CosmicBeetle is a threat actor targeting SMBs worldwide, deploying ScRansom ransomware while impersonating LockBit.
Analyst brief
CosmicBeetle is a threat actor known for deploying the ScRansom ransomware, which succeeded its earlier Scarab variant. It primarily targets SMBs globally, impersonating the LockBit gang to leverage its reputation for extortion. The actor gains initial access via RDP brute forcing and exploiting vulnerabilities like CVE-2020-1472 (Zerologon) and FortiOS SSL-VPN, followed by credential dumping and deploying the custom 'Spacecolon' toolset (ScHackTool, ScInstaller, ScService) for data destruction. Defenders should focus on securing RDP and VPN access, patching for Zerologon, and investigating anomalies involving non-LockBit artifacts that leave ScRansom traces on compromised systems.
CosmicBeetle
unknown
CosmicBeetle is a threat actor known for deploying the ScRansom ransomware, which has replaced its previous variant, Scarab. The actor utilizes a custom toolset called Spacecolon, consisting of ScHackTool, ScInstaller, and ScService, to gain initial access through RDP brute forcing and exploiting vulnerabilities like CVE-2020-1472 and FortiOS SSL-VPN. CosmicBeetle has been observed impersonating the LockBit ransomware gang to leverage its reputation and has shown a tendency to leave artifacts on compromised systems. The group primarily targets SMBs globally, employing techniques such as credential dumping and data destruction.