Ransomware, Malware, Threat Intelligence

Sophisticated RustyRocket malware added to WorldLeaks ransomware’s arsenal

(Adobe Stock)

Infosecurity Magazine reports that more clandestine and persistent intrusions have been conducted by the WorldLeaks ransomware operation through the new advanced RustyRocket malware.

Windows and Linux systems could be compromised by the RustyRocket payload, which functions as an information-stealing and proxy tool, according to research from Accenture Cybersecurity. Moreover, RustyRocket's required pre-encrypted configuration inputs at runtime hinders detection, allowing WorldLeaks to remain for longer in targeted networks for subsequent data extortion activities. Such findings show attackers' implementation of evolved attack techniques to bypass traditional security defenses, said Accenture Cyber Intelligence Global Head T. Ryan Whelan.

"[RustyRocket] demonstrates that the best defense for enterprises is to strengthen defenses by leaning into advanced approaches for continuous threat exposure management, security testing, and red teaming, all while preparing your people to be ready for such attacks," said Whelan. Organizations have also been recommended to strengthen outbound data transfer monitoring and implement network segmentation to combat such threats.

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds