Lockbit perd la couronne du ransomware le plus redoutable, son successeur s\u2019appelle Rorschach<\/title>\n<meta name=\"description\" content=\"Des chercheurs en cybers\u00e9curit\u00e9 ont d\u00e9couvert un ransomware si puissant qu'ils lui d\u00e9cernent la palme du virus le plus foudroyant.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Lockbit perd la couronne du ransomware le plus redoutable, son successeur s\u2019appelle Rorschach\" \/>\n<meta property=\"og:description\" content=\"Des chercheurs en cybers\u00e9curit\u00e9 ont d\u00e9couvert un ransomware si puissant qu'ils lui d\u00e9cernent la palme du virus le plus foudroyant.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html\" \/>\n<meta property=\"og:site_name\" content=\"PhonAndroid\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/phonandroid\" \/>\n<meta property=\"article:published_time\" content=\"2023-04-07T13:50:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-04-07T15:22:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/wp-pa.phonandroid.com\/uploads\/2023\/04\/135261607_m_normal_none_1200_750.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"750\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Andry Nirina\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@phonandroid\" \/>\n<meta name=\"twitter:site\" content=\"@phonandroid\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Andry Nirina\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html\"},\"author\":{\"name\":\"Andry Nirina\",\"@id\":\"https:\/\/www.phonandroid.com\/#\/schema\/person\/67f2bc6bb88f474341af110793c64939\"},\"headline\":\"Lockbit perd la couronne du ransomware le plus redoutable, son successeur s\u2019appelle Rorschach\",\"datePublished\":\"2023-04-07T13:50:09+00:00\",\"dateModified\":\"2023-04-07T15:22:37+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html\"},\"wordCount\":433,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.phonandroid.com\/#organization\"},\"articleSection\":[\"S\u00e9curit\u00e9\"],\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html#respond\"]}],\"copyrightYear\":\"2023\",\"copyrightHolder\":{\"@id\":\"https:\/\/www.phonandroid.com\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html\",\"url\":\"https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html\",\"name\":\"Lockbit perd la couronne du ransomware le plus redoutable, son successeur s\u2019appelle Rorschach\",\"isPartOf\":{\"@id\":\"https:\/\/www.phonandroid.com\/#website\"},\"datePublished\":\"2023-04-07T13:50:09+00:00\",\"dateModified\":\"2023-04-07T15:22:37+00:00\",\"description\":\"Des chercheurs en cybers\u00e9curit\u00e9 ont d\u00e9couvert un ransomware si puissant qu'ils lui d\u00e9cernent la palme du virus le plus foudroyant.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/www.phonandroid.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Lockbit perd la couronne du ransomware le plus redoutable, son successeur s\u2019appelle Rorschach\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.phonandroid.com\/#website\",\"url\":\"https:\/\/www.phonandroid.com\/\",\"name\":\"PhonAndroid\",\"description\":\"PhonAndroid\",\"publisher\":{\"@id\":\"https:\/\/www.phonandroid.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.phonandroid.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.phonandroid.com\/#organization\",\"name\":\"PhonAndroid\",\"url\":\"https:\/\/www.phonandroid.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/www.phonandroid.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.phonandroid.com\/wp-content\/themes\/phonadroid-v3\/assets\/images\/lg-phonandroid-amp-4.png\",\"contentUrl\":\"https:\/\/img.phonandroid.com\/2023\/06\/dark.png\",\"width\":280,\"height\":60,\"caption\":\"PhonAndroid\"},\"image\":{\"@id\":\"https:\/\/www.phonandroid.