Cyber Security News

Albabat Ransomware Expands Reach to Target Linux and macOS Platforms

A recent report from Trend Micro has revealed that a new variant of the Albabat ransomware now targets Linux and macOS platforms, marking a significant expansion in its capabilities.

Previously limited to Windows systems, this updated strain demonstrates the evolving sophistication of ransomware threats.

The malware is still under active development, with its multi-OS functionality posing heightened risks to organizations with diverse IT environments.

New Multi-OS Capabilities Detected in Latest Variant

The ransomware operates by encrypting files on infected endpoints, sparing only those stored in specific system-related directories.

Additionally, it exhibits advanced anti-analysis mechanisms by terminating various system processes, including those related to debugging, virtual machines (VMs), and other security tools.

A notable feature of the new variant is its use of the GitHub REST API to retrieve configuration data, showcasing the attackers’ reliance on legitimate cloud services to evade detection.

Detection and Mitigation Measures

Symantec has identified and implemented protections against this threat through multiple detection technologies.

These include adaptive-based signatures such as ACM.Ps-Http!g2 and ACM.Untrst-Bcdedit!g1, behavior-based detections like SONAR.SuspLaunch!gen4, and machine learning algorithms such as Heur.AdvML.A!300.

VMware Carbon Black products also provide robust defenses by blocking malicious indicators and delaying malware execution for cloud-based scans.

The ransomware has been classified under various threat categories, including Ransom.Albabat and Trojan.Gen.MBT.

Network-based detections are also in place to identify suspicious activities such as connections to GitHub cloud services or malicious applications attempting to access cloud storage.

Organizations are advised to enforce strict endpoint security policies, including blocking all forms of unknown or potentially unwanted programs (PUPs) and leveraging advanced reputation services for real-time threat intelligence.

The addition of Linux and macOS support underscores the growing trend of ransomware developers targeting non-Windows platforms to exploit gaps in multi-OS security strategies.

By leveraging cloud-based services like GitHub for operational purposes, attackers further complicate detection efforts while maintaining operational efficiency.

Organizations are urged to adopt a proactive approach by implementing comprehensive endpoint protection solutions, conducting regular security audits, and ensuring all systems are updated with the latest patches.

As ransomware threats like Albabat continue to evolve, maintaining a layered defense strategy remains critical in mitigating potential damages.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup – Try for Free

Aman Mishra

Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Recent Posts

Linux Lite 7.4 Final Released: Enhanced GUI and Bug Fixes

Linux Lite, a popular lightweight Linux distribution aimed at making Linux accessible to beginners, has…

11 minutes ago

Operation HollowQuill – Weaponized PDFs Deliver a Cobalt Strike Malware Into Gov & Military Networks

In a recent revelation by SEQRITE Labs, a highly sophisticated cyber-espionage campaign, dubbed Operation HollowQuill,…

10 hours ago

Earth Alux Hackers Use VARGIET Malware to Target Organizations

A new wave of cyberattacks orchestrated by the advanced persistent threat (APT) group Earth Alux…

10 hours ago

“Lazarus Hackers Group” No Longer Refer to a Single APT Group But a Collection of Many Sub-Groups

The term "Lazarus Group," once used to describe a singular Advanced Persistent Threat (APT) actor,…

10 hours ago

DarkCloud: An Advanced Stealer Malware Sold on Telegram to Target Windows Data

DarkCloud, a highly advanced stealer malware, has emerged as a significant threat to Windows systems…

10 hours ago

Triton RAT Uses Telegram for Remote System Access and Control

Cado Security Labs has uncovered a new Python-based Remote Access Tool (RAT) named Triton RAT,…

10 hours ago