• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

Geek's Advice

IT News, Software Reviews, How To's & Computer Help

  • News
  • Reviews
  • Removal guides
  • Fix
  • Tutorials
  • Forum
  • ASK A GEEK

Ransomware Gangs Begin Using Intermittent Encryption Strategy

September 13, 2022 By Matt Corey Leave a Comment

Cybercriminals begin adapting intermittent encryption techniques in new ransomware attacks

Contents

  • Cybercriminals begin adapting intermittent encryption techniques in new ransomware attacks
  • Cybercriminals promote new encryption features in hacking forums
  • Intermittent encryption to be seen in more ransomware attacks

Cybercriminals are now devising a new method called intermittent encryption that ensures the whole data on target computer gets encrypted much faster. This nascent method works by encrypting just sections of files contained in any system under attack. Speedy data encryption reduces the chances of attack failure, antivirus detection or partial data encryption.

This intermittent encryption tactic is no less dangerous considering that it would still make infected data unrecoverable except with the use of a decryptor and private key. To explain it in detail, this particular encryption process is based on intermittently skipping every [n] bytes of a file, thereby reducing the time required to fully encrypt it and make it useless to the victim.

Also, since its encryption process is less complicated, malware detection software that identify signals released by intense file IO operations might become less efficient.

Ransomware gangs started using new technique called intermittent encryption to lock data stored in target computers

Cybercriminals promote new encryption features in hacking forums

According to a report published by SentinelLabs, the new encryption mode was started by LockFile ransomware in 2021 and was later adapted by other ransomware groups, including Black Basta, Agenda, Qyick, and PLAY. The criminals behind these threats now promote the use of intermittent encryption mode in their operations, which also helps entice others into joining their Raas operations.

Qyick is not only making use of intermittent encryption but has described its speed as unmatched. This statement was contained in a notification the malware promoters dropped in hacking forums.

Qyick ransomware advertisement on dark web forum promoting its RaaS
Qyick ransomware advertisement in a hacking forum.

However, Agenda ransomware, on its part, provides the intermittent encryption as an option that can be enabled and configured in the settings if need be. The user may choose between three encryption modes:

  • Skip-step mode. Parameters ‘skip’ and ‘step’. Encrypts every ‘step’ MB of the file, skips ‘skip’ MB.
  • Fast mode: Parameter ‘f’. Encrypts only the first ‘f’ MB of the file.
  • Percent mode. Parameters ‘n’ and ‘p’ where p must be between 1 and 99. Encrypts every ‘n’ MB of the file, skips ‘p’ MB, where ‘p’ means ‘p’ % of total file size.

This pattern is also similar to BlackCat as they enable configuration choices in order to create a byte-skipping algorithm. There is also an option to encrypt only the initial bytes of any given file, also use a dot pattern, or encrypt certain percentage of file blocks. In addition to that, its auto mode is configured to combine several modes to achieve a more complicated result.

The recent high-profile PLAY ransomware attack on the Argentina’s Judiciary also used intermittent encryption. Note that PLAY does not offer configuration options but rather checks the file size and divides the file into as many as 3 to 5 chunks and encrypts every second chunk.

Lastly, Black-Basta doesn’t enable modes to be selected. The malware decides what to do according to the file size. For files not exceeding 704 bytes in size, it encrypts the whole data. However, for files between 704 bytes and 4 KB, it locks 64 bytes, skips 192 bytes, then again 64 bytes and so on.

example of intermittent encryption performed by Black-Basta ransomware
Intermittent data encryption by Black-Basta ransomware (source: App.Any.Run)

If the file size exceeds 4 KB, Black-Basta ransomware reduces the unaffected byte intervals to 128 bytes while the encrypted sections still remain at 64 bytes.

Intermittent encryption to be seen in more ransomware attacks

From what we have deduced so far, intermittent encryption has huge advantages and probably no significant drawback. Therefore, an increasing number of cybercriminals are likely to join the bandwagon in the future. Speed is one of the most important factors to ransomware operators, as they seek to lock large data amounts unnoticed.

At the moment, LockBit’s version appears to have the fastest encryption speed, so if cybercriminals decide to make use of the partial encryption method, the time required to make victim’s files inaccessible would be shortened even more.

