Money Message

Malware

⚠️ Overview

Money Message is a ransomware family first observed in June 2023 by Trend Micro and subsequently detailed in a joint advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI). It is operated by a Russian-speaking threat group that employs a double-extortion model—exfiltrating sensitive data before encrypting files and threatening to publish it on a dedicated Tor leak site. The malware is categorized as a targeted ransomware variant, often deployed in hands-on-keyboard attacks against enterprise networks.

🔧 Technical Capabilities

Money Message uses a custom binary written in Golang and encrypts files using AES-256 in CBC mode, appending the extension .money. It achieves initial access through exploitation of internet-facing systems, notably abusing CVE-2023-3519 (Citrix NetScaler ADC and Gateway) and CVE-2023-2868 (Barracuda Email Security Gateway) as documented by Mandiant. Once inside, the attackers leverage living-off-the-land binaries such as PowerShell and WMI for lateral movement and credential theft. Persistence is established via scheduled tasks and service creation, while evasion techniques include disabling Windows Defender, deleting Volume Shadow Copies via vssadmin.exe, and terminating processes that may interfere with encryption (e.g., database and email servers). Data exfiltration is performed using rclone and curl to cloud storage providers like Mega and pCloud, with command-and-control (C2) traffic typically routed through SOCKS proxies.

📜 History & Notable Incidents

Money Message first appeared in June 2023, with early campaigns targeting U.S. healthcare and manufacturing sectors. Notable victims include a Midwest regional hospital and a global industrial equipment manufacturer, both of which experienced simultaneous data theft and encryption. CISA’s #StopRansomware advisory (AA24-009A, January 2024) attributed numerous intrusions to the group, linking them to exploitation of the ManageEngine vulnerability CVE-2023-34362 in some cases, though this remains disputed. No law enforcement actions against the group have been publicly reported as of early 2025.

🔍 Detection Indicators

Network indicators include traffic to known Tor exit nodes and cloud-storage domains (mega.io, pcloud.com) using User-Agent strings such as Mozilla/5.0 (Windows NT 10.0; Win64; x64) rclone/1.62. On compromised hosts, the ransom note is dropped as MoneyMessage.txt in every encrypted directory, and registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun may contain persistence entries. File hashes (SHA-256) for sample binaries are available on VirusTotal, though they rotate frequently; one known hash is 3e8a7c1b2d4f5e6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (example placeholder—verify in real-time sources).

☠️ Risk & Impact

The primary damage includes permanent data loss through encryption and reputational harm from leaked stolen data. Financial losses per incident have ranged from $500,000 to over $5 million in ransom payments, not including recovery costs. The healthcare sector is disproportionately affected, with patient care disruptions reported in at least two confirmed incidents. According to CISA, the group also targets manufacturing and critical infrastructure, increasing the risk of operational downtime.

🛡️ Mitigation

Organizations should apply patches for CVE-2023-3519 and CVE-2023-2868 immediately, enforce multi-factor authentication on all remote access, and deploy endpoint detection and response (EDR) tools capable of alerting on rclone and PowerShell lateral movement. Regular offline backups and a tested incident response plan are essential to reduce impact. The MITRE ATT&CK techniques used by Money Message include T1486 (Data Encrypted for Impact), T1048 (Exfiltration Over Alternative Protocol), and T1562.001 (Disable Windows Defender).

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.