PYSA Gang Employs the ChaChi Trojan to Deliver Ransomware

Ransomware gangs often rely on a wide range of malware families to gain complete control over infected systems, as well as to spread laterally across entire networks. One of the ransomware gangs to recently introduce a new Trojan in their arsenal is the PYSA Ransomware or Mespinoza Ransomware gang. Allegedly, they are using a previously undetected Trojan called ChaChi. It has already been used in attacks against US-based entities operating in the government and educational sectors.

Just like many other malware developers, the PYSA gang have also decided to rely on the Golang programming language. More and more cybercriminals use Golang because its malicious behavior is, technically, slightly more difficult to detect. This increases PYSA gang's odds of evading antivirus tools and other network security products.

But what does the ChaChi Trojan Do?

The ChaChi Trojan appears to be a well-developed project, which has features and properties typical for Remote Access Trojan (RAT.) The threat is able to gain persistence on compromised Windows machines by abusing Windows Registry keys, as well as the task scheduling service. Furthermore, its operators gain the ability to access and manipulate the file system, steal credentials, create proxy servers, execute remote commands, and more.

Despite all of these fancy features, many of the recent attacks to involve the ChaChi Trojan had one end goal – to drop a ransomware implant. Of course, the PYSA gang used their own ransomware in these attacks. The criminals do not go after regular consumers, and, instead, their sights are set onto high-value targets, which may opt to pay hundreds of thousands of dollars to get their data back.

Targets of the ChaChi Trojan may be approached through fraudulent emails, asking them to review an attachment or to download a file. Employees must be careful with random emails asking them to interact with attachments. Furthermore, their workstations should be regularly patched and protected by trustworthy antivirus tools.

June 25, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.