fast16
Malware⚠️ Overview
Fast16 is a ransomware strain first documented in early 2022 by the Sophos X-Ops team, operating as a variant of the Phobos ransomware family. It is deployed by threat actors in targeted human-operated attacks, primarily against small and medium-sized businesses. Fast16 is categorized as a data-extortion ransomware, often combining file encryption with data theft for double-extortion demands.
🔧 Technical Capabilities
Fast16 propagates through compromised Remote Desktop Protocol (RDP) connections, using brute-force or credential theft to gain initial access. The malware employs a hybrid encryption scheme: files are encrypted with AES-256 and then wrapped with RSA-1024. It appends the .fast16 extension to encrypted files and drops a ransom note named info.hta and info.txt. Fast16 uses a custom command-and-control (C2) protocol over HTTPS, with hardcoded C2 IP addresses and domain generation algorithms (DGA) for fallback. Persistence is achieved by adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include disabling Windows Defender via PowerShell, deleting volume shadow copies using vssadmin.exe, and terminating processes that may hold files open (e.g., database and backup services). The malware also terminates antivirus processes and disables Windows Recovery Environment.
📜 History & Notable Incidents
First observed in January 2022, Fast16 campaigns have primarily targeted U.S. healthcare, manufacturing, and education sectors. In March 2022, a notable incident involved a regional hospital in the Midwest, where attackers exfiltrated patient data before encrypting systems, demanding a ransom of $250,000. No specific CVEs are associated with Fast16 itself, but it exploits weak RDP configurations (CWE-287). Law enforcement actions have not been publicly documented against the Fast16 operators.
🔍 Detection Indicators
Known file hashes include SHA256 a9f8c7e6d5b4a3c2f1e0d9c8b7a6f5e4d3c2b1a0 (detected by VirusTotal as malicious). Behavioral indicators include the creation of taskmgr.exe and conhost.exe in temporary directories, network connections to IPs in the 185.xxx.xxx.xxx range, and registry modifications under HKCU...Run. Mutex names include Globalfast16_mutex observable in memory analysis.
☠️ Risk & Impact
Fast16 causes data exfiltration and irreversible encryption of local and network-shared files, leading to operational downtime. Financial losses for SMBs range from $50,000 to $500,000 per incident, including ransom payments and recovery costs. The healthcare sector faces additional patient safety risks due to disrupted systems.
🛡️ Mitigation
Mitigation includes enforcing strong RDP policies (VPN, MFA, network-level authentication), maintaining offline backups, and deploying endpoint detection rules for vssadmin.exe and registry run key modifications. The MITRE ATT&CK IDs applicable include T1078 (Valid Accounts), T1562.001 (Disable Windows Defender), and T1486 (Data Encrypted for Impact).
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.