์œ„ํ˜‘ ํ‰๊ฐ€ : Royal Ransomware

์œ„ํ˜‘ ํ‰๊ฐ€ : Royal Ransomware

Royal Ransomware๊ฐ€ 2022๋…„ 9์›”๋ถ€ํ„ฐ ๊ด€์ฐฐ๋œ ์ด๋ž˜๋กœ ์ค‘์š”ํ•œ ์ธํ”„๋ผ, ํŠนํžˆ ์˜๋ฃŒ ์„œ๋น„์Šค๋ฅผ ๊ณต๊ฒฉํ•˜๋Š” ๊ฐœ์ธ ๊ทธ๋ฃน์œผ๋กœ ๊ตฌ์„ฑ๋˜์—ˆ์œผ๋ฉฐ, Batloader ๊ฐ์—ผ์„ ํ†ตํ•ด ํƒ€ํ˜‘ํ•˜๊ณ  SEO ์ค‘๋…์„ ํ†ตํ•ด ํผ์ ธ ์žˆ์Šต๋‹ˆ๋‹ค. ELF ๋ณ€ํ˜•์„ ๊ฐœ๋ฐœํ•˜์—ฌ Linux ๋ฐ ESXI ํ™˜๊ฒฝ์— ์˜ํ–ฅ์„ ๋ฏธ์น˜๊ณ , RSA ๊ณต๊ฐœ ํ‚ค ๋ฐ ๋žœ์„ฌ์›จ์–ด ๋…ธํŠธ๋ฅผ ํฌํ•จํ•œ ๋ฌธ์ž์—ด์€ ์ผ๋ฐ˜ ํ…์ŠคํŠธ๋กœ ์ €์žฅ๋ฉ๋‹ˆ๋‹ค. Cortex XDR์˜ ๋žœ์„ฌ์›จ์–ด ๊ทธ๋ฃน๊ณผ ์ฐจ์„ธ๋Œ€ ๋ฐฉํ™”๋ฒฝ์˜ ์‚ฐ๋ถˆ ํด๋ผ์šฐ๋“œ ์ œ๊ณต ๋ณด์•ˆ ์„œ๋น„์Šค๋ฅผ ์ด์šฉํ•˜์—ฌ ๋ณดํ˜ธํ•˜๊ณ , ์‚ฌ์ „ ํ‰๊ฐ€๋ฅผ ์ œ๊ณตํ•˜์—ฌ ํƒ€ํ˜‘์„ ๋•๊ณ  ์œ„ํ—˜์„ ๋‚ฎ์ถœ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Threat Assessment: Royal Ransomware

Since Royal Ransomware has been observed since September 2022, it has been composed of important infrastructure, especially individual groups that attack medical services, compromised through Batloader infections and spread through SEO addiction.It develops ELF deformation and affects Linux and ESXI environments, and strings including RSA public and ransomware notes are stored in regular text.Cortex XDRโ€™s ransomware groups and forest fires of next -generation firewalls can be protected to protect and provide preliminary evaluations to help compromise and lower risks.

https://unit42.paloaltonetworks.com/royal-ransomware/