Skip to content

Rorschach malware is identified: it has a high level of customization and high speed in its encryption

Researchers have identified a malware called Rorschach, which offers a high level of customization and stands out for being one of the fastest strains in terms of the speed of its encryption.

LOOK: Twitter: Shutdown of free API has affected third-party platforms

The Incident Response Team of the cybersecurity company Check Point (CPIRT) has found this malicious software when responding to a ransomware case against a US-based company.

In their research, the professionals found a unique ransomware strain capable of being deployed using a signed component of Palo Alto Network’s Crotex XDR. According to Check Point, this method “It is not commonly used to upload ‘ransomware’, so it reveals a new approach being taken by cybercriminals to evade detection”as explained in a press release.

LOOK: The 10 most powerful cell phones in the world, according to the AnTuTu ranking

Unlike other cases of ‘ransomware’, the author of the threat is not hiding behind an alias and does not appear to be affiliated with any of the known ransomware groups. Thus, its behavior suggests that it is partially autonomous and propagates automatically when running on a Domain Controller (DC) while clearing event logs from affected machines.

On the other hand, the researchers have assured that this ‘malware’ is “extremely flexible”, since it operates not only based on a built-in settings which allows you to change its behavior according to the needs of the operator.

LOOK: Barbie: how to create your own poster with the movie filter?

They have also pointed out that although it seems to have been inspired by some of the best-known ‘ransomware’ families, it also contains unique features, such as the use of direct ‘syscalls’, that is, calls to communicate with the system kernel.

Source: Elcomercio

Share this article:
globalhappenings news.jpg
most popular