ZeroHour
The Recordpublished ()ingested

Cisco: BlackByte ransomware gang only posting 20% to 30% of successful attacks

criticalRansomwareimportance 60CVE-2024-37085

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-37085
Authentication Bypass in VMware ESXi via AD Group Recreation

VMware ESXi is vulnerable to an authentication bypass (CWE-305) when the host is configured to use Active Directory for user management. An attacker who has sufficient Active Directory permissions can delete the AD group tied to ESXi administration (typically the default 'ESXi Admins' group) and then re-create it, causing ESXi to treat the re-created group as the original administrator group. This grants the actor full access to the ESXi host without needing ESXi credentials themselves. Only ESXi hosts that were joined to and configured with Active Directory for user management are affected; hosts using local authentication are not. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-30 with known ransomware use, and EPSS assigns a high 26.8% probability of exploitation in the next 30 days (98th percentile).

Do: Apply the security updates or mitigations published in the vendor's (VMware/Broadcom) advisory for your ESXi release, per the CISA KEV required action. As interim mitigation, protect the configured AD admin group (default 'ESXi Admins') from deletion or re-create it with the original identity, and restrict AD permissions that allow arbitrary group deletion. Since ransomware use is known, audit AD logs for deletion/re-creation of the 'ESXi Admins' group and verify integrity of any AD-joined ESXi hosts.

7.227% KEV ransomware
  • VMware ESXi
mass≈100,000+ ESXi hosts (tens of thousands are internet-exposed in public scans, and the installed base is far larger, though only AD-joined hosts are vulnerable)
Full article445 words · extracted from therecord.media · click to collapse

The BlackByte ransomware gang is only posting a fraction of its successful attacks on its leak site this year, according to researchers from Cisco. 

The company’s cybersecurity arm, Talos, said it believes the group is only creating extortion posts for about 20% to 30% of its successful attacks. 

An analysis of the group's leak site shows it posted 41 victims in 2023 and just three so far in 2024. BlackByte has been highly active this year, but it’s unclear why the group isn’t posting more leaks, Cisco Talos said.  

BlackByte is responsible for several high-profile attacks on local governments like Newburgh, New York, and Augusta, Georgia, as well as organizations like the San Francisco 49ers and Yamaha

Cisco Talos researchers said several recent incident response investigations they participated in revealed that the group is evolving rapidly — often leading the way in exploiting vulnerabilities like CVE-2024-37085, a bug in ESXi software  highlighted by Microsoft last month. 

“Talos IR observed the threat actor leveraging this vulnerability, which initially received limited attention from the security community, within days of its publication,” the researchers said. “This highlights the speed with which ransomware groups like BlackByte can adapt their [tactics, techniques and procedures] to incorporate newly disclosed vulnerabilities, and the level of time and effort put into identifying potential avenues for advancing an attack.”

The researchers said the ransomware-as-a-service (RaaS) group is believed to be an offshoot of the now-defunct Conti operation that emerged in late 2021. 

BlackByte has a history of scanning for and exploiting public-facing vulnerabilities, according to Cisco Talos, but the flexibility afforded by the RaaS model “allows threat actors to quickly counter new defensive strategies developed by cybersecurity experts by iterating and updating its tooling.” 

Critical Start cyberthreat researcher Callie Guenther said the exploitation of CVE-2024-37085 stood out because the products it affects — VMware ESXi hypervisors that allow servers to run multiple virtual machines and efficiently allocate computing resources. The focus on ESXi hypervisors by groups like BlackByte is particularly concerning because the technology is often central to the IT infrastructure and vital business applications of enterprises, she added.

“The adoption of the CVE-2024-37085 vulnerability by BlackByte signals an understanding of the value in targeting these systems, as they offer a high return on investment for the attackers in terms of potential ransom payouts,” she said.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/blackbyte-ransomware-group-posting-fraction-of-leaks