FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
kcheng
Staff
Staff
Article Id 336910
Description This article describes the preventive measures that can be applied to FortiGate to block and stop Brain Cipher ransomware from infecting internal hosts.
Scope FortiGate.
Solution

Brain Cipher ransomware is a ransomware variant from the LockBit hacker group. Below are the recommendations to ensure that Brain Cipher is not impacting the internal systems:

 

  1. Ensure the operating system is updated with the latest security patch.
  2. Ensure the application in use is updated with the latest security patch.
  3. Ensure that the firewall policy configured to process traffic has been applied with the appropriate security profile such as AntiVirus and Webfilter service that blocks all the known indicators of compromise (IoCs).
  4. Endpoint AntiVirus such as FortiClient and FortiEDR protects the end host when it is not connected to the network of the FortiGate.

 

The following AntiVirus signature developed by FortiGuard lab would translate to blocking of Brain Cipher ransomware attempt:

W32/BlackMatter.K!tr.ransom

W32/Filecoder_BlackMatter.E!tr.ransom

W32/Ransom_Win32_LOCKBIT.YXCGT

W32/BlackMatter.K!tr.ransom

 

Additional information can be found in the following Threat Signal Report:

Brain Cipher Ransomware Attack