Cyber Security News

RansomHub Affiliate Deploying New Custom Backdoor Dubbed ‘Betruger’ For Persistence

A RansomHub affiliate has been observed recently deploying a new custom backdoor named ‘Betruger’.

This sophisticated malware, discovered on March 20, 2025, by the Symantec Threat Hunter team, represents a concerning evolution in ransomware attack methodologies.

The Betruger backdoor is a multi-function tool specifically designed for executing ransomware attacks.

It consolidates various capabilities typically spread across multiple tools, potentially streamlining the attack process and reducing the attacker’s digital footprint.

This approach could make detection and mitigation more challenging for cybersecurity professionals.

Broadcom analysts noted that Betruger incorporates an array of features crucial for comprehensive system infiltration and data exfiltration.

These include the ability to capture screenshots, steal credentials, log keystrokes, perform network scanning, and escalate privileges within the compromised system.

The emergence of Betruger shows the ongoing arms race between cybercriminals and security experts.

Developing Custom Tools

By developing custom tools, ransomware groups are attempting to stay one step ahead of detection mechanisms and security protocols.

Symantec’s response to this threat has been swift, with the company rolling out a range of protective measures.

These include adaptive-based protections such as ACM.Ps-RgPst!g1 and ACM.Untrst-RunSys!g1, behavior-based detection like SONAR.TCP!gen1, and file-based identification methods targeting Backdoor.Betruger and associated malware variants.

The discovery of Betruger also highlights the evolving nature of Ransomware-as-a-Service (RaaS) operations.

RansomHub, as a RaaS provider, enables affiliates to leverage sophisticated tools like Betruger, potentially lowering the barrier to entry for conducting complex ransomware attacks.

Cybersecurity experts advise organizations to remain vigilant and ensure their security systems are up-to-date.

Implementing robust backup strategies, regularly patching systems, and conducting security awareness training for employees remain crucial steps in defending against such evolving threats.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

2 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

3 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

5 hours ago