Close Menu
Jordan Gazette
  • Home
  • Jordan
  • Business
  • Lifestyle
  • Companies news
  • Submit A Press Release
Facebook X (Twitter) Instagram Pinterest
Breaking News:
  • Emirates introduces second service to Tokyo Narita
  • Arabian Automobiles’ Ramadan Campaign Puts INFINITI Luxury on Your Terms
  • Emirates Flight Catering (EKFC) commissions large-scale biodigester, with aim to reduce annual CO₂ emissions by 2,000 tonnes
  • Manhattan’s Legacy Finds a New Address in Dubai as Art House Hills Launches in Arjan
  • Dubai Customs discusses cooperation with senior Omani delegation
  • ÇáãØÈÎ ÇáÐí íÞÏã áß ÎíÇÑÇÊ æÇÚíÉ Ýí ÔåÑ ÇáÕíÇã: ÑãÖÇä ÈÕÍÉ ÃÝÖá: ÃØÚãÉ ÊÚÒøÒ ÇáØÇÞÉ æÇáÕÝÇÁ
  • AED 2 Dim Sums Take Over Business Bay
  • Wheelchair tennis makes historic debut, quarter-finals conclude and eala/tjen advance at mubadala abu dhabi open
Friday, February 6
Facebook X (Twitter) Instagram Pinterest
Jordan Gazette
  • Home
  • Jordan

    EU, HCST, Orange Jordan, and SESAME lead dialogue on ‘The Science We Need for 2050’

    APT Global publishes inaugural ESG report and unveils sustainable 400-person labour accommodation

    Arab Bank Group profits grow by 9.3% to $818.1mln for the first nine months of 2025

    Record-breaking results: Boursa Kuwait net profit climbs 59.81% to KD 23.05mln

    Faraday Future Announces Strategic Cooperation with RAK Motors to Oversee FX Super One Sales and Services in the UAE, Building a Complete Production-to-Service Ecosystem In the UAE

  • Business

    Faraday Future Announces New FX Super One Deliveries in the Middle East as It Continues to Advance Towards the Region’s 2026 Delivery Goals

    GBT closes $1.3 million pre-seed to expand smart city technologies in KSA

    SBC Summit Malta 2026 Rolls Out Dual-Structure Agenda Merging Strategy and Practice

    Faraday Future Showcases its EAI Vehicles and EAI Robotics Strategy at the UMEX 2026 in Abu Dhabi as it Drives a New Era of Mobility in the Middle East Marketplace

    The Ministry of Economy and Planning announces that it will launch the SUSTAIN Platform in 2026 to accelerate AI-enabled cross-sector collaboration for sustainable development, during the World Economic Forum Annual Meeting

  • Lifestyle

    Signia by Hilton launches Club Signia

    Legends Charity Game in Lisbon to raise millions for charity

    Joel Corry and Imanbek to headline star-studded SBC Summit Opening Party

    Diriyah Company showcases world-class luxury hospitality offerings at ILTM Asia Pacific 2025

    Zulal Wellness Resort partners with Qatar Airways Privilege Club

  • Companies news

    Emirates introduces second service to Tokyo Narita

    Arabian Automobiles’ Ramadan Campaign Puts INFINITI Luxury on Your Terms

    Emirates Flight Catering (EKFC) commissions large-scale biodigester, with aim to reduce annual CO₂ emissions by 2,000 tonnes

    Manhattan’s Legacy Finds a New Address in Dubai as Art House Hills Launches in Arjan

    Dubai Customs discusses cooperation with senior Omani delegation

  • Submit A Press Release
Jordan Gazette
Home » ESET Research: CosmicBeetle group joins forces with other ransomware gangs, targets businesses in Europe and Asia
Business

ESET Research: CosmicBeetle group joins forces with other ransomware gangs, targets businesses in Europe and Asia

Facebook Twitter Pinterest WhatsApp
Share
Facebook Twitter LinkedIn Pinterest WhatsApp

ESET researchers have mapped the recent activities of the CosmicBeetle threat group, documenting its new ScRansom ransomware being deployed and discovering connections to other well-established ransomware gangs. CosmicBeetle has been spreading ransomware to small and medium businesses (SMBs), mainly in Europe and Asia. ESET Research has observed the threat actor using the leaked LockBit builder and trying to leverage LockBit’s ransomware reputation. Besides LockBit, ESET believes that CosmicBeetle is probably a new affiliate of ransomware-as-a-service actor RansomHub, a new ransomware gang active since March 2024 with rapidly increasing activity.

