Monti Gang Launches Updated Ransomware Targeting Linux

The Monti ransomware threat group has reappeared following a hiatus of two months, introducing a new version of their encryptor designed for Linux systems. The group has shifted their focus towards government and legal sectors in their recent attacks.

Initially emerging in June 2022, shortly after the Conti ransomware group ceased its operations, Monti had been imitating Conti's methods and tools, even incorporating leaked source code from Conti. However, this pattern has changed with the latest version.

Monti Takes a Page from Conti's Book

According to Trend Micro, this new variant marks a notable departure from its previous Linux-based iterations. Unlike the earlier version, which heavily relied on the leaked Conti source code, the recent release utilizes a distinct encryptor and displays new behaviors, as outlined by Trend Micro's researchers Nathaniel Morales and Joshua Paul Ignacio.

Through a BinDiff analysis, it was discovered that while previous versions displayed a 99% similarity to Conti, the current version only demonstrates a 29% similarity. This drastic decrease in similarity points toward a substantial overhaul.

Key alterations include introducing a '--whitelist' parameter to bypass encrypting specific virtual machines, alongside the removal of command-line arguments like '--size,' '--log,' and '--vmlist.'

Additionally, the Linux variant has been engineered to manipulate the motd (message of the day) file in order to exhibit the ransom note. Instead of utilizing Salsa20 encryption, it now employs AES-256-CTR encryption. Moreover, the encryption process now depends solely on file size. To elaborate, files larger than 1.048 MB but smaller than 4.19 MB will only have the initial 100,000 bytes encrypted. On the other hand, files exceeding 4.19 MB will have a portion of their content locked, contingent on the outcome of a Shift Right operation. Files below 1.048 MB in size will be entirely encrypted.

Trend Micro's researchers suggest that while elements of the Conti source code likely serve as the foundation for this new Monti variant, significant modifications have been introduced to the code, particularly regarding the encryption algorithm.

August 16, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.