Ransomware gang targets IT workers with new SharpRhino malware

Share:

The Hunters International ransomware group is targeting IT workers with a new C# remote access trojan (RAT) called SharpRhino to breach corporate networks.

The malware helps Hunters International achieve initial infection, elevate their privileges on compromised systems, execute PowerShell commands, and eventually deploy the ransomware payload.

Quorum Cyber researchers who observed the malware used in a ransomware attack report that it is disseminated by a typosquatting site impersonating the website for Angry IP Scanner, a legitimate networking tool used by IT professionals.

In January 2024, cybersecurity firm eSentire and researcher 0xBurgers previously saw the malware distributed through a fake Advanced IP Scanner website.

Hunters International is a ransomware operation launched in late 2023 and flagged as a possible rebrand of Hive due to its code similarities.

Notable victims include U.S. Navy contractor Austal USA, Japanese optics giant Hoya, Integris Health, and the Fred Hutch Cancer Center, where the cybercriminals demonstrated their lack of moral boundaries.

So far, in 2024, the threat group has announced 134 ransomware attacks against various organizations worldwide (except for CIS), ranking it tenth among the most active groups in the space.

SharpRhino RAT

SharpRhino spreads as a digitally signed 32-bit installer (‘ipscan-3.9.1-setup.exe’) containing a self-extracting password-protected 7z archive with additional files to perform the infection.

The installer modifies the Windows registry for persistence and creates a shortcut to Microsoft.AnyKey.exe, normally a Microsoft Visual Studio binary that is abused in this case.

Additionally, the installer drops ‘LogUpdate.bat’, which executes PowerShell scripts on the device to compile C# into memory for stealthy malware execution.

For redundancy, the installer creates two directories, ‘C:\ProgramData\Microsoft: WindowsUpdater24’ and ‘LogUpdateWindows,’ which are both used in the command and control (C2) exchange.

Two commands are hardcoded onto the malware, namely ‘delay,’ to set the timer of the next POST request for retrieving a command, and ‘exit,’ to terminate its communication.

Analysis shows that the malware can execute PowerShell on the host, which can be used to perform various dangerous actions.

Quorum tested this mechanism by successfully launching the Windows calculator through SharpRhino.

Hunters International’s new tactic of deploying websites to impersonate legitimate open-source network scanning tools indicates that they are targeting IT workers in the hopes of breaching accounts with elevated privileges.

Users should be careful of sponsored results in search results to evade malvertising, activate ad blockers to hide these results entirely, and bookmark official project sites known to procure safe installers.

To mitigate the effects of ransomware attacks, establish a backup plan, perform network segmentation, and ensure all software is up to date to reduce opportunities for privilege elevation and lateral movement.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
2:00 am, Jan 22, 2025
weather icon 3°C
L: 2° | H: 3°
mist
Humidity: 90 %
Pressure: 1007 mb
Wind: 1 mph SE
Wind Gust: 2 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 4 km
Sunrise: 7:52 am
Sunset: 4:31 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
2° | 3°°C 1 mm 100% 5 mph 95 % 1006 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
2° | 8°°C 1 mm 100% 17 mph 94 % 1005 mb 0 mm/h
Fri Jan 24 9:00 pm
weather icon
6° | 10°°C 1 mm 100% 24 mph 91 % 1004 mb 0 mm/h
Sat Jan 25 9:00 pm
weather icon
4° | 6°°C 0.89 mm 89% 8 mph 86 % 1012 mb 0 mm/h
Sun Jan 26 9:00 pm
weather icon
5° | 8°°C 0.2 mm 20% 14 mph 86 % 1011 mb 0 mm/h
Today 3:00 am
weather icon
3° | 3°°C 0 mm 0% 3 mph 90 % 1006 mb 0 mm/h
Today 6:00 am
weather icon
3° | 3°°C 0.8 mm 80% 3 mph 92 % 1006 mb 0 mm/h
Today 9:00 am
weather icon
3° | 4°°C 1 mm 100% 3 mph 94 % 1005 mb 0 mm/h
Today 12:00 pm
weather icon
4° | 4°°C 0.8 mm 80% 4 mph 91 % 1003 mb 0 mm/h
Today 3:00 pm
weather icon
4° | 4°°C 0 mm 0% 5 mph 89 % 1002 mb 0 mm/h
Today 6:00 pm
weather icon
3° | 3°°C 0 mm 0% 3 mph 87 % 1003 mb 0 mm/h
Today 9:00 pm
weather icon
2° | 2°°C 0 mm 0% 4 mph 95 % 1004 mb 0 mm/h
Tomorrow 12:00 am
weather icon
2° | 2°°C 0 mm 0% 3 mph 94 % 1004 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€101,415.65
4.40%
Ethereum(ETH)
€3,192.40
2.59%
XRP(XRP)
€3.06
2.81%
Tether(USDT)
€0.96
0.13%
Solana(SOL)
€241.91
6.62%
Dogecoin(DOGE)
€0.353595
6.42%
USDC(USDC)
€0.96
0.00%
Shiba Inu(SHIB)
€0.000020
2.88%
Pepe(PEPE)
€0.000015
2.70%
Peanut the Squirrel(PNUT)
€0.354125
-1.82%
Scroll to Top