PonyFinal Ransomware Compromised Corporate Networks in Targeted Operations

NJCCIC Alert

Original Release Date: 6/2/2020

Summary

Over the past two months, a new ransomware variant, “PonyFinal”, has infected corporate networks in the US, India, and Iran. It is a Java-based, human-operated ransomware, in which threat actors breach corporate networks before deploying the ransomware. In previous incidents, the threat actors behind the ransomware brute-forced the password for an account on the company’s systems management server and then deployed a Visual Basic script (VBscript) that ran a PowerShell reverse shell to steal local data. The threat actors spread to other systems on the network and then launched the ransomware. The attackers have targeted workstations with Java Runtime Environment (JRE) installed or, if not found, installed JRE on workstations before running the ransomware. Encrypted files are appended with the .enc file extension and the ransom note provided is often named README_files.txt and provides instructions to pay the ransom demand. PonyFinal has repeatedly targeted the healthcare sector during the COVID-19 pandemic. There is no known decryption tool at the time of this writing.

Recommendations

The NJCCIC advises following the recommendations in the Ransomware: Risk Mitigation Strategies guide, which includes establishing a comprehensive data backup plan. More information can be found in the Microsoft Security Intelligence Twitter thread and the ZDnet article.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.