Symantec’s Threat Hunter team has identified a sophisticated custom backdoor named “Betruger” linked to a RansomHub affiliate.
This newly discovered backdoor appears to be purpose-built for ransomware operations, consolidating multiple attack functions into a single tool, likely to minimize the attacker’s footprint during campaigns.
The backdoor incorporates an extensive array of capabilities typically distributed across multiple tools in ransomware attacks.
These include screen capture functionality, credential theft mechanisms, keylogging capabilities, network scanning features, and privilege escalation techniques.
Security researchers believe this consolidated approach represents a tactical evolution designed to reduce the number of distinct tools needed during an attack, thereby lowering detection probability.
Symantec has implemented comprehensive protection against this threat through multiple detection layers.
The security vendor’s adaptive-based protections include signatures such as ACM.Ps-RgPst!g1, ACM.Ps-SvcReg!g1, and ACM.Untrst-RunSys!g1, while behavior-based detection identifies the threat as SONAR.TCP!gen1.
File-based detections have been established under various classifications including Backdoor.Betruger, Backdoor.Cobalt, Backdoor.SystemBC, and Ransom.Ransomhub!g1.
Additionally, machine learning algorithms have been deployed to identify the threat through heuristic analysis with signatures like Heur.AdvML.A!300 through Heur.AdvML.C.
VMware Carbon Black products are also effective against this threat, with existing policies blocking associated malicious indicators.
Security experts recommend implementing policies that block all malware types (Known, Suspect, and PUP) and delay execution for cloud scanning to maximize protection.
The discovery of Betruger highlights the ongoing evolution of ransomware tactics, with threat actors increasingly developing custom tools to enhance their operational efficiency.
RansomHub, operating as a Ransomware-as-a-Service platform, continues to demonstrate sophisticated capabilities through its affiliates’ use of advanced custom malware.
Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup – Try for Free
Caido has unveiled version 0.47.0 of its web pentesting tool, cementing its position as a…
Infosys, a leading IT services company, has announced that it has reached an agreement in…
A recent vulnerability in Apache Tomcat, identified as CVE-2025-24813, has sparked concerns among cybersecurity professionals…
Cloudflare has announced that it will shift its APIs to HTTPS-only connections, effectively closing all…
The Cybersecurity and Infrastructure Security Agency (CISA) released five critical advisories related to vulnerabilities and…
A recent cybersecurity threat has been identified, where steganographic malware is being distributed through seemingly…