CISA, NSA, FBI have recently released a joint advisory report with TTPs for BlackMatter ransomware that primarily leverages the SMB (Server Message Block), light directory access protocol (LDAP), and AD (Active Directory) to identify all the available hosts on the network.
While the BlackMatter ransomware was targeting several critical infrastructure entities in the U.S. since July 2021, and this includes two major Food and Agriculture Sector organizations.
CISA, the FBI, and NSA urge all organizations to immediately apply all the recommended mitigations, since, the attacks of this ransomware directly affect consumer access to critical infrastructure services.
The user credentials that were previously compromised, NtQuerySystemInformation, and EnumServicesStatusExW were exploited by the BlackMatter ransomware to list all the running processes and services.
To discover all the hosts in the Active Directory BlackMatter exploits the embedded credentials in the LDAP and SMB protocol. And to identify each host for accessible shares it uses the srvsvc.NetShareEnumAll Microsoft Remote Procedure Call (MSRPC) function.
From the original compromised host, BlackMatter remotely encrypts the shares’ contents like ADMIN$, C$, SYSVOL, and NETLOGON by leveraging the embedded credentials and SMB protocol.
Here are the recommended mitigations offered by CISA, the FBI, and NSA mentioned below:-
Moreover, the Director of Cybersecurity at NSA, Rob Joyce stated:-
“The threat of ransomware goes beyond specific impacts to a victim company — it has risen to a national security issue. NSA’s technical skills and threat intelligence will continue to support our partners across government and industry to degrade adversary footholds into networks where they launch the ransomware.”
“Employing the mitigations in the joint advisory with CISA and FBI will protect networks and mitigate the risk against BlackMatter and other ransomware attacks.”
You can follow us on Linkedin, Twitter, Facebook for daily Cyber security and hacking news updates.
The Cl0p ransomware group has claimed responsibility for infiltrating Broadcom's internal systems as part of…
Grafana Labs has disclosed a critical security vulnerability affecting Grafana Enterprise that could allow attackers…
A critical security vulnerability has been discovered in ASUSTOR backup and synchronization software, allowing attackers…
Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors…
SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…
OpenAI has launched GPT-5.1-Codex-Max, a specialized coding model designed to handle complex development tasks autonomously. The…