Ransomware News 2020 November - Úvod 2020 2019 2018 0 1 2 3
2020 - January February March April May June July August September October November December
H Ransomware Jak útočí Klany Techniky Obrana Popisky Anti-Ramson Tool Rescue plan Anti-ransomware vaccine RansomFree Prevence Video Vývoj
28.11.20 | MasterChef, Big Brother producer hit by DoppelPaymer ransomware | French multinational production and distribution firm Banijay Group SAS was hit earlier this month by a DoppelPaymer ransomware attack and had sensitive information stolen by the ransomware operators during the incident. | |
28.11.20 | Canon publicly confirms August ransomware attack, data theft | Canon has finally confirmed publicly that the cyberattack suffered in early August was caused by ransomware and that the hackers stole data from company servers. | |
28.11.20 | Chicago-based transportation technology firm Rand McNally is working on restoring network functionality following a cyberattack that hit its systems earlier this week. | ||
28.11.20 | Ransomware hits largest US fertility network, patient data stolen | US Fertility, the largest network of fertility centers in the U.S., says that some of its systems were encrypted in a ransomware attack that affected the company two months ago, in September 2020. | |
28.11.20 | GrujaRS found a new Vash Sorena variant that appends the .encrypt extension. | ||
28.11.20 | Belden networking giant's company data stolen in cyberattack | Network device manufacturer Belden was hit with a cyberattack that allowed threat actors to steal files containing information about employees and business partners. | |
28.11.20 | Egregor RaaS Continues the Chaos with Cobalt Strike and Rclone | Egregor ransomware is an offshoot of the Sekhmet malware family that has been active since mid-September 2020. The ransomware operates by compromising organizations, stealing sensitive user data, encrypting said data, and demanding a ransom to exchange encrypted documents. Egregor is ransomware associated with the cyberattacks against GEFCO and Barnes & Noble, Ubisoft, and numerous others. | |
28.11.20 | Baltimore County Public Schools has been hit today by a ransomware attack that led to a systemic shutdown of its network due to the number of systems impacted in the attack. | ||
28.11.20 | Danish news agency Ritzau refuses to pay after ransomware attack | Ritzau, the largest independent news agency in Denmark founded in 1866 by Erik Ritzau, said in a statement that it will not pay the ransom demanded by a ransomware gang that hit its network on Tuesday morning. | |
28.11.20 | Sopra Steria expects €50 million loss after Ryuk ransomware attack | French IT services giant Sopra Steria said today in an official statement that the October Ryuk ransomware attack will lead to a loss of between €40 million and €50 million. | |
28.11.20 | Emmanuel_ADC-Soft found a new LolKek ransomware variant that appends the .xls extension to encrypted files. | ||
28.11.20 | Over the course of 8 hours the PYSA/Mespinoza threat actors used Empire and Koadic as well as RDP to move laterally throughout the environment, grabbing credentials from as many systems as possible on the way to their objective. The threat actors took their time, looking for files and reviewing the backup server before executing ransomware on all systems. Hours after being ransomed, our files were opened from multiple Tor exit nodes, which confirms our suspicion that files had been exfiltrated. | ||
28.11.20 | Michael Gillespie found a new STOP Djvu Ransomware variant the appends the .lisp extension to encrypted files. | ||
28.11.20 | Ransomware forces E-Land South Korean retail giant to close stores | South Korean conglomerate and retail giant E-Land has suffered a ransomware attack causing 23 of its retail stores to suspend operations while they deal with the attack. | |
28.11.20 | Ranzy Ransomware | Better Encryption Among New Features of ThunderX Derivative | Ranzy ransomware emerged in September/October this year, and appears to be an evolution of ThunderX and, to a lesser extent, Ako ransomware. Ranzy shares many features and under-the-hood elements with its predecessors. However there have been a few key updates, including tweaks to encryption, methods of exfiltration, and the (now commonplace) use of a public “leak blog” to post victim data for those who do not comply with the ransom demand. | |
