{"id":3588,"date":"2021-08-20T12:43:14","date_gmt":"2021-08-20T17:43:14","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3588"},"modified":"2021-08-20T12:43:15","modified_gmt":"2021-08-20T17:43:15","slug":"deepbluemagic-is-a-fairly-complex-new-ransomware","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/deepbluemagic-is-a-fairly-complex-new-ransomware\/","title":{"rendered":"DeepBlueMagic is a fairly complex new ransomware"},"content":{"rendered":"\n<p>Researchers at Heimdal Security discovered the new ransomware variant on Wednesday, August 11, 2021, which is being used by a group of threats calling themselves DeepBlueMagic. This ransomware works in a completely different way than any other ransomware found in the past.<\/p>\n\n\n\n<p>This ransomware uses a third-party encryption tool called BestCrypt Volume Encryption from Jetico. Instead of first encrypting the files on the victim&#8217;s system, the ransomware first targeted different drives on the server, with the exception of the system drive located on the &#8220;C: \\&#8221; Partition). &#8221; The BestCrypt volume encryption was present on the accessible disk, C, along with a file called &#8220;rescue.rsc&#8221;, a rescue file commonly used by these classes of threats to recover the partition in case of damage. But unlike the legitimate uses of the software, the ransom file itself was also encrypted by the product, using the same mechanism, and requiring a password to open it.<\/p>\n\n\n\n<p>Unfortunately DeepBlueMagic ransomware also removes Volume Shadow Copies to ensure that file restoration is not possible. Since it was detected on a Windows server operating system, the ransomware also tried to activate Bitlocker on all endpoints of that active directory, so the best we can do is save sample backup copies on other external devices.<\/p>\n\n\n\n<p>Fortunately, it seems that it is possible to partially bypass this ransomware or at least in the case of the compromised server that Heimdal analyzed. According to Heimdal, the affected server was restored because the ransomware only started the encryption process, without actually following it. Fundamentally, the DeepBlueMagic ransomware only encrypted the headers of the affected partition, to break the function of Windows Shadow Volumes, \u201dthe researchers shared.<\/p>\n\n\n\n<p>Related reads:<br><a href=\"https:\/\/truxgoservers.com\/blog\/acute-a-dangerous-high-risk-ransomware\/\">Acute dangerous high-risk Ransomware<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/nephilim-ransomware-that-targets-wealthy-companies\/\">Nephilim Ransomware targets wealthy companies<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/hades-ransomware-that-targetting-businesses\/\">Hades ransomware targetting businesses<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers at Heimdal Security discovered the new ransomware variant on Wednesday, August 11, 2021, which is being used by a group of threats calling themselves DeepBlueMagic. This ransomware works in a completely different way than any other ransomware found in the past. This ransomware uses a third-party encryption tool called BestCrypt Volume Encryption from Jetico. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3589,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10,16],"tags":[36,105],"class_list":["post-3588","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-ransomware","tag-cybersecurity","tag-ransomware"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>DeepBlueMagic is a fairly complex new ransomware - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"As we well know, ransomwares are the favorite tools of cybercriminals for obvious reasons and today we will see a new called DeepBlueMagic...\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/deepbluemagic-is-a-fairly-complex-new-ransomware\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DeepBlueMagic is a fairly complex new ransomware - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"As we well know, ransomwares are the favorite tools of cybercriminals for obvious reasons and today we will see a new called DeepBlueMagic...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/deepbluemagic-is-a-fairly-complex-new-ransomware\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-08-20T17:43:14+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-08-20T17:43:15+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/DeepBlue.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1186\" \/>\n\t<meta property=\"og:image:height\" content=\"753\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/deepbluemagic-is-a-fairly-complex-new-ransomware\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/deepbluemagic-is-a-fairly-complex-new-ransomware\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"DeepBlueMagic is a fairly complex new ransomware\",\"datePublished\":\"2021-08-20T17:43:14+00:00\",\"dateModified\":\"2021-08-20T17:43:15+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/deepbluemagic-is-a-fairly-complex-new-ransomware\\\/\"},\"wordCount\":295,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/deepbluemagic-is-a-fairly-complex-new-ransomware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/DeepBlue.jpg\",\"keywords\":[\"Cybersecurity\",\"Ransomware\"],\"articleSection\":[\"Cybersecurity\",\"Ransomware\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/deepbluemagic-is-a-fairly-complex-new-ransomware\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/deepbluemagic-is-a-fairly-complex-new-ransomware\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/deepbluemagic-is-a-fairly-complex-new-ransomware\\\/\",\"name\":\"DeepBlueMagic