Cyber Security News

DJvu Ransomware Mimic as Cracked Software to Compromise Computers

A recent campaign has been observed to be delivering DJvu ransomware through a loader that pretends to be freeware or cracked software. This ransomware has been previously reported to provide a .xaro extension to infected files, and threat actors demand a ransom for decrypting those files.

The main goals of this ransomware are data exfiltration, stealing information, and ransom demand. This malware uses a Shotgun approach and is found to be deployed with a variety of other malicious files.

Document
Protect Your Storage With SafeGuard

Is Your Storage & Backup Systems Fully Protected? – Watch 40-second Tour of SafeGuard

StorageGuard scans, detects, and fixes security misconfigurations and vulnerabilities across hundreds of storage and backup devices.

DJvu Ransomware Infection

The threat actors distributed malicious .7z archive files for the initial access vector with an untrusted website masquerading as a legitimate freeware distribution site. When the victims download the malicious install.7z archive file and extract it, it consists of an install.exe file.

This file is a large binary-packed file with a size of about ~0.7 GB. Further analysis of this file revealed that this was a PrivateLoader first observed in 2021.

If victims execute the install.exe file, it downloads several additional malware like Redline Stealer (infostealer), Vidar (infostealer), Amadey (botnet), Nymaim (downloader), GCleaner(loader), XmRig(Crytominer), Fabookie (Facebook infostealer) and LummaC Stealer (MaaS platform acting as an infostealer).

In addition to this, the Xaro payload was found to be running on the compromised machine within three minutes of the install.exe execution. There were two observed flows of the execution and termination of the Xaro payload.

First Flow & Second Flow

The first flow uses a process name with a four-character long alphanumeric string, such as 5r64.exe, and injects itself a code by creating a child process of itself. This child process creates a registry at the location \software\microsoft\windows\currentversion\run\syshelper. 

The second flow was similar to the first but used certain bypass security measures. The child process in this flow connects to a C2 server api.2ip[.]ua. In addition to this, it also encrypts files in the C:\Users\User directory on the compromised machines.

Furthermore, a complete report about this ransomware variant has been published by CyberReason, which provides detailed information about the execution process, payloads used, source code, and other information.

Indicators of Compromise

TypeValueComment
SHA-25610ef30b7c8b32a4c91d6f6fee738e39dc02233d71ecf4857bec6e70520d0f5c1install.exe
SHA-25683546201db335f52721ed313b9078de267eaf1c5d58168b99e35b2836bf4f0fcXaro payload
SHA-2563d9cf227ef3c29b9ca22c66359fdd61d9b3d3f2bb197ec3df42d49ff22b989a4Build2.exe
SHA-2568d7f0e6b6877bdfb9f4531afafd0451f7d17f0ac24e2f2427e9b4ecc5452b9f0Build3.exe
Domainapi.2ip[.]uaXaro C2 Server
Domaincolisumy[.]comXaro C2 Server
Domainzexeq[.]comXaro C2 Server
Task NameAzure-Update-TaskScheduled Task
Task NameTime Trigger TaskScheduled task used to rerun Xaro
Registrysoftware\microsoft\windows\currentversion\run\syshelperRegistry entry used by Xaro for persistence

Experience how StorageGuard eliminates the security blind spots in your storage systems by trying a 14-day free trial.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago