The cybersecurity landscape has witnessed a surge in ransomware attacks recently, and a new player known as “Volcano Demon” has emerged with a flurry of attacks over the past few weeks. This threat actor employs unique locker malware and sophisticated evasion techniques, making detection and forensic investigations significantly challenging. Identified by researchers at Halcyon, Volcano Demon introduces a novel malware, LukaLocker, which encrypts files with a .nba extension.
Innovative Evasion Techniques
Volcano Demon’s operations are notable for their meticulous evasion tactics. Before initiating an attack, the group installs limited logging and monitoring solutions on the victim’s systems. They also use “No Caller ID” numbers to conduct ransom negotiations, further complicating the detection and tracking efforts of security experts. According to a blog post by Halcyon, the attackers clear logs prior to exploitation, hindering a comprehensive forensic analysis.
Interestingly, despite employing double extortion methods, Volcano Demon does not have a leak site to post stolen data. This further muddies the waters for investigators trying to track and attribute the attacks.
Technical Overview of LukaLocker
The LukaLocker malware, used by Volcano Demon, is designed to encrypt files on both Windows workstations and servers. The attackers utilize common administrative credentials harvested from the victim’s network to deploy a Linux version of LukaLocker. Prior to encrypting files, they exfiltrate data to their command-and-control (C2) server, setting the stage for double extortion.
Victims are instructed to contact the attackers via the qTox messaging software and await a callback, adding another layer of complexity to the communication tracking process.
First discovered by Halcyon researchers on June 15, LukaLocker is an x64 PE binary written and compiled in C++. It employs API obfuscation and dynamic API resolution, techniques that obscure its malicious functions and help evade detection and reverse engineering efforts.
Similarities to Conti Ransomware
LukaLocker bears some resemblance to the now-defunct Conti ransomware. Upon execution, unless a specific flag (“–sd-killer-off”) is set, LukaLocker terminates various security and monitoring services on the network. These services include antivirus and endpoint protection tools, backup and recovery software, database systems from Microsoft, IBM, and Oracle, as well as Microsoft Exchange Server, virtualization software, and remote access tools. Additionally, it closes other processes such as web browsers, Microsoft Office applications, and remote access software like TeamViewer.
The encryption mechanism used by LukaLocker is the Chacha8 cipher, with the key and nonce generated via the Elliptic-curve Diffie-Hellman (ECDH) key agreement algorithm over Curve25519. The malware can encrypt files fully or partially, with encryption percentages ranging from 10% to 100%.
Indicators of Compromise and Defense Strategies
Despite the challenges in conducting a full forensic analysis due to Volcano Demon’s evasion tactics, Halcyon researchers have identified various indicators of compromise (IoCs). These include a Trojan named Protector.exe, the Locker.exe encryptor, a Linux cryptor file called Linux locker/bin, and command-line scripts like Reboot.bat that precede encryption. Some of these IoCs have been uploaded to Virus Total for public reference.
Given the sophisticated methods employed by Volcano Demon, it is crucial for organizations to adopt robust defense measures. Since the attackers exploit administrative credentials to infiltrate networks, implementing multifactor authentication (MFA) and conducting thorough employee training to recognize phishing campaigns are essential steps in mitigating the risk of compromise.
Conclusion
Ransomware remains a persistent and disruptive threat to organizations worldwide. Despite numerous law enforcement actions against major cybercriminal gangs, new adversaries like Volcano Demon continue to emerge with innovative techniques and malware. Organizations must remain vigilant and proactive in their cybersecurity efforts, employing advanced detection tools and comprehensive training programs to defend against these evolving threats.
In conclusion, the emergence of Volcano Demon highlights the ever-changing nature of the ransomware landscape. As attackers develop new methods and tools, defenders must continually adapt their strategies to stay ahead. By understanding the tactics and techniques used by adversaries like Volcano Demon, organizations can better prepare for and respond to ransomware attacks, safeguarding their critical assets and data.

Discover more from Open Security Labs
Subscribe to get the latest posts sent to your email.







