{"id":46244,"date":"2022-04-18T00:00:00","date_gmt":"2022-04-18T00:00:00","guid":{"rendered":"urn:uuid:1c33de71-9b43-feab-5d89-593b2e0975a3"},"modified":"2022-04-18T00:00:00","modified_gmt":"2022-04-18T00:00:00","slug":"an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/","title":{"rendered":"An Investigation of the BlackCat Ransomware via Trend Micro Vision One"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-641.png\"><!-- OneTrust Cookies Consent Notice start for trendmicro.com --><!-- OneTrust Cookies Consent Notice end for trendmicro.com --> <!-- Begin mPulse library --> <!-- END mPulse library --> <head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width\"> <meta name=\"description\" content=\"We recently investigated a case related to the BlackCat ransomware group using the Trend Micro Vision One\u2122 platform, which comes with extended detection and response (XDR) capabilities. BlackCat (aka AlphaVM or AlphaV) is a ransomware family created in the Rust programming language and operated under a ransomware-as-a-service (RaaS) model. \"> <meta name=\"robots\" content=\"index,follow\"> <meta name=\"keywords\" content=\"endpoints,ransomware,research,articles, news, reports\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge,chrome=1\"> <meta name=\"template\" content=\"article1withouthero\"> <meta property=\"article:published_time\" content=\"2022-04-18\"> <meta property=\"article:tag\" content=\"ransomware\"> <meta property=\"article:section\" content=\"research\"> <link rel=\"icon\" type=\"image\/ico\" href=\"\/content\/dam\/trendmicro\/favicon.ico\"> <link rel=\"canonical\" href=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware.html\"> <title>An Investigation of the BlackCat Ransomware via Trend Micro Vision One<\/title> <link href=\"https:\/\/fonts.googleapis.com\/css?family=Open+Sans:300,300i,400,400i,600\" rel=\"stylesheet\">\n<link href=\"\/\/customer.cludo.com\/css\/296\/1798\/cludo-search.min.css\" type=\"text\/css\" rel=\"stylesheet\"> <link rel=\"stylesheet\" href=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch.min.css\" type=\"text\/css\"> <meta property=\"og:url\" content=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware.html\"><br \/>\n<meta property=\"og:title\" content=\"An Investigation of the BlackCat Ransomware via Trend Micro Vision One\"><br \/>\n<meta property=\"og:description\" content=\"We recently investigated a case related to the BlackCat ransomware group using the Trend Micro Vision One\u2122 platform, which comes with extended detection and response (XDR) capabilities. BlackCat (aka AlphaVM or AlphaV) is a ransomware family created in the Rust programming language and operated under a ransomware-as-a-service (RaaS) model. \"><br \/>\n<meta property=\"og:site_name\" content=\"Trend Micro\"><br \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-641.png\"><br \/>\n<meta property=\"og:locale\" content=\"en_US\"> <meta name=\"twitter:card\" content=\"summary_large_image\"><br \/>\n<meta name=\"twitter:site\" content=\"@TrendMicro\"><br \/>\n<meta name=\"twitter:title\" content=\"An Investigation of the BlackCat Ransomware via Trend Micro Vision One\"><br \/>\n<meta name=\"twitter:description\" content=\"We recently investigated a case related to the BlackCat ransomware group using the Trend Micro Vision One\u2122 platform, which comes with extended detection and response (XDR) capabilities. BlackCat (aka AlphaVM or AlphaV) is a ransomware family created in the Rust programming language and operated under a ransomware-as-a-service (RaaS) model. \"><br \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-641.png\"> <\/head> <body class=\"articlepage page basicpage context-business\" id=\"readabilityBody\" readability=\"51.279850746269\"> <!-- Page Scroll: Back to Top --> <a id=\"page-scroll\" title=\"VerticalPageScroll\" href=\"javascript:jumpScroll($(this).scrollTop());\"> <span class=\"icon-chevron-up\"><\/span> <\/a> <!-- \/* Data Layer *\/ --> <\/p>\n<div class=\"root responsivegrid\">\n<div class=\"aem-Grid aem-Grid--12 aem-Grid--default--12 \">\n<div class=\"articleBodyNoHero aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"research-layout article container\" role=\"contentinfo\">\n<article class=\"research-layout--wrapper row\" data-article-pageid=\"1615841420\">\n<div class=\"col-xs-12 col-md-12 one-column\">\n<div class=\"col-xs-12 col-md-12\" readability=\"9.825918762089\">\n<div class=\"article-details\" role=\"heading\" readability=\"39.303675048356\"> <span class=\"article-details__bar\" role=\"img\"><\/span> <\/p>\n<p class=\"article-details__display-tag\">Ransomware<\/p>\n<p class=\"article-details__description\">We recently investigated a case related to the BlackCat ransomware group using the Trend Micro Vision One\u2122 platform, which comes with extended detection and response (XDR) capabilities. BlackCat (aka AlphaVM or AlphaV) is a ransomware family created in the Rust programming language and operated under a ransomware-as-a-service (RaaS) model. <\/p>\n<p class=\"article-details__author-by\">By: Lucas Silva, Leandro Froes <time