Tag: BlackCat Ransomware

Scattered Spider Adopts RansomHub and Qilin Ransomware for Cyber Attacks
News

Scattered Spider Adopts RansomHub and Qilin Ransomware for Cyber Attacks

Microsoft has disclosed that the notorious cybercrime collective known as Scattered Spider has included ransomware strains like Qilin and RansomHub in its repertoire. A threat actor noted for using complex social engineering techniques to compromise targets and create persistence for later exploitation and data theft is called the "Scattered Spider." Additionally, it has a history of using the BlackCat ransomware to attack VMware ESXi servers. It overlaps with activity clusters that are monitored under the names 0ktapus, Octo Tempest, and UNC3944 by the larger cybersecurity community. An important gang member was reportedly detained in Spain last month read more about Scattered Spider Adopts RansomHub and Qilin Ransomware for Cyber Attacks. Get up to date on the latest cybersecur...
FBI Takes Down BlackCat Ransomware, Releases Free Decryption Tool
News

FBI Takes Down BlackCat Ransomware, Releases Free Decryption Tool

In addition to formally announcing the stop of the BlackCat ransomware campaign, the U.S. Justice Department (DoJ) has made available a decryption tool that over 500 impacted victims can utilize to unlock files that the malware has locked. In a case of hacking the hackers, court documents reveal that the U.S. Federal Bureau of Investigation (FBI) sought the assistance of a confidential human source (CHS) to function as an associate for the BlackCat group and obtain access to a web panel used for managing the gang's victims. A number of law enforcement agencies from the United States, Germany, Denmark, Australia, the United Kingdom, Spain, Switzerland, and Austria collaborated and assisted read more FBI Takes Down BlackCat Ransomware, Releases Free Decryption Tool. Get up to date ...
Healthcare giant Henry Schein hit twice by BlackCat ransomware
News

Healthcare giant Henry Schein hit twice by BlackCat ransomware

The BlackCat/ALPHV ransomware group, which also gained access to Henry Schein's network in October, has launched a second cyberattack this month, according to the American healthcare company. With operations and affiliates in 32 countries, Henry Schein is a Fortune 500 provider of healthcare products and services, with over $12 billion in revenue reported in 2022. It first made public on October 15 that, following a cyberattack the day before, it had to take some systems offline in order to contain the threat. On November 22, more than a month later, the business announced that some of its apps and the e-commerce platform had once more been taken offline due to an additional attack read more Healthcare giant Henry Schein hit twice by BlackCat ransomware. Get up to date on the lat...
Improved BlackCat Ransomware Strikes with Lightning Speed and Stealthy Tactics
News

Improved BlackCat Ransomware Strikes with Lightning Speed and Stealthy Tactics

The threat actors who created the BlackCat ransomware have created an upgraded version that prioritises speed and stealth in an effort to get past security barriers and accomplish their objectives. According to a recent investigation by IBM Security X-Force, the latest version, known as Sphynx and released in February 2023, has a "number of updated capabilities that strengthen the group's efforts to evade detection." Vx-underground initially brought attention to the "product" update in April 2023. Last month, Trend Micro described a Linux variant of Sphynx that is read more Improved BlackCat Ransomware Strikes with Lightning Speed and Stealthy Tactics. Stay one step ahead of cyber threats with ReconBee.com. Explore our comprehensive coverage of recent cyber attacks, cybersecurity...