×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Eset
  • ESET Research: CosmicBeetle teams up with other ransomware groups and targets companies in Europe and Asia

Customer Press Room

ESET Research: CosmicBeetle teams up with other ransomware groups and targets companies in Europe and Asia

by Grandangolo Communications / Monday, 23 September 2024 / Published in Eset

CosmicBeetle exploits years-old vulnerabilities to attack small and medium-sized businesses

Researchers of ESET, a global European leader in the cybersecurity market, have mapped the recent activities of the CosmicBeetle threat group, documenting the use of the new ScRansom ransomware and revealing links to other established ransomware groups. CosmicBeetle spread ransomware against small and medium-sized businesses (SMEs), mainly in Europe and Asia.

ESET Research observed that the threat actor used the publicly released LockBit builder and attempted to exploit the ransomware's reputation. In addition to LockBit, ESET believes CosmicBeetle is likely a new affiliate of ransomware-as-a-service actor RansomHub, a new ransomware group active since March 2024 with rapidly growing activity.

“Possibly due to the difficulties involved in writing custom ransomware from scratch, CosmicBeetle sought to exploit LockBit's reputation, perhaps to mask problems in the underlying ransomware and thus increase the likelihood that victims will be willing to pay,” says Jakub Souček, the ESET researcher who analyzed CosmicBeetle's latest activities. "Additionally, we recently observed the deployment of ScRansom and RansomHub payloads on the same machine a week apart. The execution of RansomHub was unusual compared to the typical cases we have observed in ESET telemetry, but very similar to CosmicBeetle's modus operandi. Since there are no public data leaks related to RansomHub, we believe with some confidence that CosmicBeetle may be a recent affiliate," adds Souček.

CosmicBeetle often uses brute-force techniques to hack its targets. Furthermore, it exploits various known vulnerabilities. Small and medium-sized businesses across industries around the world are the most common victims of this threat actor, as this is the segment most likely to use vulnerable software or lack robust patch management processes.

ESET Research has observed attacks against SMEs in the following industries: manufacturing, pharmaceuticals, legal, education, healthcare, technology, hospitality, financial services and regional governments.

Besides encrypting data, ScRansom can also terminate various processes and services on the infected machine. ScRansom is not a very sophisticated ransomware, but CosmicBeetle was still able to compromise interesting targets and cause significant damage. This is mainly due to the fact that CosmicBeetle is still an immature player in the ransomware world, and the ScRansom distribution is affected by several issues. Victims affected by ScRansom, who decide to pay, should act with caution.

ESET Research managed to obtain a decryptor implemented by CosmicBeetle for its recent encryption scheme. ScRansom is in continuous development, which complicates things further. Encryption and decryption are very complex and error-prone processes, making it difficult to guarantee complete file recovery. Successful decryption depends on the decryptor working properly and on CosmicBeetle providing all necessary keys, and even then, some files may be permanently destroyed. Even in the best case scenario, decryption is time-consuming and complicated.

CosmicBeetle, active since at least 2020, is the name given by ESET Research to a cybercriminal group discovered in 2023. This group is best known for using a set of custom tools developed in Delphi, called Spacecolon which includes ScHackTool, ScInstaller, ScService and ScPatcher. For more technical information on CosmicBeetle's latest activity, see the blog “CosmicBeetle steps up: Probation period at RansomHub” on WeLiveSecurity.com. Follow ESET Research on Twitter (now known as X) For the latest news from ESET Research.

Tagged under: Eset

About Grandangolo Communications

What you can read next

ESET has discovered Hodur, a malware that exploits the war in Ukraine
ESET announces version 6.0 of Mobile Security for Android
ESET presents the projects for the ESET Campus: an innovation and technology hub in the heart of Europe

Customer Press Room

  • Vertiv introduces backup power for personal devices and business applications

    Vertiv™ PowerUPS 200 Series is a ...
  • Sandworm Group Hits Energy Company in Poland with DynoWiper: ESET Research Analysis

    ESET researchers have identified DynoWip...
  • Antonio Menghini is the new Chief Commercial Officer of Innovaway

    At the same time, Giuseppe Piccolo took over ...
  • Vertiv introduces a new AI-powered predictive maintenance service for modern data centers and AI factories

    Vertiv™ Next Predict is a new service...
  • Vertiv expands flexible, energy-efficient edge cooling system for small, medium and edge applications in EMEA

    The Vertiv perimeter cooling system...

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • Abstract
  • abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Information Tecnology
  • Innovaway
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP