RansomHub affiliate leverages multi-function Betruger backdoor
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-24521 | Out-of-bounds Write Privilege Escalation in Microsoft Windows CLFS Driver CVE-2022-24521 is an elevation-of-privilege flaw in the Windows Common Log File System (CLFS) driver, a kernel component, caused by an out-of-bounds write (CWE-787). A local attacker who already has limited privileges on an affected Windows machine can trigger the bug and gain elevated (SYSTEM/administrator) rights without any user interaction. Because the CLFS driver is part of the operating system, every user and service on an unpatched host is exposed to post-compromise escalation, which ransomware operators use to move from an initial foothold to full control. Affected products per the data include Windows 10 releases 1507, 1607, 1809, 1909, 20H2, 21H1, and 21H2, Windows 11 21H2, Windows 7, Windows 8.1, Windows RT 8.1, and Windows Server 2008. The flaw was patched in Microsoft's April 2022 Patch Tuesday, added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-13, and is known to be used in ransomware campaigns, with public reporting tying exploitation to Cuba ransomware activity. Do: Apply the April 2022 Microsoft security updates (Patch Tuesday, released April 12, 2022) to all affected Windows 10/11, Windows 7/8.1/RT 8.1, and Windows Server 2008 systems immediately, per the CISA KEV required action; note that Windows 7/8.1/RT 8.1 and Server 2008 may require Extended Security Updates to receive the fix. Because this is a local privilege escalation, prioritize hosts reachable for initial access, review endpoint telemetry for suspicious limited-user-to-SYSTEM activity, and watch for indicators associated with Cuba ransomware campaigns exploiting this flaw. | 7.8 | 7% | KEV ransomware |
| mass≈1 billion+ Windows devices (the CLFS driver ships in all supported Windows 10/11 and legacy client releases) | |
| CVE-2023-27532 | Missing Authentication in Veeam Backup & Replication Exposes Stored Credentials Veeam Backup & Replication (VBR) contains a missing-authentication flaw (CWE-306) in its Cloud Connect component that lets an unauthenticated network attacker obtain encrypted credentials stored in VBR's configuration database. It is triggered simply by connecting to the exposed service, because the function that serves credential material performs no authentication check; no privileges or user interaction are required (CVSS 3.1: 7.5, network vector). With the recovered credentials, an attacker can gain access to backup infrastructure hosts, which has been used as an entry point and pivot for ransomware operations. Any organization running Veeam Backup & Replication is potentially affected, with the greatest risk where the VBR/Cloud Connect service is reachable from the internet. Exploitation is confirmed: CISA added the bug to its KEV catalog on 2023-08-22 with known ransomware use, the Cuba ransomware group has been observed stealing credentials through this exploit, and EPSS assigns a 77.6% near-term exploitation probability (100th percentile). Do: Apply the fixes Veeam provides in its security advisory immediately — per CISA's KEV listing, patch per vendor instructions or discontinue use — prioritizing internet-facing Cloud Connect servers. After patching, rotate all credentials stored in the configuration database, since they should be considered exposed, and review those accounts for signs of misuse. Restrict network access to the VBR service from untrusted networks and check servers for exploitation indicators such as unexpected connections to the service or anomalous logins with stored credentials. | 7.5 | 78% | KEV ransomware |
| largetens of thousands of deployments, of which thousands are internet-exposed (estimate) |
Full article411 words · extracted from helpnetsecurity.com · click to collapse
A RansomHub affiliate is leveraging a new multi-function backdoor dubbed Betruger to perform various actions during their attacks, Symantec researchers have discovered.
The Betruger backdoor
The malware can take screenshots, log keystroke, scan networks, dump credentials, upload files to a command and control (C2) server, as well as be leveraged for privilege escalation.
“Betruger was found while investigating an attempted attack. From there we found another case where it was used,” Dick O’Brien, Principal Intelligence Analyst with the Symantec Threat Hunter Team by Broadcom, told Help Net Security.
“The limited number of attacks it has been used in suggests that it may have only been used by one affiliate, but who it was developed by is an open question.”
The likely impetus for using a multi-function backdoor like Betruger is to allow attackers reduce their dwell time on target networks: instead of dropping several tools, they can just drop one.
Whether this malware will make the attack more “noisy” remains to be seen. After all, using malware can be a bit more conspicuous than using legitimate tools (e.g., remote monitoring and management software).
The attackers made the effort to masquerade the backdoor as a legitimate application, though, with file names such as mailer.exe and turbomailer.exe.
Ransomhub affiliates’ toolkit
RansomHub is a ransomware-as-a-service operation that has been extremely active in the last year.
“The group has reportedly won over many affiliates by offering them better terms compared to rival operations, such as a great percentage of ransom payments and a payment model where the affiliate is paid by the victim before passing on the operator’s cut,” Symantec researchers noted.
“Betruger is just one of a range of tools that have been used by RansomHub affiliates in recent months. Like a growing number of ransomware attackers, some have begun using tools that leverage the Bring Your Own Vulnerable Driver (BYVOD) technique to disable security solutions, most notably EDRKillshifter.”
Among the tools known to be in their arsenal are:
- Impacket (for remote service execution, Kerberos manipulation, Windows credential dumping, etc.)
- Stowaway Proxy Tool (for proxying network traffic)
- Rclone (for data exfiltration)
- Mimikatz (for credential dumping)
- ScreenConnect, Atera, Splashtop and TightVNC (for remote access to target computers)
- NetScan (for host name and network service discovery)
- SystemBC (a commodity backdoor for C2 communication).
They’ve also been spotted exploiting CVE-2022-24521 for privilege escalation and CVE-2023-27532 for obtaining credentials for accessing targets’ backup infrastructure.
Symantec has shared indicators of compromise associated with the latest RansomHub attacks.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/03/20/ransomhub-affiliate-leverages-multi-function-betruger-backdoor/