Tag: Ransomware Attacks

Hive0163 Uses AI-Assisted Slopoly Malware for Persistent Access in Ransomware Attacks
News

Hive0163 Uses AI-Assisted Slopoly Malware for Persistent Access in Ransomware Attacks

Cybersecurity experts have revealed information about a potential AI-generated virus called Slopoly that was used by Hive0163, a financially driven threat actor. In a report published with The Hacker News, IBM X-Force researcher Golo Mühl stated that while AI-generated malware like Slopoly is still quite unimpressive, it demonstrates how threat actors may weaponize AI to create new malware frameworks in a fraction of the time it used to take. Extortion via widespread data exfiltration and ransomware powers Hive0163's operations. NodeSnake, Interlock RAT, JunkFiction loader, and Interlock ransomware are just a few of the many harmful programs linked to the e-crime gang. The threat actor used Slopoly during the post-exploitation stage of one ransomware attack that the organization ...
Initial access hackers switch to Tsundere Bot for ransomware attacks
News

Initial access hackers switch to Tsundere Bot for ransomware attacks

In order to obtain network access that potentially result in ransomware attacks, a prolific initial access broker known as TA584 has been seen leveraging the Tsundere Bot in conjunction with the XWorm remote access trojan. According to Proofpoint experts who have been monitoring TA584's activities since 2020, the threat actor has recently greatly expanded its operations, launching a continuous assault chain that compromises static detection. Kaspersky initially reported Tsundere Bot last year, attributing it to a Russian-speaking operator with connections to the 123 Stealer virus. Proofpoint claims that the virus can be used for information gathering, data exfiltration, lateral movement, and the installation of additional payloads, even if its objectives and mode of infection were s...
Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading
News

Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading

In order to enable ransomware assaults, the threat actor identified as Storm-0249 is probably abandoning its function as an initial access broker in favor of a mix of more sophisticated strategies like domain spoofing, DLL side-loading, and fileless PowerShell execution. According to a report shared with The Hacker News by ReliaQuest, these techniques provide them the ability to evade defenses, enter networks, sustain persistence, and operate covertly, causing grave worries for security personnel. Microsoft has given the name Storm-0249 to an initial access broker that has sold access points to other cybercrime groups, such as ransomware and extortion actors like Storm-0501. In September 2024, the IT giant first brought attention to it. Then, earlier this year, Microsoft also dis...
Microsoft disrupts ransomware attacks targeting Teams users
News

Microsoft disrupts ransomware attacks targeting Teams users

Microsoft revoked more than 200 certificates used to sign fraudulent Teams installers in early October, halting a surge of Rhysida ransomware attacks. The threat group behind the assaults, Vanilla Tempest, distributed phony MSTeamsSetup.exe files that infected victims with the Oyster backdoor by using domains that imitate Microsoft Teams, such as teams-install[.]top, teams-download[.]buzz, teams-download[.]top, and teams-install[.]run. These assaults were a component of a late September malvertising effort that promoted phony Microsoft Teams installs that backdoored Windows devices with Oyster malware (also known as Broomstick and CleanUpLoader) through search engine advertising and SEO poisoning. The domains and advertisements directed users to websites that mimicked the Microso...
Hackers now use Velociraptor DFIR tool in ransomware attacks
News

Hackers now use Velociraptor DFIR tool in ransomware attacks

The Velociraptor digital forensics and incident response (DFIR) tool has begun to be used by threat actors in assaults that use the Babuk and LockBit ransomware. According to Cisco Talos analysts, there is a medium level of confidence that the campaigns are being carried out by a Chinese adversary known as Storm-2603. Mike Cohen developed the open-source DFIR tool Velociraptor. Rapid7 has acquired the project and offers its clients an improved version. On August 26, the cybersecurity firm Sophos revealed that hackers were abusing Velociraptor to get remote access. In particular, the threat actors used it to create a secure communication tunnel with the command and control (C2) infrastructure by downloading and running Visual Studio Code on compromised systems read more about Hack...
UK to ban public sector orgs from paying ransomware gangs
News

