Vice Society Ransomware: In-Depth Analysis, Detection, and Mitigation
What is Vice Society Ransomware?
Vice Society is a multi-pronged extortion and ransomware group which emerged in early to mid 2021. The group also leverages both Windows and Linux variations of ransomware. The latter of which is frequently observed in campaigns targeting ESXi or heavily virtualized environments. Vice Society is known to ‘outsource’ the development of their ransomware payloads.
What Does Vice Society Ransomware Target?
Vice Society ransomware is known to target large enterprises and high-value targets as well as medium-sized businesses. They have also been known to focus on organizations in the government, healthcare, and educational sectors. Vice Society is observed to heavily target virtualized environments (Linux variant) in particular.
How Does Vice Society Ransomware Work?
Vice Society ransomware targets its victims through phishing and spear phishing emails. They are also known to use third-party frameworks (e.g., Empire, Metasploit, Cobalt Strike) and the PrintNightmare exploitation (CVE-2021-34527 and CVE-2021-1675).
Vice Society Ransomware Technical Details
Once in their target environment, there is a heavy use of COTS (Commercial off the shelf) utilities and LOLBins to move as stealthily as possible. In recently analyzed Windows samples, persistence is achieved via Registry (RUN key). In addition, an embedded .BAT file is dropped and executed by the ransomware to inhibit system recovery (removal of VSS and boot recovery options).
Infected victims are instructed to engage threat actors via email (onionmail addresses). Vice Society operations have generated, or outsourced the development of, ‘variants’ of their ransomware based on Hive, Zeppelin, and HelloKitty (on Linux).
How to Detect Vice Society Ransomware
The SentinelOne Singularity XDR Platform detects and prevents malicious behaviors and artifacts associated with Vice Society ransomware.
If you do not have SentinelOne deployed, here are a few ways you can identify Vice Society ransomware in your network:
Security Tools
Use anti-malware software or other security tools capable of detecting and blocking known ransomware variants. These tools may use signatures, heuristics, or machine learning algorithms, to identify and block suspicious files or activities.
Network Traffic
Monitor network traffic and look for indicators of compromise, such as unusual network traffic patterns or communication with known command-and-control servers.
Security Audits
Conduct regular security audits and assessments to identify network and system vulnerabilities and ensure that all security controls are in place and functioning properly.
Education & Training
Educate and train employees on cybersecurity best practices, including identifying and reporting suspicious emails or other threats.
Backup & Recovery Plan
Implement a robust backup and recovery plan to ensure that the organization has a copy of its data and can restore it in case of an attack.
How to Mitigate Vice Society Ransomware
SentinelOne Singularity XDR Platform prevents Vice Society ransomware infections. In case of an infection, the SentinelOne Singularity XDR Platform detects and prevents malicious behaviors and artifacts associated with Vice Society ransomware.
SentinelOne customers are protected from Vice Society ransomware without any need to update or take action. In cases where the policy was set to Detect Only and a device became infected, remove the infection by using SentinelOne’s unique rollback capability. As the accompanying video shows, the rollback will revert any malicious impact on the device and restore encrypted files to their original state.
In case you do not have SentinelOne deployed, there are several steps that organizations can take to mitigate the risk of Vice Society ransomware attacks:
Educate employees
Employees should be educated on the risks of ransomware, and how to identify and avoid phishing emails, malicious attachments, and other threats. They should be encouraged to report suspicious emails or attachments, and to avoid opening them, or clicking on links or buttons in them.
Implement strong passwords
Organizations should implement strong, unique passwords for all user accounts, and should regularly update and rotate these passwords. Passwords should be at least 8 characters long and should include a combination of uppercase and lowercase letters, numbers, and special characters.
Enable multi-factor authentication
Organizations should enable multi-factor authentication (MFA) for all user accounts, to provide an additional layer of security. This can be done through the use of mobile apps, such as Google Authenticator or Microsoft Authenticator, or the use of physical tokens or smart cards.
Update and patch systems
Organizations should regularly update and patch their systems, to fix any known vulnerabilities, and to prevent attackers from exploiting them. This includes updating the operating system, applications, and firmware on all devices, as well as disabling any unnecessary or unused services or protocols.
Implement backup and disaster recovery
Organizations should implement regular backup and disaster recovery (BDR) processes, to ensure that they can recover from ransomware attacks or other disasters. This includes creating regular backups of all data and systems and storing these backups in a secure, offsite location. The backups should be tested regularly to ensure that they are working and that they can be restored quickly and easily.
Vice Society Ransomware FAQs
What is Vice Society Ransomware?
Vice Society is known for its ransomware extortion attacks on manufacturing, education, and healthcare organizations. It works as a double extortion attack and doesn’t operate as a ransomware-as-a-service model. It has targets across Europe and the United States and has made a significant compromise on the Los Angeles Unified School District.
Who is behind Vice Society Ransomware?
Vice Society is believed to have originated in Russia. Its ideal prey is universities, K-12 schools, colleges, and similar institutions.
How does Vice Society Ransomware spread?
Vice Society can steal data from ‘victims’ networks before encryption and then carry out double extortion attacks. It will threaten to publish the stolen data on the dark web unless the victim pays its ransom demand.
Which operating systems are targeted by Vice Society Ransomware?
Vice Society targets primarily Windows environments but sometimes infects Linux servers. Vice Society uses unpatched security holes, lack of network security, and vulnerable passwords. Unpatched software is most likely to be hit by organizations that are not in line with software patches.
What types of files does Vice Society Ransomware encrypt?
Vice Society encrypts various files, including documents, spreadsheets, databases, and images. It encrypts whatever is valuable to extort victims into paying. If the ransomware is disseminated via a network, it can encrypt shared drives and backups. You can protect your information by maintaining offline backups, using cloud storage with security controls, and having your network securely configured.
What encryption algorithms does Vice Society Ransomware use?
Vice Society Ransomware uses AES and RSA encryption in the majority of instances. AES encrypts the files, and RSA encrypts the decryption key, making it nearly impossible to decrypt files without paying. You can protect yourself by storing the backups offline, where even if Vice Society encrypts your files, you can restore your files without paying the attackers.
What security best practices help prevent Vice Society Ransomware infections?
Train your employees to recognize when they make demands and how to avoid engaging with cybercriminals online. Gaining strong security awareness is the first step towards acquiring an upper hand and preventing falling victim to these ransomware attacks. You will be better protected once you know what to watch out for.
Make an incident response and emergency plan soon and adopt a layered, multi-layered approach to security and threat prevention. You should also have rollback options in your infrastructure to restore unauthorized file changes from your local network cache in a 72-hour window. This can help prevent the changes made by the ransomware strain and protect your organization.