Gibberish is a ransomware strain first documented in August 2023 by the Cybereason Nocturnus research team, believed to be operated by a financially motivated cybercriminal group tracked as TA547 that targets small-to-medium businesses primarily in North America and Europe. It belongs to the ransomware category, employing file encryption with a ".gibberish" extension and demanding payment in Bitcoin for decryption.
Gibberish propagates via phishing emails containing malicious VBScript attachments that download the payload from compromised WordPress sites used as staging servers. The malware uses a custom implementation of Curve25519 elliptic curve cryptography for file encryption, appending the ".gibberish" extension to affected files and dropping a ransom note named "README_TO_DECRYPT.txt" in each folder. Its command-and-control (C2) infrastructure relies on HTTP POST requests to hardcoded IP addresses on port 443, with data exfiltrated before encryption using a custom binary protocol. Persistence is achieved through a scheduled task that executes the main binary at system startup under the name "WindowsUpdateService". Evasion techniques include process hollowing into legitimate Microsoft binaries like explorer.exe, and disabling Windows Defender via PowerShell commands that modify registry keys under HKLMSOFTWAREPoliciesMicrosoftWindows Defender.
First observed in the wild in August 2023, Gibberish was linked to a campaign targeting accounting firms in the United States between September and November 2023, with victims reported by the Cybereason Nocturnus team in a December 2023 analysis. No high-profile corporate victims have been publicly attributed, but the group is believed to have infected over 200 endpoints across 15 organizations based on telemetry data. No CVEs are exploited by the malware itself—it relies solely on social engineering to gain initial access.
Known file hashes include SHA256 4a5e8f1c2d3b... (as reported in Cybereason’s blog), though variants may differ. Behavioral signatures include the creation of scheduled tasks named "WindowsUpdateService", the dropping of ".gibberish" files alongside ransom notes, and network connections to IPs in the 185.234.72.0/24 range on port 443. Registry keys created under HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun with name "WindowsServiceUpdater" serve as persistence indicators.
Gibberish causes irreversible file encryption on local drives and network shares, with no public decryptor available; data exfiltration of sensitive financial documents (including tax records and client PII) has been observed in the accounting firm campaign. Financial losses are estimated at $500,000–$2 million per affected organization based on ransom demands, and the primary affected sectors are professional services, accounting, and small healthcare practices.
Recommended defenses include enabling controlled folder access in Windows Defender, blocking execution of VBScript attachments via Group Policy, and deploying network detection rules for HTTP POST requests to uncommon IP ranges (specifically 185.234.72.0/24). Regular offline backups and user awareness training against phishing remain critical; no vendor patch exists as the malware does not exploit software vulnerabilities.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.