class=\"article-details__date\">April 18, 2022<\/time> <span>Read time:&nbsp;<\/span><span class=\"eta\"><\/span> (<span class=\"words\"><\/span> words) <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<hr class=\"research-layout-divider\"> <main class=\"main--content col-xs-12 col-md-8 col-md-push-2\"> <\/p>\n<div class=\"richText\" readability=\"43.034756097561\">\n<div readability=\"32.880487804878\">\n<p>We recently investigated a case related to the BlackCat <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/definition\/ransomware\">ransomware<\/a> group using the Trend Micro Vision One\u2122 platform, which comes with extended detection and response (XDR) capabilities. BlackCat (aka AlphaVM or AlphaV) is a ransomware family created in the Rust programming language and operated under a <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/definition\/ransomware-as-a-service-raas\">ransomware-as-a-service (RaaS)<\/a> model. Our data indicates that BlackCat is primarily delivered via third-party frameworks and toolsets (for example, Cobalt Strike) and uses exploitation of exposed and vulnerable applications (for example, Microsoft Exchange Server) as an entry point.&nbsp;<\/p>\n<p>BlackCat has versions that work on both Windows and Linux operating systems and in VMware\u2019s ESXi environment. In this incident, we identified the exploitation of <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-31207\">CVE-2021-31207<\/a>. This vulnerability abuses the New-MailboxExportRequest PowerShell command to export the user mailbox to an arbitrary file location, which could be used to write a web shell on the Exchange Server.<\/p>\n<p>In this blog entry, we discuss the kill chain used by the malicious actors behind this incident and how we used the Trend Micro Vision One platform to track the threats involved in the incident. We also dive deeper into the notable post-exploitation routines that were used until the host\u2019s encryption.<\/p>\n<p>We begin with the Trend Micro Vision One platform, where we noticed an incident being created in the Vision One console with a few workbenches related to it. Upon checking, we noticed several suspicious web shells being dropped on the local Microsoft Exchange Server. Based on that information, we started the analysis of the Exchange Server.&nbsp;&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-1.png\" alt=\"Figure 1. The incident view created by Vision One\"><figcaption>Figure 1. The incident view created by Vision One<\/figcaption><\/figure>\n<\/p><\/div>\n<div>\n<div class=\"richText\" readability=\"36.844863731656\">\n<div readability=\"20.361635220126\">\n<p>We first noticed that ASPX files, normally dropped after ProxyShell and ProxyLogon exploitation, were dropped and detected (Backdoor.ASP.WEBSHELL.SMYXBH5A) in the affected machine. This type of ProxyShell exploitation usually involves three vulnerabilities: <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-34473\">CVE-2021-34473,<\/a> <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-34523\">CVE-2021-34523<\/a>, and the previously mentioned CVE-2021-31207. The first two were patched in July 2021, while the last one was fixed in May 2021. Successful exploitation of these vulnerabilities could lead to arbitrary writing of files that an attacker could abuse to upload web shells to a target Exchange Server. In this engagement, we determined that CVE-2021-31207 was being actively exploited.<\/p>\n<p>The exploitation is performed by importing a web shell as an email inside the user draft mailbox. It is then exported to c:\/inetpub\/wwwroot\/aspnet_client\/{5-random-digit}.aspx. Upon analysis of the infected host, we identified several web shell variants used by the malicious actors.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-2.png\" alt=\"Figure 2. The email saved in the drafts folder\"><figcaption>Figure 2. The email saved in the drafts folder<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-3.png\" alt=\"Figure 3. The ASPX files as shown on the Vision One workbench\"><figcaption>Figure 3. The ASPX files as shown on the Vision One workbench<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"34.5\">\n<div readability=\"14\">\n<p>A web shell is a piece of code written in web development programming language, such as ASP or JSP, that attackers could drop onto web servers to gain remote access and the ability to execute arbitrary code and commands to meet their objectives.<\/p>\n<p>We discovered that the web shell employed in the attack uses the exec_code query parameter to execute the desired command.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-4.png\" alt=\"Figure 4. A snippet of web shell content\"><figcaption>Figure 4. A snippet of web shell content<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"34\">\n<div readability=\"13\">\n<p>Once a web shell is successfully inserted into the victim\u2019s server, it could allow remote attackers to perform various tasks, such as stealing data and dropping other malicious tools. In this engagement, we saw the Internet Information Services (IIS) process (w3wp.exe) spawning a PowerShell process that downloaded a Cobalt Strike beacon (detected as Backdoor.Win32.COBEACON.OSLJDO).