Skip to main content

Posts

Showing posts with the label Ransomeware Attacks.

Maze Ransomware Behind Pensacola Attack, Data Breach Looms

Maze exfiltrates data as well as locks down systems. Officials said they don’t know yet whether any residents’ personal information has been breached.  The Maze ransomware is likely the culprit behind the recently reported cyberattack on Pensacola, Fla. that occurred earlier this week, which downed systems citywide. In an email  sent to  county commissioners, IT administrators said that the Florida Department of Law Enforcement said that the Pensacola attack was indeed ransomware, and Maze operators quickly  took responsibility  for the incident, saying that they are demanding $1 million in ransom. As of Wednesday, Pensacola’s systems were slowly coming back online, as IT staff cleared the network of malware, officials told the  Pensacola News Journal  (online payments for Pensacola Energy and city sanitation customers remained down). It’s unclear whether the city is paying the ransom, but officials did say they don’t know yet ...

Tech and Health Companies Targeted by New Zeppelin Ransomware

A new variant of Vega ransomware family, dubbed  Zeppelin , has recently been spotted in the wild targeting technology and healthcare companies across Europe, the United States, and Canada. However, if you reside in Russia or some other ex-USSR countries like Ukraine, Belorussia, and Kazakhstan, breathe a sigh of relief, as the ransomware terminates its operations if found itself on machines located in these regions. It's notable and interesting because all previous variants of the Vega family, also known as VegaLocker, were primarily targeting Russian speaking users, which indicates Zeppelin is not the work of the same hacking group behind the previous attacks. Since Vega ransomware and its previous variants were offered as a service on underground forums, researchers at BlackBerry Cylance believes either Zeppelin "ended up in the hands of different threat actors" or "redeveloped from bought/stolen/leaked sources." According to a  report  BlackBerry Cylan...

Snatch Ransomware Reboots Windows in Safe Mode to Bypass Antivirus

Cybersecurity researchers have spotted a new variant of the Snatch ransomware that first reboots infected Windows computers into Safe Mode and only then encrypts victims' files to avoid antivirus detection. Unlike traditional malware, the new Snatch ransomware chooses to run in Safe Mode because in the diagnostic mode Windows operating system starts with a minimal set of drivers and services without loading most of the third-party startup programs, including antivirus software. Snatch has been active since at least the summer of 2018, but SophosLabs researchers spotted the Safe Mode enhancement to this ransomware strain only in recent cyber attacks against various entities they investigated. "SophosLabs researchers have been investigating an ongoing series of ransomware attacks in which the ransomware executable forces the Windows machine to reboot into Safe Mode before beginning the encryption process," the  researchers say . "The ransomware, which calls itsel...

RIPlace – A latest Evasion Technique Let Ransomware to Encrypt Files Undetected

RIPlace a new evasion technique that allows threat actors to encrypt files on Windows-based computers without being detected by anti-ransomware products. Nyotron’s Security researchers discovered a new technique that leverages Microsoft Windows file system rename operations to stay undetected from security products, RIPlace Evasion Technique Attackers can use this RIPlace method to alter any files on the computers running with Windows XP or the new version of operating systems. According to Nyotron’s  Research , all antivirus products including Endpoint Detection and Response tested so far were completely blind to file operations using this technique, including encryption. Whenever a renamed file requests operation being called the  IRP_MJ_SET_INFORMATION  it requests to set metadata about a file with  FileInformationClass  set to  FileRenameInformation  and then filter gets a callback, so that it could filter the request. Researchers...

Mass Malware Attack – Ransomware, Screenlockers, RATs, Attack & Gain Backdoor Access

Researchers discovered a mass malware distribution campaign that utilizing the well-known political figures in the U.S. including President Donald Trump, former presidential candidate Hillary Clinton with a series of ransomware, screen lockers, RATs and other malicious applications. A variety of malicious applications uncovered with this campaign, and it was developed to infect the victims with ransomware, implant a backdoor in organization networks with political motivation. Researchers believe that the malware authors are motivated by their political beliefs and turned into malware distribution in different forms. Malware Infection Process Initially, attackers deliver the malware via malspam email campaigns with fake body content related to banking fraud alerts, and it comes from the director of Global Risk for credit card company Visa. The malspam emails come with a malicious attachment that contains RTF files, once it opened, RTF documents retrieve a malicious PE32 e...

Apple iTunes and iCloud for Windows 0-Day Exploited in Ransomware Attacks

Watch out Windows users! The cybercriminal group behind BitPaymer and iEncrypt ransomware attacks has been found exploiting a zero-day vulnerability affecting a little-known component that comes bundled with Apple's iTunes and iCloud software for Windows to evade antivirus detection. The vulnerable component in question is the  Bonjour  updater, a zero-configuration implementation of network communication protocol that works silently in the background and automates various low-level network tasks, including automatically download the future updates for Apple software. To be noted, since the Bonjour updater gets installed as a separate program on the system, uninstalling iTunes and iCloud doesn't remove Bonjour, which is why it eventually left installed on many Windows computers — un-updated and silently running in the background. Cybersecurity researchers from Morphisec Labs discovered the exploitation of the Bonjour zero-day vulnerability in August when the attackers ta...