Ransomware impersonates employees and self-spreads

April 2024 News & Events

Following a recent incident, the Kaspersky Global Emergency Response team is shedding light on an attack where adversaries crafted their own variant of encryption malware equipped with self-propagation capabilities. Exploiting stolen privileged administrator credentials, the cybercriminals breached infrastructure. This incident took place in West Africa, but other regions are also experiencing attacks with builder-based ransomware, albeit lacking the sophisticated features observed in this case.

The latest incident occurred in Guinea-Bissau, revealing that custom ransomware employs unseen techniques. It can create an uncontrolled avalanche effect, with infected hosts attempting to spread the malware further within the victim’s network. After the recent occurrence, Kaspersky is providing a detailed analysis.

Impersonation. The threat actor impersonates the system administrator with privileged rights by leveraging illicitly acquired credentials. This scenario is critical, as privileged accounts provide extensive opportunities to execute the attack and gain access to the most critical areas of the corporate infrastructure.

Self-spreading. The customised ransomware can also spread autonomously across the network using highly privileged domain credentials and conduct malicious activities, such as disabling Windows Defender, encrypting network shares, and erasing Windows Event Logs to encrypt data and conceal its actions. The malware’s behaviour results in a scenario where each infected host attempts to infect other hosts within the network.

Adaptive features. The customised configuration files and the aforementioned features enable the malware to tailor itself to the specific configurations of the victimised company’s architecture. For example, the attacker can configure the ransomware to infect only specific files, such as all .xlsx and .docx files, or only a set of specific systems.

When executing this custom build in a virtual machine, Kaspersky observed it performing malicious activities and generating a custom ransom note on the desktop. In real scenarios, this note includes details on how the victim should contact the attackers to obtain the decryptor.

“The LockBit 3.0 builder was leaked in 2022, but attackers still actively use it to create customised versions – and it does not even require advanced programming skills. This flexibility gives adversaries many opportunities to enhance the effectiveness of their attacks, as the recent case shows. It makes these kinds of attacks even more dangerous, considering the escalating frequency of corporate credential leaks,” says Cristian Souza, Incident Response Specialist at Kaspersky Global Emergency Response Team.

Kaspersky also found that attackers used the SessionGopher script to locate and extract saved passwords for remote connections in the affected systems.

LockBit is a cybercriminal group offering ransomware as a service (RaaS). In February 2024, an international law-enforcement operation seized control of the group. A few days after the operation, the ransomware group defiantly announced that it was back in action.

Measures to mitigate ransomware attacks

• Implement a frequent backup schedule and conduct regular testing.

• Deploy robust security solutions.

• Reduce your attack surface by disabling unused services and ports.

• Maintain up-to-date systems and software to patch vulnerabilities promptly.

• Regularly perform penetration tests and vulnerability scanning to detect weaknesses and implement appropriate countermeasures.

• Provide regular cybersecurity training to employees to increase awareness of cyber threats and mitigation strategies.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

AURA appoints Taryn Winer as global head of people
News & Events Security Services & Risk Management
Following its €13,5 million Series B funding round last year and accelerating international expansion, particularly across the United States, AURA has appointed Taryn Winer as global head of people.

Read more...
Gallagher Security releases new fence controllers
Perimeter Security, Alarms & Intruder Detection News & Events
Gallagher Security has announced the release of its new F5 and F6 Fence Controllers, marking the latest generation of enhanced-safety, monitored-pulse fence technology, designed to meet the demands of modern security environments.

Read more...
Paxton set to launch game-changing new system
Paxton Access Control & Identity Management News & Events
Access control is evolving fast. Installers and end users are looking for systems that are simple to install, easy to manage remotely, and flexible enough to scale. In response, Paxton is exploring how emerging technologies can reshape access control.

Read more...
From the editor's desk: When the rules change
Technews Publishing News & Events
         Welcome to the SMART Surveillance & AI Handbook 2026. We were a bit nervous about including AI in the title, since it either has a good or bad reputation depending on the individual – very few people ...

Read more...
Proactive estate security in Cape Town
neaMetrics OneSpace Technologies Technews Publishing SMART Security Solutions Fang Fences & Guards ATG Digital Editor's Choice News & Events Integrated Solutions Infrastructure Residential Estate (Industry)
SMART Security Solutions started the year with our annual SMART Estate Security Conference in Cape Town on 26 February 2026. Held at Anna Beulah Farm, the conference saw a number of delegates enjoying the farm’s excellent cuisine, while listening to outstanding presenters.

Read more...
The impact of misguided viral campaigns
News & Events Training & Education
For many years, traditional media have been perceived as slower, more inflexible, and less responsive compared to digital platforms. But in an ecosystem flooded with content, its value is becoming clearer: verification, context, and accountability.

Read more...
Gallagher Security strengthens KwaZulu-Natal presence
Gallagher News & Events Integrated Solutions
Gallagher Security has reinforced its commitment to the KwaZulu-Natal region with its Command the Future event. The full-day event welcomed over 100 channel partners, end users, and consultants, marking Gallagher’s third major event in Durban.

Read more...
Rise in malicious insider threat reports
News & Events Information Security
Mimecast Study finds 46% of SA organisations report a rise in malicious insider threat reports over the past year: reveals disconnect between security awareness and technical controls as AI-powered attacks accelerate.

Read more...
Centurion raises the bar at HomeSec Expo
Centurion Systems News & Events Access Control & Identity Management Residential Estate (Industry) Smart Home Automation Commercial (Industry)
Centurion Systems unveiled its latest product lines at HomeSec Expo 2026, introducing SMART+, a simpler way for installers and end users to manage their Centurion installations - as well as a few new products.

Read more...
Duxbury SA Milesight distributor
Duxbury Networking News & Events Surveillance
Duxbury Networking has been appointed the exclusive distributor of Milesight surveillance solutions in South Africa, expanding its surveillance portfolio with a platform designed to deliver AI-driven analytics, rapid deployment, and open integration for modern security environments.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.