is a fairly complex new ransomware - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/deepbluemagic-is-a-fairly-complex-new-ransomware\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/deepbluemagic-is-a-fairly-complex-new-ransomware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/DeepBlue.jpg\",\"datePublished\":\"2021-08-20T17:43:14+00:00\",\"dateModified\":\"2021-08-20T17:43:15+00:00\",\"description\":\"As we well know, ransomwares are the favorite tools of cybercriminals for obvious reasons and today we will see a new called DeepBlueMagic...\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/deepbluemagic-is-a-fairly-complex-new-ransomware\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/deepbluemagic-is-a-fairly-complex-new-ransomware\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/deepbluemagic-is-a-fairly-complex-new-ransomware\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/DeepBlue.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/DeepBlue.jpg\",\"width\":1186,\"height\":753},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/deepbluemagic-is-a-fairly-complex-new-ransomware\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"DeepBlueMagic is a fairly complex new ransomware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DeepBlueMagic is a fairly complex new ransomware - Truxgo Server Blog","description":"As we well know, ransomwares are the favorite tools of cybercriminals for obvious reasons and today we will see a new called DeepBlueMagic...","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/deepbluemagic-is-a-fairly-complex-new-ransomware\/","og_locale":"es_MX","og_type":"article","og_title":"DeepBlueMagic is a fairly complex new ransomware - Truxgo Server Blog","og_description":"As we well know, ransomwares are the favorite tools of cybercriminals for obvious reasons and today we will see a new called DeepBlueMagic...","og_url":"https:\/\/truxgoservers.com\/blog\/deepbluemagic-is-a-fairly-complex-new-ransomware\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-08-20T17:43:14+00:00","article_modified_time":"2021-08-20T17:43:15+00:00","og_image":[{"width":1186,"height":753,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/DeepBlue.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/deepbluemagic-is-a-fairly-complex-new-ransomware\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/deepbluemagic-is-a-fairly-complex-new-ransomware\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"DeepBlueMagic is a fairly complex new ransomware","datePublished":"2021-08-20T17:43:14+00:00","dateModified":"2021-08-20T17:43:15+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/deepbluemagic-is-a-fairly-complex-new-ransomware\/"},"wordCount":295,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/deepbluemagic-is-a-fairly-complex-new-ransomware\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/DeepBlue.jpg","keywords":["Cybersecurity","Ransomware"],"articleSection":["Cybersecurity","Ransomware"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/deepbluemagic-is-a-fairly-complex-new-ransomware\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/deepbluemagic-is-a-fairly-complex-new-ransomware\/","url":"https:\/\/truxgoservers.com\/blog\/deepbluemagic-is-a-fairly-complex-new-ransomware\/","name":"DeepBlueMagic is a fairly complex new ransomware - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/deepbluemagic-is-a-fairly-complex-new-ransomware\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/deepbluemagic-is-a-fairly-complex-new-ransomware\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/DeepBlue.jpg","datePublished":"2021-08-20T17:43:14+00:00","dateModified":"2021-08-20T17:43:15+00:00","description":"As we well know, ransomwares are the favorite tools of cybercriminals for obvious reasons and today we will see a new called DeepBlueMagic...","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/deepbluemagic-is-a-fairly-complex-new-ransomware\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/deepbluemagic-is-a-fairly-complex-new-ransomware\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/deepbluemagic-is-a-fairly-complex-new-ransomware\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/DeepBlue.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/DeepBlue.jpg","width":1186,"height":753},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/deepbluemagic-is-a-fairly-complex-new-ransomware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"DeepBlueMagic is a fairly complex new ransomware"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3588","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3588"}],"version-history":[{"count":3,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3588\/revisions"}],"predecessor-version":[{"id":3885,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3588\/revisions\/3885"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3589"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3588"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3588"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3588"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}