Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors CosmicBeetle

Also known as: NoName, EternalBlue, Zerologon, NONAME, Repellent Scorpius, BURNTCIGAR, including CUBA, BlackCat, Medusa, LockBit, RansomHub over the years

Description

CosmicBeetle has developed a sophisticated hybrid operating model that marries older high‑profile CVE exploitation with modern credential‑guessing techniques. Initial access is typically achieved via scanning for exposed services such as SMB (CVE‑2017‑0144) or FortiOS SSL‑VPN, followed by brute‑force attempts over RDP and SMB, often employing the Spacecolon toolset that includes ScHackTool, ScInstaller, and ScService. Once inside, the actor injects a custom ransomware package – ScRansom – backed by a deployable decryption utility requiring manual ProtectionKey entry, and supplements it with a RansomHub delivery payload to widen its attack surface. The actor’s execution methodology is distinctive: after establishing an RDP session over VPN or other remote protocols, CosmicBeetle frequently performs manual mouse movements and key strokes to trigger PowerShell scripts or Windows command‑shell commands that launch the ransomware chain. Persistence is achieved by creating local administrator accounts and modifying registry run keys as well as deploying services. Strategically, CosmicBeetle has exhibited a penchant for impersonation of well-known ransomware families such as LockBit; this tactic serves dual purposes: it erodes victims’ confidence in their own incident response capabilities and encourages payments under the guise of a “known” threat actor. The group further amplifies impact by deleting system logs, shutting down critical services, and destroying backups, thereby reducing the possibility of successful recovery. CosmicBeetle’s attacks often leave behind artifacts – process termination patterns, a unique file‑extension list used in encryption, and a “ProtectionKey” prompt – which can aid forensic investigators. By registering leak sites with domains such as Filecoder.Spacecolon or custom ransom leakage subdomains, the actor can monetize stolen data while maintaining operational secrecy.

Goals & Targeting

Targeted Sectors

Financial services
Healthcare
Manufacturing
Pharmaceutical
Government
Education
Hospitality
Media
Energy
Defense

Targeted Countries / Regions

UA
IN
US

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 hour ago

Executive Summary

CosmicBeetle is a financially driven threat actor that targets small‑to‑medium businesses across Europe, Asia and the United States by exploiting legacy SMB vulnerabilities such as EternalBlue and Zerologon, brute‑forcing RDP and SMB credentials, and deploying its custom ScRansom ransomware in conjunction with RansomHub payloads. The group also leverages leaked LockBit 3.0 builder code to impersonate LockBit, aiming to increase victim compliance and payment. Its operations combine public‑facing exploit use, manual RDP manipulation, data destruction and a leak site for stolen data.

Goals & Targeting

CosmicBeetle’s core strategic objective is financial gain through ransomware extortion. The group targets small‑ to medium‑sized enterprises (SMBs) that are less likely to have robust security controls and backup policies, focusing on sectors such as finance, healthcare, manufacturing, energy, education, hospitality, media, pharmaceutical, government and defense. Operationally, the actor concentrates on geographically diverse markets – primarily Ukraine, India and the United States – leveraging publicly available exploits, vulnerable infrastructure, and brute‑force techniques to penetrate networks with minimal defensive friction.

Enhanced Description

Key Capabilities

  • Exploit legacy SMB vulnerabilities such as EternalBlue (CVE-2017-0144)
  • Exploiting Zerologon (CVE-2020-1472) and newer CVEs (CVE-2021-42278/42287, CVE-2022-42475)
  • Brute-force credential guessing on SMB, RDP and VPN accounts
  • Vulnerability scanning of internet‑exposed IPs including FortiOS SSL‑VPN
  • Utilizing Spacecolon toolset (ScHackTool, ScInstaller, ScService) for deployment
  • Deploying custom ScRansom ransomware alongside RansomHub payloads
  • Deleting files/services and destroying backups to amplify impact
  • Impersonating LockBit brand via leaked 3.0 builder code
  • Manually manipulating victim’s mouse during authenticated RDP sessions
  • Creating local administrator accounts for persistence
  • Abusing valid accounts from credential theft
  • Requiring manual entry of ProtectionKey per decryption ID in decryptor
  • Registering leak sites/domains to host stolen data

MITRE ATT&CK Tactics

Initial Access
Execution
Impact
Reconnaissance
Resource Development
Persistence
Defense Evasion
Credential Access

ATT&CK Techniques

T1110.001
T1068
T1021
T1590.005
T1595.002
T1583.001
T1587.001
T1588.001
T1588.002
T1588.005
T1190
T1204
T1059.003
T1059.001
T1136.001
T1078
T1140
T1212
T1485
T1486

Software / Tooling

ScRansom
RansomHub
LockBit 3.0 builder (leaked)
Decryptor (ProtectionKey tool)
ScHackTool
Spacecolon
LockBit Black builder

Campaigns & Victims

CosmicBeetle operates with a consistent, low‑frequency campaign cadence aimed at SMBs in high‑value sectors. The group initiates attacks via exploit reconnaissance and brute‑force credential guessing, then establishes an authenticated RDP session to manually trigger ransomware execution. Over time, they have refined their technique by adding data destruction tactics and LockBit impersonation, thereby reducing the likelihood of recovery and increasing the monetary value extracted from victims. Known campaigns involve early 2024 attacks targeting European SMEs, with a noticeable shift toward India and U.S. markets in late summer.

IOC Patterns

  • CVE-2017-0144
  • CVE-2020-1472
  • CVE-2021-42278/42287
  • CVE-2022-42475
  • Process or service termination patterns
  • Brute‑force login attempts
  • Leak site domain(s) for stolen data distribution
  • Targeted ransomware file extension list
  • Work ID string format in ransom notes

Recommended Actions

  • Ensure timely patching of known vulnerabilities such as SMB-CVE-2017-0144, Zerologon (CVE-2020-1472), and FortiOS SSL‑VPN CVEs.
  • Disable obsolete SMB services (e.g., SMBv1) and enforce strong, multi‑factor authentication for RDP and VPN access.
  • Implement rate limiting and real‑time monitoring for brute‑force login attempts against SMB/RDP accounts.
  • Deploy endpoint detection that flags bulk file encryption events or large lists of targeted file extensions.
  • Block outbound traffic to known leak sites and domains used by CosmicBeetle (“Filecoder.Spacecolon”, etc.).
  • Maintain offline, isolated backups and test recovery procedures frequently.
  • Use updated antivirus/malware signatures capable of detecting custom ransomware families such as ScRansom and RansomHub.”],

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 5 Domain 10 SHA-1 Hash 3 Email Address 2

References

  1. www.welivesecurity.com — Cited by web research for: EternalBlue
  2. thehackernews.com — Cited by web research for: NONAME
  3. www.welivesecurity.com — Cited by web research for: T1053.005
  4. www.eset.com — Cited by web research for: LockBit
  5. www.bitdefender.com — Cited by web research for: DragonForce

Intel Summary

32

Techniques

46

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

Ransomware
Wiper / Destructive
APT
SMB-Sector
Credential-Dumping
Impersonation
Custom-Malware

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.