18 September 2023

Black Cat actors encrypt Azure accounts with new Sphynx ransomware


Black Cat actors encrypt Azure accounts with new Sphynx ransomware

The BlackCat (ALPHV) ransomware group has been observed using compromised Microsoft accounts and the new Sphynx ransomware variant to take over Azure Storage accounts.

First spotted earlier this year, the Sphynx variant embeds the Impacket networking framework and the Remcom hacking tool, both facilitating lateral movement in compromised networks. The Impacket tool has credential dumping and remote service execution modules that could be used for broad deployment of the BlackCat ransomware in target environments. Microsoft said it first discovered this new version in July 2023.

While investigating a recent breach, Sophos X-Ops researchers discovered that the attacker used an updated Sphynx version. The threat actor was able to gain access to the targeted Azure portal using a stolen Azure access key.

The attackers used a variety of remote monitoring and management tools such as AnyDesk, Splashtop, and Atera, as well as Chrome to access the target's installed LastPass vault via the browser extension. They obtained a one-time password for accessing the target's Sophos Central account used to manage Sophos products.

The threat actor then altered security policies and disabled Tamper Protection within Central before encrypting the victim’s systems and remote Azure Storage accounts via ransomware.

Sophos said that 39 Azure accounts in total were successfully encrypted by the attackers.

Last week, the BlackCat ransomware group took responsibility for the MGM Resort hack. The group said that they encrypted more than 100 ESXi servers after MGM Resorts took down its internal infrastructure, as well as exfiltrated data from the network. The gang also said they maintain access to some of the company’s infrastructure and are threatening to carry out new attacks unless a ransom is paid.


Back to the list

Latest Posts

North Korea’s Lazarus adds new LightlessCan backdoor to its arsenal

North Korea’s Lazarus adds new LightlessCan backdoor to its arsenal

The hackers posed as a recruiter from Meta to gain access to the network of an aerospace firm.
2 October 2023
Critical Exim flaws put millions of servers at risk of hacker attacks

Critical Exim flaws put millions of servers at risk of hacker attacks

The vulnerabilities could allow attackers to breach the servers and gain access to sensitive data.
2 October 2023
Cyber Security Week in Review: September 29, 2023

Cyber Security Week in Review: September 29, 2023

The world in brief: the MOVEit protocol maker releases fixes for new critical bugs, Cisco warns of a zero-day in IOS and IOS XE software, and more.
29 September 2023