<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-5.png\" alt=\"Figure 5. The IIS process w3wp.exe spawning a PowerShell process\"><figcaption>Figure 5. The IIS process w3wp.exe spawning a PowerShell process<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32.5\">\n<div readability=\"10\">\n<p>The PowerShell method WebClient.DownloadFile was used to download a DLL file from the IP address 5[.]255[.]100[.]242. After the download, the DLL was executed using rundll32.exe to call the exported function ASN1_OBJECT_create. &nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-6.png\" alt=\"Figure 6. The PowerShell command used to download the DLL\"><figcaption>Figure 6. The PowerShell command used to download the DLL<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"34\">\n<div readability=\"13\">\n<p>Upon further investigation, we discovered that the DLL, libeay32.dll, was a tampered version of a known DLL normally used by OpenSSL and by other programs to help with SSL communication. The malicious actors modified an exported function of the DLL to host a Cobalt Strike stager shellcode. The DLL was using a nonvalid certificate that belonged to the video communications company Zoom and was issued by GoDaddy.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-7.png\" alt=\"Figure 7. The libeay32.dll certificate\"><figcaption>Figure 7. The libeay32.dll certificate<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-8.png\" alt=\"Figure 8. The libeay32.dll issuer\"><figcaption>Figure 8. The libeay32.dll issuer<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"35\">\n<div readability=\"15\">\n<p>Once executed, the exported function (ASN1_OBJECT_create) works as a loader for a classic Cobalt Strike stager shellcode. Although this function contains a lot of code, most of it is just junk code containing useless operations. What it really does is simply allocate memory using VirtualAlloc, copy a nonencrypted shellcode to the allocated region, and then transfer the execution to it. The shellcode then decrypts another shellcode, which is the Cobalt Strike stager shellcode.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-9.png\" alt=\"Figure 9. Virtual memory being allocated for the first shellcode\"><figcaption>Figure 9. Virtual memory being allocated for the first shellcode<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-10.png\" alt=\"Figure 10. Execution being transferred to the first shellcode\"><figcaption>Figure 10. Execution being transferred to the first shellcode<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-11.png\" alt=\"Figure 11. Decrypted Cobalt Strike stager shellcode\"><figcaption>Figure 11. Decrypted Cobalt Strike stager shellcode<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"41.5\">\n<div readability=\"28\">\n<p>The stager performs an HTTP GET request to a remote server mimicking a normal jQuery request to the path \/jquery-3.5.1.slim.min.js. The shellcode then reads the server response, allocates memory also using the VirtualAlloc function, copies the downloaded content to the allocated region, and then transfers the execution to a hard-coded offset within the downloaded content.<\/p>\n<p>Because of the way malleable command-and-control (C&amp;C) stagers work, the behavior depends on the content being downloaded. During our research, we were not able to collect the payload from the remote server. However, using the Vision One platform, we collected enough information to be able to state that the downloaded payload managed to spawn the WerFault.exe process and inject it into the system to host another Cobalt Strike beacon.<\/p>\n<p>It should be noted that all the following activities described in this blog post were performed by the injected WerFault.exe process.<\/p>\n<p>While using the Vision One platform, we identified the C&amp;C server used by the malicious actors.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-12.png\" alt=\"Figure 12. The Cobalt Strike beacon C&amp;C server as shown in the Vision One console\"><figcaption>Figure 12. The Cobalt Strike beacon C&amp;C server as shown in the Vision One console<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p>The spawned WerFault.exe process generated the following activities:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Discovered accounts (account discovery technique)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Dropped and executed the NetScan tool<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Dropped and executed the Bloodhound tool<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Dropped the CrackMapExec tool<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Dropped other versions of the tampered DLL to remote machines (lateral movement)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Executed the PowerShell version of the Inveigh tool<\/span><\/li>\n<\/ul>\n<p>The following commands were executed for account discovery:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">net