Rust Goes Wild
Ransomware-as-a-service crews such as BlackCat, Hive and RansomExx have developed their own versions of their ransomware in Rust. Trend Micro said its researchers had recently found in the wild a sample of the Agenda ransomware written in Rust language and detected as Ransom.Win32.AGENDA.THIAFBB.As Trend Micro wrote:“The Agenda ransomware is also known to deploy customized ransomware for each victim, and we have seen that its Rust variants have an allocated space for adding accounts in their configuration to be used mostly for privilege escalation.”
Rust Tactics Examined
The Rust variant has also been seen using intermittent encryption, a tactic used by threat actors for faster encryption and detection evasion, Trend Micro said.According to Trend Micro:“The actors customized previous ransomware binaries for the intended victim through the use of confidential information such as leaked accounts and unique company IDs as the appended file extension."
“Threat actors continue to favor ransomware as their tool of choice for conducting their operations, reiterating the call for enterprises and organizations to rely on a multilayered solution to secure data."