Nevertheless, cybercriminals understand that encryption must be complex enough to prevent independent decryption regardless of whether intermittent encryption was used or not. So far, BlackCat format seems to be highly sophisticated while new Qyick samples, on the other hand, haven’t been analyzed by malware researchers yet.

Computer users and companies should take action to implement required cybersecurity measures. A good start would be installing a robust antivirus engine, configuring a firewall and ensuring that secure RDP credentials are used.

Matt Corey Geeks Advice
Matt Corey

Matt Corey is passionate about the latest tech news, gadgets and everything IT. Matt loves to criticize Windows and help people solve problems related to this operating system. When he’s not tinkering around with new gadgets he orders, he enjoys skydiving, as it is his favorite way to clear his mind and relax.

Related posts:

  1. Fake Windows 10 Updates Infect Computers with Magniber Ransomware Threat actors use Windows updates as a bait to spread...
  2. Protection Against Ransomware – Best Practices in 2021 Protection against ransomware is essential as attack cases increaseContentsProtection against...
  3. Woman dies after German hospital hack, ransomware operators suspected of negligent homicide Cybercriminals have gone too far – patient died after German...

Filed Under: News Tagged With: Encryption, ransomware, Windows

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

SEARCH OUR SITE

Trending

decrypt files locked by stop djvu ransomware virus

Decrypt Files Locked by STOP/DJVU Ransomware (Updated 2023 Guide)

Some STOP/DJVU ransomware victims can decrypt or … [Read More...] about Decrypt Files Locked by STOP/DJVU Ransomware (Updated 2023 Guide)

Remove STOP/DJVU Ransomware Virus (2023 Guide)

STOP/DJVU in 2023: more than 670 versions, latest … [Read More...] about Remove STOP/DJVU Ransomware Virus (2023 Guide)

Remove Segurazo Antivirus (SAntivirus Removal Guide 2023)

Segurazo review: is it a virus? Segurazo … [Read More...] about Remove Segurazo Antivirus (SAntivirus Removal Guide 2023)

easy ways to fix dns_probe_finished_nxdomain error on windows, mac, android, chromebook

Fix DNS_PROBE_FINISHED_NXDOMAIN Error (Windows, Mac, Android, Chromebook)

DNS_PROBE_FINISHED_NXDOMAIN error … [Read More...] about Fix DNS_PROBE_FINISHED_NXDOMAIN Error (Windows, Mac, Android, Chromebook)

POPULAR SOFTWARE REVIEWS

Private Internet Access Review

Private Internet Access Review 2023: Fast, Secure & Cheap VPN

Private Internet Access (PIA) VPN maintains its long-term role as a leader Private Internet … [Read More...] about Private Internet Access Review 2023: Fast, Secure & Cheap VPN

restoro review 2020

Restoro Review 2023: Best Windows Repair Tool?

What is Restoro and how it works? Restoro is primarily a PC repair software designed for Windows … [Read More...] about Restoro Review 2023: Best Windows Repair Tool?

INTEGO antivirus review for Mac 2021

Intego Antivirus Review: Best Mac Antivirus in 2023?

Intego Antivirus for Mac is probably the best security choice for OS X Intego Antivirus for Mac … [Read More...] about Intego Antivirus Review: Best Mac Antivirus in 2023?

OUR EXPERTS RECOMMEND

Comprehensive PC Repair Software

geek's advice recommends restoro pc repair as editors choice
DOWNLOAD NOW
  • Uses Avira engine to remove malware
  • Repairs Virus Damage
  • Fixes Windows Errors & BSOD
  • Replaces Damaged DLLs
  • Repairs Damaged Windows Settings
  • Identifies Hardware Problems

Compatible with Microsoft Windows.

Read Full Review

Robust Mac Antivirus

geek's advice recommends intego mac internet security x9 as editors choice
GET INTEGO
  • 24/7 real-time protection
  • Intelligent firewall
  • Scans emails for malware
  • Scans iOS devices & external drives
  • Excellent malware detection rate
  • Easy-to-use

Compatible with Mac OS X 10.9-12.

Read Full Review

Copyright © 2023 Geeksadvice.com. Any unauthorized copying, redistribution or reproduction of part or all of the site contents in any form is prohibited.

About Us · Terms of Use · Privacy Policy · Contact Us