Ransomware and Recent Variants

Discussion in 'malware problems & news' started by ronjor, Mar 31, 2016.

  1. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,099
    Location:
    UK
  2. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    Blackbyte ransomware hits San Francisco 49ers ahead of Super Bowl

    "The NFL's San Francisco 49ers team is recovering from a cyberattack by the BlackByte ransomware gang who claims to have stolen data from the American football organization.

    While the 49ers did not confirm whether hackers successfully deployed the ransomware, they said they are still in the process of recovering systems, indicating that devices were likely encrypted..."

    https://www.bleepingcomputer.com/ne...sco-49ers-hit-by-blackbyte-ransomware-attack/
     
  3. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    The Week in Ransomware - February 18th 2022 - Mergers & Acquisitions
    https://www.bleepingcomputer.com/ne...-february-18th-2022-mergers-and-acquisitions/
     
  4. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
  5. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Master Key for Hive Ransomware Retrieved Using a Flaw in its Encryption Algorithm
    https://thehackernews.com/2022/02/master-key-for-hive-ransomware.html
     
  6. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    "Two ransomware gangs hacked the same target at the same time: Here's what happened next...

    A healthcare provider fell victim to two simultaneous cyber attacks by two separate ransomware gangs using different techniques to exploit unpatched security vulnerabilities in Microsoft Exchange Server at the same time, which even led to the second ransomware attack encrypting the ransom note left by the first..."

    https://www.zdnet.com/article/two-r...et-at-the-same-time-heres-what-happened-next/
     
  7. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
  8. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
  9. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
  10. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
  11. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,067
    Location:
    Texas
    FBI and FinCEN Release Advisory on AvosLocker Ransomware
    Original release date: March 22, 2022

     
  12. pernu

    pernu Registered Member

    Joined:
    May 10, 2021
    Posts:
    82
    Location:
    Norway
  13. Osaban

    Osaban Registered Member

    Joined:
    Apr 11, 2005
    Posts:
    5,617
    Location:
    Milan and Seoul
    "Instead of attackers using the threat of leaking a victim's files to pressure them into paying, LokiLock's customers threaten to overwrite a victim's Windows Master Boot Record (MBR), which wipes all files and renders the machine unusable."
    I like to think that restoring an image would still work, wouldn't it?
     
  14. pernu

    pernu Registered Member

    Joined:
    May 10, 2021
    Posts:
    82
    Location:
    Norway
    I really can't say, but it might, and I hope ;)
     
  15. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
  16. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,438
    Location:
    Slovakia
    I was wondering, what file formats ransomware does not encrypt? Like .sys, .log or? Lets say that I backup some files and put the mentioned extensions instead, it would not touch it?
     
  17. 1PW

    1PW Registered Member

    Joined:
    Apr 2, 2010
    Posts:
    1,937
    Location:
    North of the 38th parallel.
    Hello @TairikuOkami

    Although that could be an interesting technique to try, it seems that not exactly file formats, but some languages may have some immunity.

    Perhaps you too may have recalled reading that some ransomware groups, (DarkSide et al) with close ties to the Russian Federation, will not attack some (Windows®) victim systems detected to use the Russian & Ukrainian languages. One trouble being that several dozens of languages are used between the Russian Federation and Ukraine.

    Attribution: https://krebsonsecurity.com/2021/05/try-this-one-weird-trick-russian-hackers-hate/

    HTH
     
    Last edited: Mar 24, 2022
  18. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    97,985
    Location:
    U.S.A.
     
  19. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,099
    Location:
    UK
  20. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    New ransomware demands victims to donate to poor
    https://www.independent.co.uk/tech/ransomware-goodwill-cyber-security-cloudsec-b2085089.html
     
  21. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Ransomware group ups pressure on victims with new extortion tactic
    https://blog.emsisoft.com/en/41331/ransomware-group-pressure-victim-with-new-tactic/
     
  22. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,099
    Location:
    UK
  23. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,099
    Location:
    UK
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.