April 30, 2021 By David Bisson 2 min read

The operators of the Mamba ransomware strain have added weaponized DiskCryptor to their ongoing attacks, the FBI warned. An open-encryption solution, DiskCryptor, is capable of encrypting all disk partitions including the system partition. While not malicious by itself, this enables Mamba to encrypt the entire drive, including the operating system. Attackers have used Mamba ransomware to target local governments, legal services and other entities.

Read on to learn about how the new ransomware variant takes advantage of DiskCryptor to encrypt its victims’ data.

Mamba’s Use of DiskCryptor

In its FLASH alert, the FBI wrote that Mamba consists of DiskCryptor wrapped in a program. The ransomware uses this program, along with a key of the attackers’ choosing, to install and begin disk encryption in the background, the warning noted.

From there, Mamba extracts some files and installs an encryption service. It then completes driver installation by restarting the system two minutes after DiskCryptor’s installation.

The ransomware concludes its encryption routine after saving its encryption key and shutdown time variable to the configuration file (myConf.txt). This file remains readable until the second restart, which occurs about two hours later.

Other Mamba Ransomware Attacks

In 2019, TrendMicro discovered a new variant of Mamba, also known as HDDCryptor. Much of what it could do was the same as previous iterations. Mamba arrived with a modified DiskCryptor component for the purpose of encrypting disk and network files as well as overwriting the Master Boot Record.

Another notable attack came in 2016, when the Mamba gang targeted San Francisco light-rail ticketing machines. The attack didn’t prevent the trains from running, but it did drop DiskCryptor onto several of the ticketing machines. In response, the agency opened its fare gates to minimize customer impact.

Several months later, the Mamba attackers resumed their attacks around the world. Kaspersky observed the malicious actors targeting groups in Brazil and Saudi Arabia.

How to Defend Against Mamba

The FBI ransomware report noted security defenders can try to determine if myConf.txt is still accessible in the event that they detect any of the DiskCryptor files. They can then try to recover their data without having to pay the ransom.

Even so, it’s not always possible to recover the encrypted data, and the last thing you want is to support ransomware as a business model. You therefore need to focus on prevention, not defense. Use awareness training to build a positive security culture. Those lessons should leverage fake phishing emails and other tests to make sure employees are familiar with common ransomware attack vectors.

Awareness isn’t enough in the face of ever-evolving threats like ransomware. Because of that, organizations need to blend their use of human controls with technical measures such as multifactor authentication and user behavior analytics. They can pair these measures with threat intelligence to stay current with the ransomware threat landscape and set up defenses before an attack happens.

More from News

Europe’s Cyber Resilience Act: Redefining open source

3 min read - Amid an increasingly complex threat landscape, we find ourselves at a crossroads where law, technology and community converge. As such, cyber resilience is more crucial than ever. At its heart, cyber resilience means maintaining a robust security posture despite adverse cyber events and being able to anticipate, withstand, recover from and adapt to such incidents. While new data privacy and protection regulations like GDPR, HIPAA and CCPA are being introduced more frequently than ever, did you know that there is new…

Feds release urgent guidance for U.S. water sector

3 min read - The water and wastewater sector (WWS) faces cybersecurity challenges that leave it wide open to attacks. In response, the CISA, EPA and FBI recently released joint guidance to the sector, citing variable cyber maturity levels and potential cybersecurity solutions. The new Incident Response Guide (IRG) provides the water sector with information about the federal roles, resources and responsibilities for each stage of the cyber incident response lifecycle. Sector owners and operators can use this information to augment their incident response…

What to expect from the new National Cyber Director

4 min read - As cyber threats show no sign of slowing down in terms of sophistication and frequency, the role of the National Cyber Director (NCD) in the United States is becoming a cornerstone of the nation’s defense strategy. Inaugural NCD Chris Inglis set a high bar for the office during his tenure, steering the country through a gauntlet of cyber challenges. Now, as Harry Coker Jr. steps into this critical role, he faces a landscape that continues to evolve with new threats on…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today