Hacking

New Ymir Ransomware Uses Stealth Techniques and Targeted Attacks

Published  ·  3 min read
Updated on November 12, 2024

Cybersecurity researchers have identified a new ransomware strain named Ymir, deployed in a recent cyberattack only two days after the targeted system was compromised by the RustyStealer malware.

"Ymir ransomware introduces a unique combination of technical features and tactics that enhance its effectiveness," said Kaspersky, a Russian cybersecurity vendor.

This ransomware takes a unique approach by leveraging specific memory management functions—malloc, memmove, and memcmp—to execute malicious code in memory, creating a more stealthy attack compared to traditional ransomware that follows sequential code execution.

Kaspersky observed that Ymir ransomware was used in a cyberattack targeting an unnamed Colombian organization. The attackers initially deployed RustyStealer to obtain corporate credentials, which were later used to gain unauthorized access and deploy the ransomware. Although it’s common for a hand-off to occur between an initial access broker and ransomware operators, it’s unclear if that happened here.

"If the brokers are indeed the same actors who deployed the ransomware, this could signal a new trend, enabling additional hijacking opportunities without needing traditional Ransomware-as-a-Service (RaaS) groups," commented Kaspersky researcher Cristian Souza.

In the attack, the threat actors used tools like Advanced IP Scanner and Process Hacker. They also deployed SystemBC malware scripts, creating a covert channel to a remote IP to exfiltrate files over 40 KB in size that were generated after a specified date.

The Ymir ransomware binary uses the ChaCha20 stream cipher to encrypt files, appending the extension “.6C5oy2dVr6” to each encrypted file. “Ymir is flexible: attackers can specify a directory to target files using the --path command. A whitelist feature allows certain files to remain unencrypted, giving attackers more control over the encryption process,” Kaspersky said.

Meanwhile, another ransomware group, Black Basta, has been observed using social engineering tactics, including sending Microsoft Teams messages and malicious QR codes to initiate attacks, redirecting victims to fraudulent domains. ReliaQuest reported that this tactic aims to convince users to download remote monitoring tools for initial access, leading to eventual ransomware deployment.

In other cases, attackers pose as IT support, tricking users into installing AnyDesk or using Quick Assist to gain remote access—a technique Microsoft previously warned about.

Ymir Ransomware: An earlier iteration of the Ymir attack involved malspam tactics, bombarding inboxes with emails and following up with phone calls posing as IT help desk support.

Other ransomware strains, such as Akira and Fog, have recently exploited unpatched SonicWall SSL VPNs with vulnerabilities (CVE-2024-40766), resulting in over 30 confirmed incidents from August to mid-October 2024, as reported by Arctic Wolf.

These developments underscore the evolving landscape of ransomware threats, with law enforcement crackdowns leading to a more fragmented ecosystem. Secureworks, soon to be acquired by Sophos, reported a 30% increase in active ransomware groups year-over-year, adding 31 new groups.

However, even with an uptick in new groups, victim numbers have not increased at the same rate, highlighting a more complex ransomware environment. Data from NCC Group indicated a slight drop in ransomware attacks from August to September 2024, with 407 cases compared to 450 the previous month. Notably affected sectors included industrial, consumer discretionary, and information technology.

Furthermore, politically motivated groups like CyberVolk are now using ransomware as a tool for retaliation, further expanding its scope.

In the U.S., officials are looking to combat ransomware by discouraging ransom payments, with Deputy National Security Adviser Anne Neuberger urging insurance companies to stop reimbursing ransom payments. "Insurance policies that cover ransomware payments incentivize ransoms that fuel cybercrime ecosystems," Neuberger wrote in the Financial Times, stressing that this practice must end.

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067