Tag: ransomware campaign

RedCurl Shifts from Espionage to Ransomware with First-Ever QWCrypt Deployment
News

RedCurl Shifts from Espionage to Ransomware with First-Ever QWCrypt Deployment

For the first time, a ransomware campaign has been connected to the Russian-speaking hacker collective RedCurl, which represents a shift in the threat actor's tactics. The action, which was noticed by the Romanian cybersecurity firm Bitdefender, entails the use of a ransomware strain called QWCrypt that has never been seen before. RedCurl, also known as Earth Kapre and Red Wolf, has a track record of planning corporate espionage attacks against organizations in the US, UK, Canada, Germany, Norway, Russia, Slovenia, and Ukraine. Since at least November 2018, it has been known to be active. In 2020, Group-IB revealed attack chains that used spear-phishing emails with lures related to human resources (HR) to initiate the malware distribution process. Huntress described the threat ac...
Botnet sent millions of emails in LockBit Black ransomware campaign
News

Botnet sent millions of emails in LockBit Black ransomware campaign

The Phorpiex botnet has been used to send millions of phishing emails in an effort to spread the LockBit Black ransomware since April. According to a warning issued on Friday by New Jersey's Cybersecurity and Communications Integration Cell (NJCCIC), the attackers employ ZIP attachments that contain an executable that, when started, encrypts the PCs of the receivers with the LockBit Black payload. The LockBit 3.0 constructor, which was made public by an unhappy developer on Twitter in September 2022, was probably used to create the LockBit Black encryptor used in these attacks. It is thought that this effort is unrelated to the LockBit ransomware operation itself. "Jenny Brown" or "Jenny Green" aliases are being used to send these phishing emails with subject lines like read more...