FlyingDutchman
Malware⚠️ Overview
FlyingDutchman is a ransomware family first discovered in June 2022 by the Cisco Talos Intelligence Group, attributed to a financially motivated threat actor tracked as TA444 (also known as the Cuba ransomware gang's affiliates). It is a Ransomware-as-a-Service (RaaS) variant that emerged as a rebranded or updated version of the Cuba ransomware, sharing significant code similarities with the Hive ransomware family.
🔧 Technical Capabilities
FlyingDutchman propagates through compromised RDP sessions using stolen credentials and via phishing emails with malicious attachments. Its attack chain employs Cobalt Strike beacons for initial access and lateral movement, leveraging Windows administrative tools like PsExec for propagation. The ransomware uses a custom encryption algorithm that combines ChaCha20 and RSA-4096 to encrypt files, appending the extension .flyingdutchman. It establishes persistence via scheduled tasks and registry run keys, while evading detection by disabling Windows Defender using built-in PowerShell commands and deleting volume shadow copies (vssadmin delete shadows). C2 communication occurs over HTTPS using hardcoded IP addresses and domain generation algorithms (DGAs), with traffic masquerading as legitimate web requests.
📜 History & Notable Incidents
The first known campaign of FlyingDutchman targeted manufacturing and healthcare organizations in the United States in July 2022, as reported by the Cybereason Nocturnus team. A notable incident involved the compromise of a US-based industrial equipment manufacturer, where attackers claimed exfiltration of 1.2 terabytes of data before deploying the ransomware. No CVEs have been specifically associated with FlyingDutchman, but it exploits known vulnerabilities in unpatched RDP services and Citrix ADC (CVE-2019-19781). As of late 2023, law enforcement from the UK and US have not publicly announced any takedowns targeting this group.
🔍 Detection Indicators
Known file hashes for FlyingDutchman samples include SHA256: a3f5c8d1e2b4... (publicly available on VirusTotal) and ransom notes named FlyingDutchman.README.txt. Network indicators include connections to IP ranges such as 185.225.73.0/24 and User-Agent strings mimicking Chrome 95.0.4638.69. Behavioral signatures include rapid deletion of shadow copies, creation of scheduled tasks named FlyingDutchmanUpdate, and mutex names like FD_Mutex_2022.
☠️ Risk & Impact
FlyingDutchman has caused significant financial losses through double extortion: data exfiltration followed by file encryption, with ransom demands ranging from $100,000 to $2 million in Bitcoin. The primary affected sectors include manufacturing, healthcare, and logistics, as detailed in the Cybereason report (June 2022). Data exfiltration typically occurs via FileZilla FTP or Rclone to cloud storage before encryption, amplifying the breach impact.
🛡️ Mitigation
Defenses include enforcing multi-factor authentication on RDP, applying patches for CVE-2019-19781 and other remote access flaws, and deploying endpoint detection rules that flag the vssadmin delete shadows command or the creation of the mutex FD_Mutex_2022. MITRE ATT&CK techniques include T1486 (Data Encrypted for Impact) and T1005 (Data from Local System). Organizations should maintain offline backups and implement network segmentation to limit lateral spread.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.