group \u201cDomain Admins\u201d \/DOMAIN<\/span><\/li>\n<li><span class=\"rte-red-bullet\">net group \u201cDomain Controllers\u201d \/DOMAIN<\/span><\/li>\n<li><span class=\"rte-red-bullet\">net group \u201cEnterprise Admins\u201d \/DOMAIN<\/span><\/li>\n<li><span class=\"rte-red-bullet\">systeminfo<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-13.png\" alt=\"Figure 13. The account discovery commands\"><figcaption>Figure 13. The account discovery commands<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31.71613832853\">\n<div readability=\"12.870317002882\">\n<p>The NetScan tool was dropped on the file path C:\\Windows\\debug and used to scan the network (<a href=\"https:\/\/attack.mitre.org\/techniques\/T1046\/\">network discovery activities<\/a>). The same directory was also used to drop other tools and samples described in this blog post. The NetScan tool, created by SoftPerfect, is capable of pinging remote computers, scanning ports, and discovering shared folders.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-14.png\" alt=\"Figure 14. The network scanning tool execution\"><figcaption>Figure 14. The network scanning tool execution<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"34.5\">\n<div readability=\"14\">\n<p>After the initial account discovery, the BloodHound tool was dropped. This tool allows the analysis of Active Directory (AD) rights and relations. Using the collected data, BloodHound maps out AD objects such as users, groups, and computers, and then accesses and queries these relationships.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-15.png\" alt=\"Figure 15. BloodHound being dropped into the system\"><figcaption>Figure 15. BloodHound being dropped into the system<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-16.png\" alt=\"Figure 16. Data extracted using BloodHound\"><figcaption>Figure 16. Data extracted using BloodHound<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32.985074626866\">\n<div readability=\"12.611940298507\">\n<p><a href=\"https:\/\/attack.mitre.org\/software\/S0488\/\">CrackMapExec<\/a> (aka CME) is a post-exploitation tool that abuses built-in AD features and protocols to achieve its functionality. Its capabilities include auto-injecting Mimikatz, shellcode, and DLLs into memory using PowerShell, and dumping NTDS.dit. The malicious actors tried to use the tool to dump credentials and conduct lateral movement through the network (detected as HackTool.Win32.Mpacket.SM).<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-17.png\" alt=\"Figure 17. The CrackMapExec execution\"><figcaption>Figure 17. The CrackMapExec execution<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<p>The spawned WerFault.exe process was also responsible for spreading other tampered versions of libeay32.dll to other machines across the environment via SMB.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-18.png\" alt=\"Figure 18. WerFault.exe used to drop the libeay32.dll across the environment\"><figcaption>Figure 18. WerFault.exe used to drop the libeay32.dll across the environment<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32.43932038835\">\n<div readability=\"10.813106796117\">\n<p><a href=\"https:\/\/github.com\/Kevin-Robertson\/Inveigh\">Inveigh<\/a> is a cross-platform .NET IPv4\/IPv6 machine-in-the-middle penetration-testing tool. It can conduct spoofing attacks and NTLM challenge\/response captures via SMB service. The information is captured through both packet sniffing and protocol-specific listeners\/sockets. In this incident, the PowerShell version of Inveigh was used to spoof the mDNS (multicast DNS) and NBNS (NetBIOS Name Service) protocols.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-19.png\" alt=\"Figure 19. The Inveigh command being executed\"><figcaption>Figure 19. The Inveigh command being executed<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"37\">\n<div readability=\"19\">\n<p>Before the execution of the BlackCat ransomware, we identified suspicious batch scripts being used by the malicious actors to prepare the environment for encryption.<\/p>\n<p>A file named spread.bat was created, and the following PowerShell command was used to execute the spread.bat file. It should be noted that we could not collect the .bat file to verify its content.<\/p>\n<p><span class=\"blockquote\">powershell -nop -exec bypass -EncodedCommand LgBcAHMAcAByAGUAYQBkAC4AYgBhAHQAIABtAGsAcwBoAGEAcgBlACAAUgBFAEEARAA=<br \/><\/span><\/p>\n<p>The Vision One platform decoded the command, resulting in the code shown in the following figure.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-20.png\" alt=\"Figure 20. The code generated after decoding the command used to execute spread.bat\"><figcaption>Figure 20. The code generated after decoding the command used to execute spread.bat<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"36.5\">\n<div readability=\"18\">\n<p>Another batch file, 123.bat, was executed. As with the previous batch file, we could not collect it to analyze its content.