“Probably due to the obstacles that writing custom ransomware from scratch brings, CosmicBeetle attempted to leech off LockBit’s reputation, possibly to mask the issues in the underlying ransomware and in turn to increase the chance that victims would pay,” says ESET researcher Jakub Souček, who analyzed the latest activity of CosmicBeetle. “Additionally, recently, we observed the deployment of ScRansom and RansomHub payloads on the same machine only a week apart. This execution of RansomHub was very unusual compared to the typical cases we have seen in ESET telemetry, but quite similar to CosmicBeetle’s modus operandi. Since there are no public leaks of RansomHub, this leads us to believe with medium confidence that CosmicBeetle may be a recent affiliate of theirs,” adds Souček.

CosmicBeetle often uses brute-force methods to breach its targets. Besides that, it misuses various known vulnerabilities. Small and medium-sized businesses from all sorts of verticals all over the world are the most common victims of this threat actor because that is the segment most likely to use the affected software, or lack robust patch management processes in place. ESET Research has observed attacks on SMBs in the following verticals: manufacturing, pharmaceuticals, legal, education, healthcare, technology, hospitality leisure, financial services, and regional government.

Besides encrypting, ScRansom can also kill various processes and services on the affected machine. ScRansom is not a very sophisticated piece of ransomware, though CosmicBeetle has been able to compromise interesting targets and cause great harm to them. This is mostly because CosmicBeetle is an immature actor in the ransomware world, and problems plague the deployment of ScRansom. Victims affected by ScRansom, who decide to pay, should be cautious.

ESET Research was able to obtain a decryptor implemented by CosmicBeetle for its recent encryption scheme. ScRansom is undergoing constant development, which is never a good sign for ransomware. The overcomplexity of the encryption (and decryption) process is prone to errors, making restoration of all files doubtful. Successful decryption relies on the decryptor working properly and on CosmicBeetle providing all the necessary keys, and even in that case, some files may be destroyed permanently by the threat actor. Even in the best-case scenario, decryption is long and complicated.

CosmicBeetle, active since at least 2020, is the name ESET researchers assigned to a threat actor discovered in 2023. This threat actor is most known for the usage of its custom collection of Delphi tools, commonly called Spacecolon, consisting of ScHackTool, ScInstaller, ScService, and ScPatcher.

About ESET:

ESET® provides cutting-edge digital security to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of known and emerging cyberthreats — securing businesses, critical infrastructure, and individuals. Whether it’s endpoint, cloud or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. An ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network.

Share. Facebook Twitter Pinterest LinkedIn WhatsApp

Related Posts

Companies News

Emirates introduces second service to Tokyo Narita

Companies News

Arabian Automobiles’ Ramadan Campaign Puts INFINITI Luxury on Your Terms

Companies News

Emirates Flight Catering (EKFC) commissions large-scale biodigester, with aim to reduce annual CO₂ emissions by 2,000 tonnes

Companies News

Manhattan’s Legacy Finds a New Address in Dubai as Art House Hills Launches in Arjan

Companies News

Dubai Customs discusses cooperation with senior Omani delegation

Companies News

ÇáãØÈÎ ÇáÐí íÞÏã áß ÎíÇÑÇÊ æÇÚíÉ Ýí ÔåÑ ÇáÕíÇã: ÑãÖÇä ÈÕÍÉ ÃÝÖá: ÃØÚãÉ ÊÚÒøÒ ÇáØÇÞÉ æÇáÕÝÇÁ

Companies News

AED 2 Dim Sums Take Over Business Bay

Companies News

Wheelchair tennis makes historic debut, quarter-finals conclude and eala/tjen advance at mubadala abu dhabi open

    Categories
    • Business (509)
    • Companies News (1,130)
    • Jordan (94)
    • Lifestyle (101)
    • MENA Business (18)
    © 2026 Jordan Gazette.
    • Homepage
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.