Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Ransomware - RansomHub Affiliates Exploit AI-Generated Python Backdoor in Advanced Cyberattacks
Ransomware Artificial Intelligence Attacks Latest News News & Analysis

RansomHub Affiliates Exploit AI-Generated Python Backdoor in Advanced Cyberattacks

Kirsten DoyleBy Kirsten DoyleJanuary 16, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
RansomHub
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

A sophisticated Python-based backdoor, potentially developed using AI, has been identified as a critical tool for RansomHub affiliates to infiltrate and maintain access to compromised networks. The discovery, made by Andrew Nelson, Principal Digital Forensics and Incident Response (DFIR) Consultant at GuidePoint Security, reveals new tactics being used by ransomware gangs. 

A Lucrative Model

RansomHub, a Ransomware-as-a-Service (RaaS) operation that debuted in February 2024, has rapidly gained notoriety in the cybercrime ecosystem. Known for its generous affiliate payment structure and multi-platform capabilities, the group is a formidable threat to entities worldwide.

RansomHub offers a generous 90/10 payment split, allowing affiliates to retain a whopping 90% of ransom payments—quite a lot more than its competitors. Affiliates leverage ransomware developed in Golang and C++, which supports platforms including Windows, Linux, and ESXi, and utilizes robust encryption algorithms such as AES256, ChaCha20, and XChaCha20.

Breaking Down the Threat

The backdoor, deployed via Remote Desktop Protocol (RDP) lateral movement, allows malefactors to entrench themselves within a victim’s network and facilitates the deployment of RansomHub encryptors across compromised systems. The tool is polished, functional, and heavily obfuscated using techniques from services like PyObfuscate[.]com to avoid detection.

GuidePoint Security’s review of the backdoor identified unique indicators of compromise, including:

  • Obfuscated filenames and scheduled task names.
  • Command-and-control (C2) addresses.
  • Precise use of the SOCKS5 protocol to establish persistent, tunneled connections.

AI-Driven Code Excellence

GuidePoint’s analysis suggests that the malware’s quality points to AI-assisted development. The Python code is structured with clearly defined classes, descriptive variable names, and comprehensive error handling, characteristics often found in AI-generated code. Despite obfuscation efforts, the code remains highly readable and testable once de-obfuscated, indicating the skill and resources behind its creation.

The Attack Lifecycle

The attack begins with initial access facilitated by SocGholish (FakeUpdate) malware. Once inside, the malicious actors deploy the Python backdoor within minutes, using it to escalate privileges and move laterally across the network. Key steps in the deployment process include:

  1. Installing Python and necessary libraries.
  2. Setting up a reverse proxy script.
  3. Establishing persistence through Windows scheduled tasks.

The backdoor functions as a reverse proxy, connecting to hardcoded C2 addresses and using a SOCKS5-like tunnel for lateral movement. Network traffic analysis confirms its ability to proxy traffic through victim systems, providing attackers with stealthy access to the broader network.

Evolving Malware Characteristics

The latest version of the Python-based backdoor features significant updates, including:

  • Hardcoded C2 variables instead of passing them as arguments.
  • Enhanced obfuscation methods to evade detection.
  • A refined tunneling mechanism for TCP traffic, though it remains limited to IPv4 and does not support IPv6.

GuidePoint Security identified 18 active IP addresses associated with the C2 infrastructure and has made these available via a collaborative GitHub feed.

The Broader Implications

This development highlights the growing trend of ransomware groups leveraging AI and advanced scripting to refine their tools. RansomHub’s affiliates demonstrate a high level of sophistication, from social engineering during initial access to maintaining persistence with bespoke malware.

For business, this highlights the need for stronger defenses, including:

  • Continuous monitoring for obfuscated scripts and unusual C2 traffic.
  • Employee training to counter social engineering attempts.
  • Proactive use of threat intelligence feeds to identify known indicators of compromise.

The discovery of this backdoor cements RansomHub’s reputation as a major threat in the ransomware ecosystem. Its combination of AI-driven development, advanced obfuscation, and functionality makes it a potent weapon for affiliates.

As ransomware groups evolve their tactics, security practitioners need to be alert, using real-time intelligence and adaptive defenses to counter this scourge. Updates on associated C2 addresses and additional findings are available on GuidePoint Security’s GitHub feed for community collaboration.

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    Dutch police, NCSC take down major botnet
  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw
  • Kirsten Doyle
    CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet
  • Kirsten Doyle
    Threat Actors Deploy Tiflux RMM for Persistent Remote Access

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Lazarus Group Turns to Medusa Ransomware in Escalating Global Extortion Campaign

February 26, 20263 Mins Read

The Cyberattack That Exposed the Fragility of Digital Heritage

February 11, 20268 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}