<\/p>\n<p>To execute the sample, a token is required to avoid automated sandbox analysis. However, any provided token can bypass the restriction and enable the malware execution. The ransomware also supports other commands, which can be obtained via the -h or &#8211;help parameters.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-21.png\" alt=\"Figure 21. The BlackCat help command output\"><figcaption>Figure 21. The BlackCat help command output<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p>The malicious actors used SysVol Share to host the BlackCat sample that was executed across the environment. This approach was used because the contents of SysVol Share are replicated across all domain controllers in the Windows Server domain, meaning that all machines will be able to access it. A copy of the sample was also dropped locally on the C:\\Windows\\debug folder.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-22.png\" alt=\"Figure 22. The BlackCat binary that was dropped in SysVol Share\"><figcaption>Figure 22. The BlackCat binary that was dropped in SysVol Share<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32.5\">\n<div readability=\"10\">\n<p>File permissions were changed using icacls.exe, a command-line utility that can be used to modify NTFS permissions, as well as net share commands.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-23.png\" alt=\"Figure 23. Permission granted through icalcls.exe\"><figcaption>Figure 23. Permission granted through icalcls.exe<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-24.png\" alt=\"Figure 24. Permission granted through net share commands\"><figcaption>Figure 24. Permission granted through net share commands<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"35.5\">\n<div readability=\"16\">\n<p>After preparing the environment, the malicious actors proceeded to execute the ransomware. Upon execution, BlackCat performs the following tasks:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Query the system UUID using wmic.<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">The universally unique identifier (UUID) is later used, together with the token, to identify the victim in a Tor website hosted by the malicious actors.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Delete volume shadow copies.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Use BCDedit to disable recovery mode.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Increase the number of network requests that the server service can perform.<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">This allows the malware to access enough files during the encryption process.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Stop the IIS service using the iisreset.exe, a well-known tool used to handle IIS services.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Execute arp command to display current ARP (Address Resolution Protocol) entries.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Execute Fsutil to allow the use of both remote and local symlinks.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Clear all event logs via wevutil.exe.<\/span><\/li>\n<\/ul>\n<p>Once these tasks are finished, the target files are encrypted, and a 7-random-digit extension is added to the files. The ransom note (detected as Ransom.Win32.BLACKCAT.B.note) is then dropped. It informs the victim that their data has been stolen and instructs them to access a Tor onion domain.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-25.png\" alt=\"Figure 25. The BlackCat ransom note\"><figcaption>Figure 25. The BlackCat ransom note<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"48.381200244948\">\n<div readability=\"41.897121861604\">\n<p>BlackCat samples, which are immediately detected by Trend Micro Predictive Machine Learning, are detected as Ransom.Win32.BLACKCAT.YXCCY.<\/p>\n<p>This investigation gave us the opportunity to learn more about the BlackCat infection chain. It highlights the continued evolution of threats that are designed to evade detection. Notable capabilities and characteristics we observed included evasive tactics, such as masking a tampered DLL to make it seem legitimate.<\/p>\n<p>Organizations should take note of the continuing trend among malicious actors of using Cobalt Strike in attacks, living-off-the-land binaries (LOLBins), and red team or penetration-testing tools to blend in with the environment.<\/p>\n<p>For organizations, a good patch management protocol can help prevent the exploitation of vulnerable internet-facing servers. Early containment and mitigation are also essential to cut off more damaging attacks that compromise environments and deploy ransomware. In this case, close monitoring of the system and prompt detection could have prevented all that was described here from coming to pass.<\/p>\n<p>In analyzing and correlating ransomware attacks, the use of multilayered detection and response solutions such as Trend Micro Vision One can provide powerful XDR capabilities that collect and automatically correlate data across multiple security layers \u2014 email, endpoints, servers, cloud workloads, and networks \u2014 to prevent attacks via automated protection, while also ensuring that no significant incidents go unnoticed.<\/p>\n<p>A list of the indicators of compromise (IOCs) for this case can be found <a href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one-ioc.txt\">here<\/a>.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<section class=\"tag--list\">\n<p>Tags<\/p>\n<\/section>\n<p> <\/main> <\/article>\n<\/div>\n<\/div><\/div>\n<\/div>\n<p> <!-- \/* Core functionality javascripts, absolute URL to leverage Akamai CDN *\/ --> <!--For Modal-start--> <\/p>\n<p> <span>sXpIBdPeKzI9PC2p0SWMpUSM2NSxWzPyXTMLlbXmYa0R20xk<\/span> <\/p>\n<p> <!--For Modal-end--> <!-- Go to www.addthis.com\/dashboard to customize your tools --> <\/body> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We recently investigated a case related to the BlackCat ransomware group using the Trend Micro Vision One\u2122 platform, which comes with extended detection and response (XDR) capabilities. BlackCat (aka AlphaVM or AlphaV) is a ransomware family created in the Rust programming language and operated under a ransomware-as-a-service (RaaS) model. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":46245,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9508,9539,9509],"class_list":["post-46244","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-endpoints","tag-trend-micro-research-ransomware","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>An Investigation of the BlackCat Ransomware via Trend Micro Vision One 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"An Investigation of the BlackCat Ransomware via Trend Micro Vision One 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-04-18T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-641.png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"An Investigation of the BlackCat Ransomware via Trend Micro Vision One\",\"datePublished\":\"2022-04-18T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\\\/\"},\"wordCount\":2114,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/04\\\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one.png\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Endpoints\",\"Trend Micro Research : Ransomware\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\\\/\",\"name\":\"An Investigation of the BlackCat Ransomware via Trend Micro Vision One 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/04\\\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one.png\",\"datePublished\":\"2022-04-18T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/04\\\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/04\\\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one.png\",\"width\":538,\"height\":271},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"An Investigation of the BlackCat Ransomware via Trend Micro Vision One\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"An Investigation of the BlackCat Ransomware via Trend Micro Vision One 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/","og_locale":"en_US","og_type":"article","og_title":"An Investigation of the BlackCat Ransomware via Trend Micro Vision One 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-04-18T00:00:00+00:00","og_image":[{"url":"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/blackcat-641.png","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"An Investigation of the BlackCat Ransomware via Trend Micro Vision One","datePublished":"2022-04-18T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/"},"wordCount":2114,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/04\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one.png","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Endpoints","Trend Micro Research : Ransomware","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/","url":"https:\/\/www.threatshub.org\/blog\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/","name":"An Investigation of the BlackCat Ransomware via Trend Micro Vision One 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/04\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one.png","datePublished":"2022-04-18T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/04\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/04\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one.png","width":538,"height":271},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/an-investigation-of-the-blackcat-ransomware-via-trend-micro-vision-one\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"An Investigation of the BlackCat Ransomware via Trend Micro Vision One"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/46244","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=46244"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/46244\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/46245"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=46244"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=46244"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=46244"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}