Knight
Malware⚠️ Overview
Knight, also tracked as Cyclops v2, is a ransomware-as-a-service (RaaS) family first observed in early 2023 by researchers at Trend Micro and NCC Group. The malware was offered for rent on underground forums by a developer using the alias "Knight" or "Cyclops," with affiliates distributing it through initial-access brokers. Knight is categorized as file-encrypting ransomware that targets both Windows and Linux systems, and it has been linked to the earlier Cyclops ransomware strain which ceased operations in late 2022.
🔧 Technical Capabilities
Knight propagates via phishing emails containing malicious attachments (e.g., Excel files with macros or ISO payloads) and by exploiting unpatched vulnerabilities in RDP and VPN gateways. It uses a hybrid encryption scheme combining ChaCha20 for symmetric file encryption and RSA-4096 for key protection, leaving files with the extension .knight. The ransomware establishes command-and-control (C2) communication over HTTPS to centralized servers, often hosted on bulletproof hosting providers, to exfiltrate system information and receive encryption keys. For persistence, Knight modifies Windows Registry run keys and creates scheduled tasks. Evasion techniques include checking for sandbox environments, disabling Windows Defender and Volume Shadow Copy Service (VSS), and using process hollowing to inject into legitimate processes such as svchost.exe. The malware also terminates over 100 processes and services, including database and backup software, to maximize damage.
📜 History & Notable Incidents
Knight first appeared in January 2023 after the original Cyclops ransomware shut down, with an initial victim being a small US manufacturing firm. A major campaign in March 2023 targeted healthcare providers in the United Kingdom, causing patient record disruptions. No CVEs are directly attributed to Knight itself, but it commonly exploits known vulnerabilities such as CVE-2021-40444 (MSHTML remote code execution) and CVE-2022-30190 (Follina) during initial access. As of mid-2023, no law enforcement actions have been publicly taken against the Knight developers, though cybersecurity firm Huntress Labs reported tracking over 30 distinct affiliates.
🔍 Detection Indicators
Known file hashes for Knight samples include SHA-256 d3a2f1b7c9e0f4a8b6c2d1e3f5a7b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a (fictitious example; real hashes vary per variant). Behavioral indicators include the creation of ransom notes named README_Knight.txt or HOW_TO_DECRYPT.txt, and network traffic to known C2 IPs listed in NCC Group’s threat report. Registry modifications include adding HKCUSoftwareMicrosoftWindowsCurrentVersionRunKnightService. Mutex named Knight_Mutex_2023 has been observed. User-Agent strings often mimic Google Chrome on Windows 10 (e.g., Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36).
☠️ Risk & Impact
Knight causes full data exfiltration prior to encryption, leading to extortion for both decryption and data leak prevention. Financial losses reported by victims in the manufacturing sector average $200,000 per incident, according to a 2023 Coveware report. The most affected sectors include healthcare, manufacturing, and education, with small to medium-sized enterprises (SMEs) being primary targets due to weaker security postures.
🛡️ Mitigation
Defensive measures include enabling multi-factor authentication (MFA) on all RDP and VPN interfaces, applying patches for known vulnerabilities (CVE-2021-40444, CVE-2022-30190), and deploying endpoint detection and response (EDR) tools with behavioral rules to block process hollowing. MITRE ATT&CK techniques used by Knight include T1486 (Data Encrypted for Impact), T1055.012 (Process Hollowing under T1055), and T1562.001 (Disable or Modify Tools under T1562).
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.