Sophos released new findings into the connections between the most prominent ransomware groups in its report, āClustering Attacker Behavior Reveals Hidden Patterns,ā after a three month investigation during the first quarter of 2023.
Distinct Similarities
SophosĀ X-Ops detected clear parallels between four different ransomware attacks involving Hive, BlackĀ Basta, andĀ twoĀ attacksĀ byĀ Royal, despiteĀ RoyalĀ beingĀ aĀ closedĀ offĀ groupĀ thatĀ doesn’tĀ overtlyĀ solicitĀ affiliatesĀ from undergroundĀ forums.
The research uncovered similarities between the attacks, including the use of the same usernames and passwords and batch scripts and files to execute instructions on compromised systems. The results indicate that all three groups are either sharing affiliations or specific technical information about their attacks.
Granular level
āBecause the ransomware-as-a-service model requires outside affiliates to carry out attacks, itās not uncommon for there to be crossover in the tactics, techniques, and procedures (TTPs) between these different ransomware groups. However, in these cases, the similarities weāre talking about are at a very granular level. These highly specific, unique behaviors suggest that the Royal ransomware group is much more reliant on affiliates than previously thought. The new insights weāve gained about Royalās work with affiliates and possible ties to other groups speak to the value of Sophosā in-depth, forensic investigations,ā said Andrew Brandt, principal researcher, Sophos.

Brandt emphasizes the importance of understanding specific attacker behavior for response teams to respond to active attacks more quickly and for security providers to create stronger protections for customers.
āWhen protections are based on behaviors, it doesnāt matter who is attackingāRoyal, Black Basta, or otherwiseāpotential victims will have the necessary security measures in place to block subsequent attacks that display some of the same distinct characteristics,ā said Brandt.










