The Week in Ransomware - January 7th 2022

Source: https://www.bleepingcomputer.com/

January 1st 2022

New Golang ransomware variant

dnwls0719 found a new Golang ransomware variant that appends the .xyz extension.

January 2nd 2022

New STOP ransomware variant

Jakub Kroustek found a new STOP ransomware variant that appends the .loov extension.

New STOP ransomware variant

Jakub Kroustek found a new STOP ransomware variant that appends the .dehd extension.

Lapsus$ ransomware gang hits SIC, Portugal’s largest TV channel

The Lapsus$ ransomware gang has hacked and is currently extorting Impresa, the largest media conglomerate in Portugal and the owner of SIC and Expresso, the country’s largest TV channel and weekly newspaper, respectively.

January 4th, 2022

New Mexico county 'first' local-government ransomware victim of 2022

Government buildings in Bernalillo County, New Mexico, were closed to the public Wednesday in response to what appears to be the first ransomware attack this year against a local government in the United States.

January 6th 2022

FinalSite ransomware attack shuts down thousands of school websites

FinalSite, a leading school website services provider, has suffered a ransomware attack disrupting access to websites for thousands of schools worldwide.

Night Sky is the latest ransomware targeting corporate networks

It's a new year, and with it comes a new ransomware to keep an eye on called 'Night Sky' that targets corporate networks and steals data in double-extortion attacks.

January 7th 2022

FBI: Hackers target US defense firms with malicious USB packages

The Federal Bureau of Investigation (FBI) warned US companies in a recently updated flash alert that the financially motivated FIN7 cybercriminal group is targeting the US defense industry with packages containing malicious USB devices to deploy ransomware.

QNAP warns of ransomware targeting Internet-exposed NAS devices

QNAP has warned customers today to secure Internet-exposed network-attached storage (NAS) devices immediately from ongoing ransomware and brute-force attacks.

New Problem ransomware variant

Amigo-A spotted a new Problem Ransomware variant that appends the .problem extension and drops a ransom note named readme.txt.