PULSE NAME
Fake Zoom Ends in BlackSuit Ransomware
WHITE AlienVault 2025-03-31 Modified: 2025-04-30
46
IOCs
MEDIUM VOLUME
A malicious website mimicking Zoom led to the installation of a trojanized installer, initiating a multi-stage attack. The initial payload, d3f@ckloader, downloaded additional components, including SectopRAT. After nine days, the threat actor deployed Brute Ratel and Cobalt Strike beacons for lateral movement. They used various techniques for discovery and credential access, including LSASS memory dumping. The attacker employed QDoor for proxying RDP connections, facilitating data collection and exfiltration via the cloud service Bublup. The intrusion culminated in the deployment of BlackSuit ransomware across multiple systems using PsExec, with a total time to ransomware of 194 hours over nine days.
Indicators of Compromise (13 / 46 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 4b22032954a12677675add0de20d7b94 2025-03-31
FileHash-MD5 5b8ebe43ded7ba460e4827206329375a 2025-03-31
FileHash-MD5 80110fbb81d0407340b908bb43c815d3 2025-03-31
FileHash-MD5 8477ef317b8974e18ed84ca69b9f6a08 2025-03-31
FileHash-MD5 85144918f213e38993383f0745d7e41e 2025-03-31
FileHash-MD5 91f69fa3439f843b51c878688963e574 2025-03-31
FileHash-MD5 9bddb0e95a03fdcea4c62210f5818184 2025-03-31
FileHash-MD5 c0230d748e61819d9dfad0da03fe6ec8 2025-03-31
FileHash-MD5 d1ba9412e78bfc98074c5d724a1a87d6 2025-03-31
FileHash-MD5 d98fb34b4fa0f83d02e3272f1cb9c5fc 2025-03-31
FileHash-MD5 eae6cd02784743cde314afb8c533c5cd 2025-03-31
FileHash-MD5 f91fbe09b593fb1104b30e3343afb392 2025-03-31
FileHash-MD5 ffb3755897b8d38ccc70b9c3baa38960 2025-03-31