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/phonandroid\",\"https:\/\/twitter.com\/phonandroid\",\"https:\/\/www.youtube.com\/user\/Phonandroidtv\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.phonandroid.com\/#\/schema\/person\/67f2bc6bb88f474341af110793c64939\",\"name\":\"Andry Nirina\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/www.phonandroid.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/c93ef547f92f7537abd94237f6aaa337?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/c93ef547f92f7537abd94237f6aaa337?s=96&d=mm&r=g\",\"caption\":\"Andry Nirina\"},\"description\":\"J\u2019aurais voulu \u00eatre un artiste, mais comme j\u2019\u00e9tais un peu paresseux, je suis devenu bassiste. Je voulais \u00e9galement \u00e9crire des romans de SF. Chanceux que je suis, me voil\u00e0 r\u00e9dacteur, car notre r\u00e9alit\u00e9 d\u00e9passe ma fiction. \u00ab Hit Play, Love \u00bb.\",\"url\":\"https:\/\/www.phonandroid.com\/author\/andry\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Lockbit perd la couronne du ransomware le plus redoutable, son successeur s\u2019appelle Rorschach","description":"Des chercheurs en cybers\u00e9curit\u00e9 ont d\u00e9couvert un ransomware si puissant qu'ils lui d\u00e9cernent la palme du virus le plus foudroyant.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html","og_locale":"fr_FR","og_type":"article","og_title":"Lockbit perd la couronne du ransomware le plus redoutable, son successeur s\u2019appelle Rorschach","og_description":"Des chercheurs en cybers\u00e9curit\u00e9 ont d\u00e9couvert un ransomware si puissant qu'ils lui d\u00e9cernent la palme du virus le plus foudroyant.","og_url":"https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html","og_site_name":"PhonAndroid","article_publisher":"https:\/\/www.facebook.com\/phonandroid","article_published_time":"2023-04-07T13:50:09+00:00","article_modified_time":"2023-04-07T15:22:37+00:00","og_image":[{"width":1200,"height":750,"url":"https:\/\/wp-pa.phonandroid.com\/uploads\/2023\/04\/135261607_m_normal_none_1200_750.jpg","type":"image\/jpeg"}],"author":"Andry Nirina","twitter_card":"summary_large_image","twitter_creator":"@phonandroid","twitter_site":"@phonandroid","twitter_misc":{"Written by":"Andry Nirina","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html#article","isPartOf":{"@id":"https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html"},"author":{"name":"Andry Nirina","@id":"https:\/\/www.phonandroid.com\/#\/schema\/person\/67f2bc6bb88f474341af110793c64939"},"headline":"Lockbit perd la couronne du ransomware le plus redoutable, son successeur s\u2019appelle Rorschach","datePublished":"2023-04-07T13:50:09+00:00","dateModified":"2023-04-07T15:22:37+00:00","mainEntityOfPage":{"@id":"https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html"},"wordCount":433,"commentCount":0,"publisher":{"@id":"https:\/\/www.phonandroid.com\/#organization"},"articleSection":["S\u00e9curit\u00e9"],"inLanguage":"fr-FR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html#respond"]}],"copyrightYear":"2023","copyrightHolder":{"@id":"https:\/\/www.phonandroid.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html","url":"https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html","name":"Lockbit perd la couronne du ransomware le plus redoutable, son successeur s\u2019appelle Rorschach","isPartOf":{"@id":"https:\/\/www.phonandroid.com\/#website"},"datePublished":"2023-04-07T13:50:09+00:00","dateModified":"2023-04-07T15:22:37+00:00","description":"Des chercheurs en cybers\u00e9curit\u00e9 ont d\u00e9couvert un ransomware si puissant qu'ils lui d\u00e9cernent la palme du virus le plus foudroyant.","breadcrumb":{"@id":"https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.phonandroid.com\/lockbit-perd-la-couronne-du-ransomware-le-plus-redoutable-son-successeur-sappelle-rohrschach.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.phonandroid.com\/"},{"@type":"ListItem","position":2,"name":"Lockbit perd la couronne du ransomware le plus redoutable, son successeur s\u2019appelle Rorschach"}]},{"@type":"WebSite","@id":"https:\/\/www.phonandroid.com\/#website","url":"https:\/\/www.phonandroid.com\/","name":"PhonAndroid","description":"PhonAndroid","publisher":{"@id":"https:\/\/www.phonandroid.