Sharpdepositorcrypter

Malware updated 4 months ago (2024-05-04T20:04:25.092Z)
Download STIX
Preview STIX
SharpDepositorCrypter, also known as OMCLoader, is a form of malware that was primarily utilized by the BlackBasta ransomware group during most of 2022. The malware originated as a loader for a .NET infostealer named SharpDepositor, which may explain its name found in PDB strings of early samples. However, it has since evolved into a more complex loader and is no longer restricted to .NET payloads. The initial versions of SharpDepositorCrypter encrypted their payload using RC4 and base64 encoding, but newer iterations have switched to using AES encryption. Throughout 2022, SharpDepositorCrypter served as the primary loader for BlackBasta ransomware, significantly contributing to the group's cyber-attacks. However, its usage began to decline in 2023. BlackBasta started to increasingly employ other crypters such as Quixotic, Quicksand, Dave, and Tron for their operations. This shift in strategy might be due to the evolution of cybersecurity measures or a strategic decision within the BlackBasta group. To differentiate between the different versions of this malware, we are currently tracking the earlier RC4-based samples as SharpDepositorCrypter, and the AES-based versions under the name OMCLoader. This distinction helps us understand the evolution of the malware and provides better insight into the tactics, techniques, and procedures (TTPs) used by threat actors like BlackBasta. It remains crucial to stay updated with these developments to effectively mitigate the risks posed by such evolving cyber threats.
Description last updated: 2024-01-06T18:32:31.743Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Sharpdepositorcrypter Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
SecurityIntelligence.com
a year ago
The Trickbot/Conti Crypters: Where Are They Now?