Ransomware-Bande nimmt IT-Mitarbeiter mit neuer SharpRhino-Malware ins Visier

Teilen:

The Hunters International ransomware group is targeting IT workers with a new C# remote access trojan (RAT) called SharpRhino to breach corporate networks.

The malware helps Hunters International achieve initial infection, elevate their privileges on compromised systems, execute PowerShell commands, and eventually deploy the ransomware payload.

Quorum Cyber researchers who observed the malware used in a ransomware attack report that it is disseminated by a typosquatting site impersonating the website for Angry IP Scanner, a legitimate networking tool used by IT professionals.

In January 2024, cybersecurity firm eSentire and researcher 0xBurgers previously saw the malware distributed through a fake Advanced IP Scanner website.

Hunters International is a ransomware operation launched in late 2023 and flagged as a possible rebrand of Hive due to its code similarities.

Notable victims include U.S. Navy contractor Austal USA, Japanese optics giant Hoya, Integris Health, and the Fred Hutch Cancer Center, where the cybercriminals demonstrated their lack of moral boundaries.

So far, in 2024, the threat group has announced 134 ransomware attacks against various organizations worldwide (except for CIS), ranking it tenth among the most active groups in the space.

SharpRhino RAT

SharpRhino spreads as a digitally signed 32-bit installer (‘ipscan-3.9.1-setup.exe’) containing a self-extracting password-protected 7z archive with additional files to perform the infection.

The installer modifies the Windows registry for persistence and creates a shortcut to Microsoft.AnyKey.exe, normally a Microsoft Visual Studio binary that is abused in this case.

Additionally, the installer drops ‘LogUpdate.bat’, which executes PowerShell scripts on the device to compile C# into memory for stealthy malware execution.

For redundancy, the installer creates two directories, ‘C:\ProgramData\Microsoft: WindowsUpdater24’ and ‘LogUpdateWindows,’ which are both used in the command and control (C2) exchange.

Two commands are hardcoded onto the malware, namely ‘delay,’ to set the timer of the next POST request for retrieving a command, and ‘exit,’ to terminate its communication.

Analysis shows that the malware can execute PowerShell on the host, which can be used to perform various dangerous actions.

Quorum tested this mechanism by successfully launching the Windows calculator through SharpRhino.

Hunters International’s new tactic of deploying websites to impersonate legitimate open-source network scanning tools indicates that they are targeting IT workers in the hopes of breaching accounts with elevated privileges.

Users should be careful of sponsored results in search results to evade malvertising, activate ad blockers to hide these results entirely, and bookmark official project sites known to procure safe installers.

To mitigate the effects of ransomware attacks, establish a backup plan, perform network segmentation, and ensure all software is up to date to reduce opportunities for privilege elevation and lateral movement.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
2:12 am, Juni 21, 2025
Wetter-Symbol 18°C
L: 16° | H: 19°
klarer Himmel
Luftfeuchtigkeit: 76 %
Druck: 1020 mb
Wind: 7 mph ENE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 0%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
16° | 19°°C 0.2 mm 20% 10 mph 71 % 1020 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
18° | 26°°C 0.34 mm 34% 15 mph 77 % 1013 mb 0 mm/h
Mo. Juni 23 10:00 pm
Wetter-Symbol
15° | 23°°C 0 mm 0% 14 mph 75 % 1016 mb 0 mm/h
Di. Juni 24 10:00 pm
Wetter-Symbol
15° | 25°°C 0.2 mm 20% 14 mph 72 % 1016 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
17° | 21°°C 1 mm 100% 10 mph 85 % 1011 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
17° | 18°°C 0 mm 0% 4 mph 71 % 1020 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
19° | 20°°C 0 mm 0% 6 mph 56 % 1019 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
27° | 27°°C 0 mm 0% 8 mph 34 % 1018 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
31° | 31°°C 0 mm 0% 9 mph 25 % 1017 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
32° | 32°°C 0 mm 0% 10 mph 23 % 1016 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
26° | 26°°C 0 mm 0% 9 mph 27 % 1014 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
25° | 25°°C 0.2 mm 20% 5 mph 39 % 1014 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
21° | 21°°C 0.34 mm 34% 7 mph 66 % 1013 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€89,576.16
-1.29%
Ethereum(ETH)
€2,093.25
-4.33%
Fesseln(USDT)
€0.87
0.00%
XRP(XRP)
€1.84
-2.27%
Solana(SOL)
€121.49
-4.53%
USDC(USDC)
€0.87
0.01%
Dogecoin(DOGE)
€0.141019
-4.81%
Shiba Inu(SHIB)
€0.000010
-2.24%
Pepe(PEPE)
€0.000009
-3.00%
Peanut das Eichhörnchen(PNUT)
€0.218233
13.10%
Nach oben scrollen