Cyber Security News

RansomHub Affiliate Deploys New Custom Backdoor “Betruger” for Persistent Access

Symantec’s Threat Hunter team has identified a sophisticated custom backdoor named “Betruger” linked to a RansomHub affiliate.

This newly discovered backdoor appears to be purpose-built for ransomware operations, consolidating multiple attack functions into a single tool, likely to minimize the attacker’s footprint during campaigns.

Advanced Multi-Function Malware Discovered

The backdoor incorporates an extensive array of capabilities typically distributed across multiple tools in ransomware attacks.

These include screen capture functionality, credential theft mechanisms, keylogging capabilities, network scanning features, and privilege escalation techniques.

Security researchers believe this consolidated approach represents a tactical evolution designed to reduce the number of distinct tools needed during an attack, thereby lowering detection probability.

Protection and Detection Mechanisms

Symantec has implemented comprehensive protection against this threat through multiple detection layers.

The security vendor’s adaptive-based protections include signatures such as ACM.Ps-RgPst!g1, ACM.Ps-SvcReg!g1, and ACM.Untrst-RunSys!g1, while behavior-based detection identifies the threat as SONAR.TCP!gen1.

File-based detections have been established under various classifications including Backdoor.Betruger, Backdoor.Cobalt, Backdoor.SystemBC, and Ransom.Ransomhub!g1.

Additionally, machine learning algorithms have been deployed to identify the threat through heuristic analysis with signatures like Heur.AdvML.A!300 through Heur.AdvML.C.

VMware Carbon Black products are also effective against this threat, with existing policies blocking associated malicious indicators.

Security experts recommend implementing policies that block all malware types (Known, Suspect, and PUP) and delay execution for cloud scanning to maximize protection.

The discovery of Betruger highlights the ongoing evolution of ransomware tactics, with threat actors increasingly developing custom tools to enhance their operational efficiency.

RansomHub, operating as a Ransomware-as-a-Service platform, continues to demonstrate sophisticated capabilities through its affiliates’ use of advanced custom malware.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup – Try for Free

Aman Mishra

Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Recent Posts

Caido v0.47.0 Released – A Web Pentesting Tool Alternative to Burp Suite

Caido has unveiled version 0.47.0 of its web pentesting tool, cementing its position as a…

17 minutes ago

Infosys to Pay $17.5M in Settlement for 2023 Data Breach

Infosys, a leading IT services company, has announced that it has reached an agreement in…

38 minutes ago

Tomcat RCE Vulnerability Exploited in the Wild – Mitigation Steps Outlined

A recent vulnerability in Apache Tomcat, identified as CVE-2025-24813, has sparked concerns among cybersecurity professionals…

1 hour ago

Cloudflare Shifts to HTTPS-Only for APIs, Closing All HTTP Ports

Cloudflare has announced that it will shift its APIs to HTTPS-only connections, effectively closing all…

2 hours ago

CISA Issues Five Advisories on Industrial Control System Vulnerabilities and Exploits

The Cybersecurity and Infrastructure Security Agency (CISA) released five critical advisories related to vulnerabilities and…

2 hours ago

New Steganographic Malware Hides in JPEG Files to Spread Infostealers

A recent cybersecurity threat has been identified, where steganographic malware is being distributed through seemingly…

14 hours ago