Also known as: NoName, EternalBlue, Zerologon, NONAME, Repellent Scorpius, BURNTCIGAR, including CUBA, BlackCat, Medusa, LockBit, RansomHub over the years
CosmicBeetle has developed a sophisticated hybrid operating model that marries older high‑profile CVE exploitation with modern credential‑guessing techniques. Initial access is typically achieved via scanning for exposed services such as SMB (CVE‑2017‑0144) or FortiOS SSL‑VPN, followed by brute‑force attempts over RDP and SMB, often employing the Spacecolon toolset that includes ScHackTool, ScInstaller, and ScService. Once inside, the actor injects a custom ransomware package – ScRansom – backed by a deployable decryption utility requiring manual ProtectionKey entry, and supplements it with a RansomHub delivery payload to widen its attack surface. The actor’s execution methodology is distinctive: after establishing an RDP session over VPN or other remote protocols, CosmicBeetle frequently performs manual mouse movements and key strokes to trigger PowerShell scripts or Windows command‑shell commands that launch the ransomware chain. Persistence is achieved by creating local administrator accounts and modifying registry run keys as well as deploying services. Strategically, CosmicBeetle has exhibited a penchant for impersonation of well-known ransomware families such as LockBit; this tactic serves dual purposes: it erodes victims’ confidence in their own incident response capabilities and encourages payments under the guise of a “known” threat actor. The group further amplifies impact by deleting system logs, shutting down critical services, and destroying backups, thereby reducing the possibility of successful recovery. CosmicBeetle’s attacks often leave behind artifacts – process termination patterns, a unique file‑extension list used in encryption, and a “ProtectionKey” prompt – which can aid forensic investigators. By registering leak sites with domains such as Filecoder.Spacecolon or custom ransom leakage subdomains, the actor can monetize stolen data while maintaining operational secrecy.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
CosmicBeetle is a financially driven threat actor that targets small‑to‑medium businesses across Europe, Asia and the United States by exploiting legacy SMB vulnerabilities such as EternalBlue and Zerologon, brute‑forcing RDP and SMB credentials, and deploying its custom ScRansom ransomware in conjunction with RansomHub payloads. The group also leverages leaked LockBit 3.0 builder code to impersonate LockBit, aiming to increase victim compliance and payment. Its operations combine public‑facing exploit use, manual RDP manipulation, data destruction and a leak site for stolen data.
Goals & Targeting
CosmicBeetle’s core strategic objective is financial gain through ransomware extortion. The group targets small‑ to medium‑sized enterprises (SMBs) that are less likely to have robust security controls and backup policies, focusing on sectors such as finance, healthcare, manufacturing, energy, education, hospitality, media, pharmaceutical, government and defense. Operationally, the actor concentrates on geographically diverse markets – primarily Ukraine, India and the United States – leveraging publicly available exploits, vulnerable infrastructure, and brute‑force techniques to penetrate networks with minimal defensive friction.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
CosmicBeetle operates with a consistent, low‑frequency campaign cadence aimed at SMBs in high‑value sectors. The group initiates attacks via exploit reconnaissance and brute‑force credential guessing, then establishes an authenticated RDP session to manually trigger ransomware execution. Over time, they have refined their technique by adding data destruction tactics and LockBit impersonation, thereby reducing the likelihood of recovery and increasing the monetary value extracted from victims. Known campaigns involve early 2024 attacks targeting European SMEs, with a noticeable shift toward India and U.S. markets in late summer.
IOC Patterns
Recommended Actions
No campaigns linked yet.
No observed data linked yet.
32
Techniques
46
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics