Quixotic

Malware updated 4 months ago (2024-05-04T20:19:27.204Z)
Download STIX
Preview STIX
Quixotic is a potent malware that has been used to crypt various ransomware samples, including BlackBasta and CobaltStrike. In May 2023, it was utilized to encrypt a BlackBasta ransomware sample, while in October 2022, it played a significant role in a CobaltStrike sample used in a BlackBasta attack. The malware stores its payload in a data section and employs XOR decryption with a key constructed from multiple strings. It's noteworthy that we began tracking Quixotic and Quartz in May 2022, and first observed Quicksand in March 2023. During 2023, there was a noticeable shift in the malware landscape as the use of SharpDepositorCrypter (SDC)/OMCLoader declined. In contrast, BlackBasta ransomware increasingly employed other crypters, including Quixotic, Quicksand, Dave, and Tron. Qakbot, another harmful software, had been using its own set of crypters, including CryptOne, Quartz, and Quixotic. Intriguingly, similarities were identified between the PE loading code found in Quicksand and the shellcode loaders used by Quartz and Quixotic. The increasing use of Quixotic and its counterparts has raised concerns among cybersecurity professionals. The malware's ability to infiltrate systems unnoticed and cause significant damage or disruption highlights its threat level. Furthermore, the observed trend towards diversifying crypters used by ransomware like BlackBasta suggests an evolving threat landscape, necessitating ongoing vigilance and robust countermeasures.
Description last updated: 2024-05-04T20:03:57.309Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Quixotic Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
6 months ago
Zoomer Hackers Shut Down the Biggest Extortion Ring of All | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker | National Cyber Security Consulting
SecurityIntelligence.com
a year ago
The Trickbot/Conti Crypters: Where Are They Now?