FortiGuard Labs is aware of a report that a new ransomware “Somnia” was observed in attacks against Ukraine. Somnia ransomware was deployed as a final payload in multiple staged attacks involving a fake IP scanner, Vidar stealer, and Cobalt Strike. The attack was attributed to FRwL (aka Z-Team, UAC-0118).Why is this Significant?This is significant because Somnia is the latest ransomware that reportedly targets Ukrainian interests. Other ransomware variants that previously targeted Ukraine include are but not restricted to Prestige, AcidRain, DoubleZero, CaddyWiper, IssacWiper, HermeticWiper, and WhisperGate.How was Somnia Ransomware Distributed?Somnia ransomware was reportedly distributed in an attack chain that goes through multiple stages. First, the attacker creates a fake Advanced IP Scanner Web site in an attempt to trick Ukrainian organizations into downloading and installing Vidar stealer disguised as “Advanced IP Scanner” installer. Once a victim’s machine is compromised by Vidar stealer, it tries to steal Telegram’s session data, which is then used to compromise VPN connections giving the attacker access to the victim’s network. Cobalt Strike was seen deployed to the compromised network. Reportedly Rсlone, Anydesk, and Ngrok were observed for data exfiltration. Finally, Somnia ransomware deployed to encrypt files on the compromised machines.What is Somnia Ransomware?Somnia is a ransomware that encrypts files on compromised machines. According to CERT-UA, there are two different types of Somnia ransomware; the one uses 3DES algorithm for file encryption and the other uses the AES algorithm. The affected files have a “.somnia” file extension.Somnia ransomware targets and encrypts files with the following extensions:File extensions targeted by Somnia ransomware (screenshot taken from a CERT-UA report)Since Somnia ransomware does not drop any ransom note and attacker’s contact information, victims will likely will not be able to decrypt the encrypted files.What is the Status of Protection?While Somnia ransomware samples are not publicly available, FortiGuard Labs detect the fake Advanced IP Scanner used as initial infection vector with the following AV signature:• W32/PossibleThreatReported network IOCs are blocked by Webfiltering.
More Stories
mod_auth_openidc-2.4.16.11-1.fc41
FEDORA-2025-7d661758bd Packages in this update: mod_auth_openidc-2.4.16.11-1.fc41 Update description: REbase mod_auth_openidc-2.4.16.11 resolves CVE-2025-31492 - mod_auth_openidc allows OIDCProviderAuthRequestMethod POSTs to leak protected...
mod_auth_openidc-2.4.16.11-1.fc40
FEDORA-2025-80600b51c5 Packages in this update: mod_auth_openidc-2.4.16.11-1.fc40 Update description: REbase mod_auth_openidc-2.4.16.11 resolves CVE-2025-31492 - mod_auth_openidc allows OIDCProviderAuthRequestMethod POSTs to leak protected...
USN-7423-1: GNU binutils vulnerabilities
It was discovered that GNU binutils incorrectly handled certain inputs. An attacker could possibly use this issue to cause a...
USN-7406-6: Linux kernel (NVIDIA Tegra IGX) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This...
USN-7402-4: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This...
lemonldap-ng-2.21.0-1.el9
FEDORA-EPEL-2025-0d5707b1a1 Packages in this update: lemonldap-ng-2.21.0-1.el9 Update description: See https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-21-0-is-out/ Read More