Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.



08:30 AM
Larry Loeb
Larry Loeb
Larry Loeb

Enterprise Is the Target of 'Big Game Hunting'

GrandCrab has mutated, and enterprises should be worried.

A ransomware malware called GrandCrab has been active for the last year, but is now showing some changes in how it is spread. Researchers from Crowdstrike noted in a recent blogthat the newest version of it (5.2) is being rented as a service to affiliates who are sophisticated in "remote desktop protocol (RDP) and VNC (Virtual Network Computing) skills, and spammers who have experience in corporate networking."

These kinds of skills are needed to move into what has been called "big game hunting," which is targeted, low-volume/high-return ransomware deployments for enterprise installations. Crowdstrike says that the originating threat actor (whom they call PINCHY SPIDER) allows a limited number of accounts to rent the malware, and gives a 60-40 split in profits (60% to the customer). They also say that PINCHY SPIDER will negotiate up to a 70-30 split for "sophisticated" customers. The ads for affiliates on hacker forums are in the Russian language.

GrandCrab has a history of being thwarted by the cybersecurity community. A series of successful mitigations and decryptors have been developed by defenders as the malware morphs and changes methods. PINCHY SPIDER has retaliated by redeveloping the ransomware every time and even devised a zero-day exploit to aid in deployment. Crowdstrike observed that this new version of GrandCrab was involved in more sophisticated kinds of deployment than usually seen in ransomware attacks.

First looking around the victim installation, a threat actor affiliate was able to move laterally around the victim's network through the use of RDP and stolen credentials. In this effort, the affiliate used system administration tools such as Sysinternals Process Monitor, Process Hacker, and a file search tool called LAN Search Pro. They were able to end up deploying GrandCrab across several other hosts.

The push to spread over networks continued. In other attempts observed by Crowdstrike, control of the enterprise domain controller was obtained. Once this happened, the affiliate used the enterprise's own IT systems management software (LANDesk) to deploy the Phorpiex Downloader to hosts across the enterprise.

The downloader will spread itself to all the removable drives on the infected machines so as to further propagate itself throughout the network. Only then does it download and execute GrandCrab on the infected hosts.

How they charge for decrypting files is unusual compared to other ransomware efforts. PINCHY SPIDER encrypts individual hosts on the enterprise network and requests payment on a per-host basis, rather than a bulk payment for all the machines on a network.

As Crowdstrike puts it, "Running successful big game hunting operations results in a higher average profit per victim, allowing adversaries like PINCHY SPIDER and their partners to increase their criminal revenue quickly."

It seems ransomware is too profitable to disappear. Enterprises have to realize that their networks will come under new attacks as criminals find new ways to make their ill-gotten gains.

— Larry Loeb has written for many of the last century's major "dead tree" computer magazines, having been, among other things, a consulting editor for BYTE magazine and senior editor for the launch of WebWeek.

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Current Issue
Enterprise Cybersecurity Plans in a Post-Pandemic World
Download the Enterprise Cybersecurity Plans in a Post-Pandemic World report to understand how security leaders are maintaining pace with pandemic-related challenges, and where there is room for improvement.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2021-09-25
There is an information leak vulnerability in the message service app of a ZTE mobile phone. Due to improper parameter settings, attackers could use this vulnerability to obtain some sensitive information of users by accessing specific pages.
PUBLISHED: 2021-09-24
Shopkit v2.7 contains a reflective cross-site scripting (XSS) vulnerability in the /account/register component, which allows attackers to hijack user credentials via a crafted payload in the E-Mail text field.
PUBLISHED: 2021-09-24
A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attackers to delete all users.
PUBLISHED: 2021-09-24
OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP trap supplied data. By creating a malicious SNMP trap, an attacker can store an XSS payload which will trigger when a user of the web UI views the events list page. This issue was fixed in ver...
PUBLISHED: 2021-09-24
OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP agent supplied data. By creating a malicious SNMP 'sysName' or 'sysContact' response, an attacker can store an XSS payload which will trigger when a user of the web UI views the data. This iss...