • Highlights
    • Blog
    • CyberDecoded
    • Cyber Review
    • CyberStory
    • CyberTips
  • Cyber Risks
    • Alerts
    • Attackers
    • Domains
    • Incidents
    • Threats
  • Opportunities
    • Events
    • Jobs
  • Repository
    • Books
    • Certifications
    • Cheat Sheets
    • Courses
    • Definitions
    • Frameworks
    • Games
    • Hardware Tools
    • Memes
    • Movies
    • Papers
    • Podcasts
    • Quotes
    • Reports
  • Report Cyber Incident
  • GET HELP

Subscribe to our newsletter

© 2022 Cybermaterial - Security Through Data .

Welcome Back!

Sign In with Google
Sign In with Linked In
OR

Forgotten Password? Sign Up

Create New Account!

Sign Up with Google
Sign Up with Linked In
OR

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.