ExtraHop® Closes Enterprise Data Center Blind Spots with new 400 Gbps sensor

Search
  • Platformchevron right
  • Solutionschevron right
  • Modern NDRchevron right
  • Resourceschevron right
  • Companychevron right
Loading…
Loading…
ExtraHop grid image

The BlackCat/ALPHV ransomware group is back in the headlines, following a $22 million attack on Change Healthcare, first reported in February 2024. The group’s eponymous ransomware was initially observed in November 2021, and by April 2022, the FBI reported that the group had infected more than 60 organizations.


Between mid-2022 and the end of 2023, BlackCat emerged as the second most prolific ransomware-as-a-service group, having perpetrated more than 1,000 successful attacks against government entities, defense contractors, critical manufacturing companies, healthcare providers, schools, and more, according to the U.S. Justice Department (DOJ). But U.S. law enforcement officials were about to catch up.

In December 2023, the DOJ announced that the FBI had infiltrated the group, seized several of its websites, and released a decryption tool to help organizations get their data back.

The February attack on Change Healthcare, coming two months after the DOJ’s announcement, dealt a blow to U.S. law enforcement efforts to crack down on the group, which has ties to the Darkside ransomware gang responsible for the attack on Colonial Pipeline. The attack also demonstrated how quickly the threat actor could regroup, even if its resurgence turned out to be short lived: BlackCat announced a few weeks after the Change Healthcare attack was reported that it was shutting down.

Even if the BlackCat ransomware group dismantles the way Darkside did in May 2021, its code and its tactics–including all the vulnerabilities and living off the land techniques it exploits–remain a significant threat to organizations worldwide. Indeed, Krebs on Security reported the group had already found a buyer for its source code.

RevealX has been helping organizations detect and stop BlackCat ransomware attacks since 2022. Here’s how RevealX catches these attacks before threat actors can spring their multi-million dollar double extortion trap.

Tactics and Techniques Associated with BlackCat Ransomware

Although technical details about the attack on Change Healthcare remain scarce, the techniques it uses are well documented in the MITRE ATT&CK® Matrix for Enterprise and other sources.

To gain initial access, the BlackCat ransomware group, like most ransomware groups, uses a variety of techniques, including stolen credentials (likely gained through initial access brokers or their own social engineering schemes) and exploitation of known and unknown software vulnerabilities. With respect to exploitation of software vulnerabilities, RevealX automatically discovers, classifies, and inventories all devices and cloud assets connecting to an organization’s network, enabling security teams to quickly pinpoint vulnerable devices and instances of vulnerabilities being exploited.

Once BlackCat threat actors are inside, they collect system and network information. They enumerate files, directories, domain trusts, and system and service logs, and they look for Active Directory data. They also try to figure out what EDR and logging tools an organization is running, so that they can then disable endpoint agents and delete logs (two techniques BlackCat is well known for). Account enumeration, network share enumeration, network discovery enumeration, and BloodHound enumeration with Active Directory would all light up in RevealX.

Next comes credential theft. The typical scenario involves a threat actor transferring malware designed to gather credentials over SMB, then executing the malware file using RPC. If your EDR and SIEM tools have been disabled, they won’t detect this activity, but RevealX will. RevealX sees SMB requests because it observes every packet going over the network, and it applies machine learning to identify suspicious SMB requests and file reads from, say, a new machine in an organization’s environment. EDR and logging tools are not set up to identify suspicious SMB requests.

hacker

RevealX also detects executable file transfer and has the ability to see when threat actors use RPC to execute malicious files. BlackCat actors have also been observed using DCSync to harvest administrative credentials by emulating a domain controller, another behavior RevealX detects.

To move laterally, they use remote desktop protocol (RDP), but RevealX picks up on this activity. It can detect suspicious use of RDP on a host–whether it’s a user’s laptop, a Windows virtual machine, a Windows server, or even a domain controller–activity that EDR and SIEM typically don’t see.

RevealX also detects command and control. BlackCat, like many other ransomware groups, uses Cobalt Strike to establish communications with a C2 server. RevealX has a number of Cobalt Strike detections, including Cobalt Strike beacons transferred internally over SMB, Cobalt Strike outbound communication, Cobalt Strike communication over SMB named pipes, and more.

Additional indicators that RevealX picks up on include detections of Tor node connections, data staging, and data exfiltration.

city and data horizon

Initial Access

Loading…

Execution

Loading…

Defense Evasion

Loading…

Discovery

Loading…

Lateral Impact

Loading…

Impact

Loading…

RevealX for Comprehensive Protection Against BlackCat Ransomware

security professional

With RevealX, you can worry less about having to cough up a $22 million dollar ransom payment. Why? Because its unmatched decryption and machine learning capabilities, its speed, scale, and protocol fluency–combined with the breadth and depth of its rules-based and behavior detectors–provide your security team with more than a dozen opportunities to stop BlackCat and other ransomware attacks before they paralyze your organization.


Want to learn more about ransomware defense strategies? Request a demo or visit our web site.

Experience RevealX NDR for yourself