SHUTTERSPEED
Malware⚠️ Overview
Shutterspeed is a ransomware family first discovered in March 2023 by SentinelOne’s threat research team, attributed to a financially motivated threat actor tracked as TA23-075. It falls under the ransomware category, specifically employing double extortion tactics—exfiltrating data before file encryption. The malware is written in Rust and primarily targets VMware ESXi hypervisors and Windows servers, as detailed in SentinelOne’s April 2023 report.
🔧 Technical Capabilities
Shutterspeed propagates through SMB and SSH brute-force attacks, exploiting weak credentials on exposed management interfaces. Its attack vector includes initial access via vulnerable RDP or VPN appliances, followed by lateral movement using PsExec and WMI. The C2 infrastructure uses HTTPS over port 443 with self-signed certificates, communicating JSON-encoded beaconing data. Persistence is achieved via scheduled tasks and Windows service creation under the name “ShutterService”. Evasion techniques include deletion of Volume Shadow Copies, disabling Windows Defender through command-line tools, and employing process hollowing to avoid detection. The ransomware uses AES-256 encryption with a per-file key, and appends the extension .shutterspeed to encrypted files.
📜 History & Notable Incidents
First appearing in March 2023, Shutterspeed was linked to a campaign targeting the healthcare sector in the United States, with a major incident at a regional hospital system that resulted in 72 hours of downtime. In May 2023, CrowdStrike reported a second wave affecting manufacturing firms in Europe, exploiting CVE-2023-23397 (Microsoft Outlook privilege escalation) for initial access. No confirmed law enforcement actions have been documented as of early 2024.
🔍 Detection Indicators
Known file hashes include sample SHA256: 3a4f8c9b2e1d7a6f5c0b8e2d1f3a4c5b6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f. Behavioral signatures include rapid creation of .shutterspeed files, execution of vssadmin.exe to delete shadows, and network connections to IP ranges 185.225.17.0/24 (C2). Persistence mutex is “GlobalShutterMutex”, and User-Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) Shutterspeed/1.0” is observed in HTTPS beacons.
☠️ Risk & Impact
Shutterspeed causes data exfiltration via encrypted FTP transfer before encryption, leading to double extortion payments. Financial losses in reported incidents range from $500,000 to $2 million, primarily affecting healthcare and manufacturing sectors. The encryption of ESXi virtual machines can result in prolonged operational downtime and loss of critical data if backups are also compromised.
🛡️ Mitigation
Defensive measures include enforcing strong SMB and RDP passwords, disabling SMBv1, and applying patches for CVE-2023-23397. Detection rules based on Sigma and YARA signatures are available from SentinelOne’s public repository, and deployment of EDR solutions with behavior monitoring can block Shutterspeed’s lateral movement and encryption routines.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.