Private HTS programs that spread ransomware

Private HTS programs that spread ransomware
AhnLab SEcurity intelligence Center found ransomware being delivered through a private HTS called UBP Asset, which appears to have been abused by an investment fraud ring that lured victims via Telegram and Band. The attack installed KRSID ransomware through modified HTS components and used a fraud site impersonating Union Bancaire Privee (UBP), with evidence tied to Bratteam88 and the domain phf-ubp[.]com. #UBPAsset #KRSID #UnionBancairePrivee #Bratteam88 #phf-ubp.com

Keypoints

  • ASEC identified a case where ransomware was distributed through a private home trading system (HTS) called UBP Asset.
  • The same HTS appears to have been used in an investment fraud operation impersonating Union Bancaire Privee (UBP).
  • Victims were reportedly recruited through Telegram and Band group chats and then pressured to deposit money.
  • The HTS installer ran UBPUpdater.Exe and UBPPatch.Psh, which retrieved Update.Lst and ultimately installed HTSPnew.Exe.
  • The ransomware payload is tracked as KRSID ransomware, written in Rust and using .Krsid as its extension.
  • Recent UBP.Dll variants were altered to execute the ransomware from the same path, suggesting the threat actor modified the HTS to launch the payload.
  • The article warns that private HTS software distributed through messaging apps is a red flag and should be obtained only from regulated financial institutions.

MITRE Techniques

  • [T1204.001] User Execution: Malicious File – The victim triggers the malicious HTS shortcut, which starts the infection chain and leads to ransomware execution (‘When the shortcut on the desktop background is clicked, “UBPUpdater.Exe” runs’).
  • [T1105] Ingress Tool Transfer – The HTS component connects to an update server and downloads the ransomware-related configuration and payload (‘connects to the HTS update server and downloads “Update.Lst”’; ‘downloaded “Update.Lst” … and then installed the ransomware “HTSPnew.Exe”’).
  • [T1036] Masquerading – The fraud operation impersonates a legitimate Swiss financial institution and uses a lookalike HTS to deceive victims (‘impersonated the name and logo of the actual Swiss-based financial institution “Union Bancaire Privee (UBP)”’; ‘designed to be so similar … that they are nearly indistinguishable’).
  • [T1566] Phishing – Victims were lured through social channels and induced to install the private HTS (‘deceive users through online ads or text messages’; ‘lure them into joining group chat rooms on social media platforms like KakaoTalk’).
  • [T1059] Command and Scripting Interpreter – The HTS launches a patch file that behaves as an executable to run the update and infection steps (‘“UBPPatch.Psh” file is an executable’; ‘executes the “UBPPatch.Psh” file’).
  • [T1486] Data Encrypted for Impact – The ransomware encrypts files on the system and demands payment for recovery (‘it encrypts the entire drive’; ‘files on their systems being encrypted by ransomware and being demanded to pay a ransom’).
  • [T1005] Data from Local System – Quasar RAT can steal account and user information from the infected environment (‘provides keylogging and account information collection capabilities’).
  • [T1021.001] Remote Services: Remote Desktop Protocol – Quasar RAT can control the infected system in real time through remote desktop (‘control the infected system in real time through remote desktop’).

Indicators of Compromise

  • [MD5] File hashes associated with the malicious components – 6d2cd65dbd0df30404b08ff007359e54, a9cce44c4d42b07f114dd2b340f0046a, and 1 more hash
  • [URL] HTS-related download or update location – https[:]//phf-ubp[.]com/UBPA/_hts_tv/user
  • [FQDN] Infrastructure used by the scam or HTS server – phf-ubp[.]com
  • [File name] Malicious HTS and payload components – UBPUpdater.Exe, UBPPatch.Psh, Update.Lst, HTSPnew.Exe, README_KRSID.Txt
  • [File extension] Ransomware-encrypted files – .Krsid
  • [Email/chat platform identifiers] Victim contact and lure channels – Telegram, Band, and KakaoTalk group chats


Read more: https://asec.ahnlab.com/en/95469/