

Rewterz Threat Advisory –CVE-2022-1852 – Linux Kernel Vulnerability
June 2, 2022
Rewterz Threat Advisory – Multiple Microsoft Edge (Chromium-based) Vulnerabilities
June 2, 2022
Rewterz Threat Advisory –CVE-2022-1852 – Linux Kernel Vulnerability
June 2, 2022
Rewterz Threat Advisory – Multiple Microsoft Edge (Chromium-based) Vulnerabilities
June 2, 2022Severity
High
Analysis Summary
Phobos Ransomware is based on the Dharma malware that first appeared at the beginning of 2019. It spreads into several systems via compromised Remote Desktop Protocol (RDP) connections. This malware does not use any UAC bypass methods. Unlike other cybercrime gangs that go after big hunts, Phobos creators go after smaller firms that don’t have sufficient funding to pay massive ransoms. This ransomware usually targets healthcare providers, with victims in the United States, Seychelles, Portugal, Brazil, Indonesia, Germany, Romania, and Japan. Its perpetrators demand a little ransom payment, which appeals to victims and enhances the chances of payment. The average Phobos ransom payment in July 2021 was $54,700.
Impact
- File Encryption
- Data Exfiltration
Indicators of Compromise
MD5
- 7627c534ec273a73fd31107bb50c376e
SHA-256
- f9de0d6af30204954b78f10500990e1b9c149a1d4376b082052af542168c587e
SHA1
- b2bfa0018b28b905e4db48838941cfa3b62d0a01
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.