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.phonandroid.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/www.phonandroid.com\/#organization","name":"PhonAndroid","url":"https:\/\/www.phonandroid.com\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.phonandroid.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.phonandroid.com\/wp-content\/themes\/phonadroid-v3\/assets\/images\/lg-phonandroid-amp-4.png","contentUrl":"https:\/\/img.phonandroid.com\/2023\/06\/dark.png","width":280,"height":60,"caption":"PhonAndroid"},"image":{"@id":"https:\/\/www.phonandroid.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/phonandroid","https:\/\/twitter.com\/phonandroid","https:\/\/www.youtube.com\/user\/Phonandroidtv"]},{"@type":"Person","@id":"https:\/\/www.phonandroid.com\/#\/schema\/person\/67f2bc6bb88f474341af110793c64939","name":"Andry Nirina","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.phonandroid.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/c93ef547f92f7537abd94237f6aaa337?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/c93ef547f92f7537abd94237f6aaa337?s=96&d=mm&r=g","caption":"Andry Nirina"},"description":"J\u2019aurais voulu \u00eatre un artiste, mais comme j\u2019\u00e9tais un peu paresseux, je suis devenu bassiste. Je voulais \u00e9galement \u00e9crire des romans de SF. Chanceux que je suis, me voil\u00e0 r\u00e9dacteur, car notre r\u00e9alit\u00e9 d\u00e9passe ma fiction. \u00ab Hit Play, Love \u00bb.","url":"https:\/\/www.phonandroid.com\/author\/andry"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/posts\/2520134","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/users\/130"}],"replies":[{"embeddable":true,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/comments?post=2520134"}],"version-history":[{"count":18,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/posts\/2520134\/revisions"}],"predecessor-version":[{"id":2520209,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/posts\/2520134\/revisions\/2520209"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/media\/2520139"}],"wp:attachment":[{"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/media?parent=2520134"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/categories?post=2520134"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/tags?post=2520134"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}

Cr\u00e9dit : 123rf<\/figcaption><\/figure>\n

En analysant le code de Rorschach, les experts ont d\u00e9couvert qu\u2019il s\u2019agit d\u2019un des ransomwares les plus rapides jamais observ\u00e9s<\/strong>, par sa vitesse de cryptage. Si son d\u00e9ploiement est automatis\u00e9. Ses concepteurs profitent de la fonctionnalit\u00e9 de side-loading de Cortex XDR, une application de s\u00e9curit\u00e9 professionnelle, pour t\u00e9l\u00e9charger une librairie de liens dynamiques (DLL) sur un ordinateur reli\u00e9 au r\u00e9seau de l\u2019entreprise cibl\u00e9e. Une fois celle-ci en place, elle d\u00e9compresse le code malveillant. Celui-ci s\u2019ex\u00e9cute ensuite \u00e0 travers un script dans le Bloc-Notes de Windows<\/a> et se r\u00e9plique sur les autres syst\u00e8mes connect\u00e9s au r\u00e9seau \u00e0 partir du Domain Controller. \u00c0 partir de l\u00e0, tous les fichiers et disques sont chiffr\u00e9s. Le pi\u00e8ge est en place.<\/p>\n

Rorschach se distingue des autres ransomwares sur plusieurs aspects. D\u2019une part, le ran\u00e7ongiciel n\u2019est pas sign\u00e9<\/strong>, une pratique pourtant r\u00e9pandue chez les cyberma\u00eetres chanteurs. Par ailleurs, \u00ab il est partiellement autonome, effectuant des t\u00e2ches qui sont g\u00e9n\u00e9ralement effectu\u00e9es manuellement lors du d\u00e9ploiement du ransomware \u00e0 l\u2019\u00e9chelle de l\u2019entreprise, comme la cr\u00e9ation d\u2019une strat\u00e9gie de groupe de domaine<\/strong> \u00bb.<\/p>\n