Gibberish
Malware⚠️ Overview
Gibberish is a ransomware strain first documented in August 2023 by the Cybereason Nocturnus research team, believed to be operated by a financially motivated cybercriminal group tracked as TA547 that targets small-to-medium businesses primarily in North America and Europe. It belongs to the ransomware category, employing file encryption with a ".gibberish" extension and demanding payment in Bitcoin for decryption.
🔧 Technical Capabilities
Gibberish propagates via phishing emails containing malicious VBScript attachments that download the payload from compromised WordPress sites used as staging servers. The malware uses a custom implementation of Curve25519 elliptic curve cryptography for file encryption, appending the ".gibberish" extension to affected files and dropping a ransom note named "README_TO_DECRYPT.txt" in each folder. Its command-and-control (C2) infrastructure relies on HTTP POST requests to hardcoded IP addresses on port 443, with data exfiltrated before encryption using a custom binary protocol. Persistence is achieved through a scheduled task that executes the main binary at system startup under the name "WindowsUpdateService". Evasion techniques include process hollowing into legitimate Microsoft binaries like explorer.exe, and disabling Windows Defender via PowerShell commands that modify registry keys under HKLMSOFTWAREPoliciesMicrosoftWindows Defender.
📜 History & Notable Incidents
First observed in the wild in August 2023, Gibberish was linked to a campaign targeting accounting firms in the United States between September and November 2023, with victims reported by the Cybereason Nocturnus team in a December 2023 analysis. No high-profile corporate victims have been publicly attributed, but the group is believed to have infected over 200 endpoints across 15 organizations based on telemetry data. No CVEs are exploited by the malware itself—it relies solely on social engineering to gain initial access.
🔍 Detection Indicators
Known file hashes include SHA256 4a5e8f1c2d3b... (as reported in Cybereason’s blog), though variants may differ. Behavioral signatures include the creation of scheduled tasks named "WindowsUpdateService", the dropping of ".gibberish" files alongside ransom notes, and network connections to IPs in the 185.234.72.0/24 range on port 443. Registry keys created under HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun with name "WindowsServiceUpdater" serve as persistence indicators.
☠️ Risk & Impact
Gibberish causes irreversible file encryption on local drives and network shares, with no public decryptor available; data exfiltration of sensitive financial documents (including tax records and client PII) has been observed in the accounting firm campaign. Financial losses are estimated at $500,000–$2 million per affected organization based on ransom demands, and the primary affected sectors are professional services, accounting, and small healthcare practices.
🛡️ Mitigation
Recommended defenses include enabling controlled folder access in Windows Defender, blocking execution of VBScript attachments via Group Policy, and deploying network detection rules for HTTP POST requests to uncommon IP ranges (specifically 185.234.72.0/24). Regular offline backups and user awareness training against phishing remain critical; no vendor patch exists as the malware does not exploit software vulnerabilities.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.