UK to ban public sector orgs from paying ransomware gangs

Following ransomware assaults, the government of the United Kingdom intends to prohibit vital infrastructure and public sector enterprises from paying ransoms. The publicly funded National Health Service (NHS), schools, and local councils are among the organizations that would be required to abide by the new proposed legislation. Recent high-profile ransomware attacks have brought attention to the serious operational, financial, and even life-threatening threats of ransomware, which is projected to cost the UK economy millions of pounds annually. According to the UK government, the prohibition would attack the business model that supports the operations of cybercriminals and make the essential services that the public depends on less appealing to ransomware gangs. We're committed...
US indicts leader of Qakbot botnet linked to ransomware attacks
News

US indicts leader of Qakbot botnet linked to ransomware attacks

Rustam Rafailevich Gallyamov, a Russian national, has been charged by the U.S. authorities with being the mastermind of the Qakbot botnet malware operation, which infected over 700,000 computers and made ransomware attacks possible. According to court filings, Gallyamov began working on Qakbot (also referred to as Pinkslipbot and Qbot) in 2008 and used it to infect thousands of computers. Over time, a group of coders came together around Qakbot, but according to the indictment, Gallyamov was also in charge of creating other viruses. For over ten years, Gallyamov employed Qakbot as a banking trojan that could record keystrokes and function as a worm, malware dropper, or backdoor. Beginning in 2019, a number of ransomware assaults by notorious gangs, including Conti, ProLock, Egreg...
Moldova arrests suspect linked to DoppelPaymer ransomware attacks
News

Moldova arrests suspect linked to DoppelPaymer ransomware attacks

A 45-year-old man connected to DoppelPaymer ransomware attacks against Dutch organizations in 2021 has been arrested by Moldovan authorities. On May 6, the suspect's house and vehicle were searched by police, and they found an electronic wallet, €84,800, two laptops, a tablet, a cell phone, six bank cards, and several data storage devices. Prosecutors in Moldova have started legal proceedings to extradite the suspect to the Netherlands, but he is still being held. Law enforcement in the Kingdom of the Netherlands, Moldovan prosecutors, and the nation's Center for Combating Cybercrimes collaborated to make the arrest. The suspect, referred to as a "foreign citizen," allegedly planned a ransomware attack against the Dutch Research Council (NWO) in 2021 that caused damages of abo...
Crypt Ghouls Targets Russian Firms with LockBit 3.0 and Babuk Ransomware Attacks
News

Crypt Ghouls Targets Russian Firms with LockBit 3.0 and Babuk Ransomware Attacks

Crypt Ghouls, a new threat actor, has been connected to a series of ransomware-based cyberattacks against Russian government and commercial institutions, aimed at both financial gain and business disruption. Utilities including Mimikatz, XenAllPasswordPro, PingCastle, Localtonet, resocks, AnyDesk, PsExec, and others are part of the toolbox that the organization under evaluation possesses, according to Kaspersky. The organization employed the popular ransomware LockBit 3.0 and Babuk as the last payload. Governmental organizations as well as Russian mining, energy, banking, and retail businesses have been the targets of these malicious attacks. Only two cases, according to the Russian cybersecurity vendor, could it identify the initial intrusion vector read more about Crypt Ghouls ...
JPCERT shares Windows Event Log tips to detect ransomware attacks
News

JPCERT shares Windows Event Log tips to detect ransomware attacks

With the goal of prompt identification of current attacks before they spread too far into a network, Japan's Computer Emergency Response Center (JPCERT/CC) has offered recommendations on how to identify the attacks of various ransomware gangs based on entries in Windows Event Logs. The method can be useful in reacting to ransomware assaults, according to JPCERT/CC, and locating the attack vector among multiple options is essential for prompt mitigation. The four categories of Windows Event Logs covered by the JPCERT/CC investigation approach are Application, Security, System, and Setup logs. Ransomware assaults frequently leave behind traces in these logs that may provide information about the attackers read more about JPCERT shares Windows Event Log tips to detect ransomware att...