CosmicBeetle — Ransomware Profile

CosmicBeetle is the designation ESET Research gave to the operator behind the Spacecolon toolset, a custom collection of Delphi utilities the vendor first analysed publicly in 2023 and whose origins it traced back to at least May 2020. The actor originally deployed variants of the pre-existing Scarab ransomware, then in 2023 switched to ScRansom, a home-grown family ESET attributes to the same operator. Initial access leans on brute-force methods alongside a stable of well-aged vulnerabilities, including EternalBlue (CVE-2017-0144), Zerologon (CVE-2020-1472), the noPac Active Directory privilege-escalation pair (CVE-2021-42278 and CVE-2021-42287), a Veeam Backup and Replication flaw (CVE-2023-27532), and the FortiOS SSL-VPN bug CVE-2022-42475. Victims are overwhelmingly small and mid-sized businesses spread across many verticals, concentrated in Europe and Asia. The crew has repeatedly traded on stronger brands' reputations: it worked from the leaked LockBit builder and dressed its ransom notes and leak site in the LockBit identity as early as November 2023, and in September 2024 ESET assessed with medium confidence that it had also enrolled as a RansomHub affiliate. Its tooling is unpolished by the vendor's own account: ScRansom's encryption is error-prone enough that victims can permanently lose files even when the decryptor itself works. The most recent detailed public analysis of the group remains ESET's September 2024 report.

Also tracked as

Spacecolon

Vendor research

Read the full analysis on IntelFusions