22.11.20 | Jakub Kroustek found a bunch of Dharma Ransomware variants that append the .cvc extension. | ||
22.11.20 | Michael Gillespie found that a hospital was hit with a custom ransomware. | ||
22.11.20 | MalwareHunterTeam found a ransomware with an interesting hidden message. | ||
22.11.20 | Sportfondsen Nederland swimming pool operator hit with ransomware | During the lock down of the past two weeks, we were hit by an IT failure caused by a computer virus (ransomware). As a result, we are difficult to reach and we have to deal with systems that do not work. | |
22.11.20 | The malware that usually installs ransomware and you need to remove right away | This article focuses on the known malware strains that have been used over the past two years to install ransomware. | |
22.11.20 | xiaopao found a new Dharma Ransomware variant that appends the .SWP extension. | ||
22.11.20 | Michael Gillespie spotted a new unidentified ransomware that appends the .esexz and drops a ransom note named readme.txt. | ||
22.11.20 | The U.S. Federal Bureau of Investigation (FBI) Cyber Division has warned private industry partners of increased Ragnar Locker ransomware activity following a confirmed attack from April 2020. | ||
22.11.20 | LightBot: TrickBot’s new reconnaissance malware for high-value targets | The notorious TrickBot has gang has released a new lightweight reconnaissance tool used to scope out an infected victim's network for high-value targets. | |
22.11.20 | The Qbot banking trojan has dropped the ProLock ransomware in favor of the Egregor ransomware who burst into activity in September. | ||
22.11.20 | MalwareHunterTeam found a new ransomware that appends the .REDROMAN and drops ransom notes names RR_README.html, OPENTHIS.html, and README.html. | ||
22.11.20 | Michael Gillespie found a new STOP Djvu ransomware variant that appends the .sglh extension. | ||
22.11.20 | Mount Locker ransomware now targets your TurboTax tax returns | The Mount Locker ransomware operation is gearing up for the tax season by specifically targeting TurboTax returns for encryption. | |
22.11.20 | MalwareHunterTeam found a new ransomware pretending to be a Blockchain Generator that appends the .lola extension and drops a ransom note named Please_Read.txt. | ||
22.11.20 | Egregor ransomware bombards victims' printers with ransom notes | The Egregor ransomware uses a novel approach to get a victim's attention after an attack - shoot ransom notes from all available printers. | |
22.11.20 | REvil ransomware hits Managed.com hosting provider, 500K ransom | Managed web hosting provider Managed.com has taken their servers and web hosting systems offline as they struggle to recover from a weekend REvil ransomware attack. | |
22.11.20 | Siri found a new ransomware that appends .pulpit extension. | ||
22.11.20 | xiaopao found a new Dharma Ransomware variant that appends the .ZIN extension. | ||
22.11.20 | xiaopao found a new HiddenTear ransomware variant that appends the .r2block extension. | ||
22.11.20 | xiaopao found a new Matrix Ransomware variant that appends the .TG33 extension. | ||
22.11.20 | The Nibiru ransomware is a .NET-based malware family. It traverses directories in the local disks, encrypts files with Rijndael-256 and gives them a .Nibiru extension. Rijndael-256 is a secure encryption algorithm. However, Nibiru uses a hard-coded string "Nibiru" to compute the 32-byte key and 16-byte IV values. The decryptor program leverages this weakness to decrypt files encrypted by this variant. | ||
22.11.20 | Jakub Kroustek found a bunch of Dharma Ransomware variants that append the .dex, .sss, .zimba, and .help extensions. | ||
22.11.20 | @0x4143 found the new Joker's Ransomware that appends the .joker extension and drops a ransom note named POWER-JOKER-PASSWORD.txt. | ||
22.11.20 | xXToffeeXx spotted a new Phobos ransomware variant that appends the .ELDAOLSA extension. | ||
22.11.20 | Michael Gillespie spotted a new unidentified ransomware that appends the .MXX extension and drops a ransom note named How To Recover Your Files!!!!.txt. | ||
22.11.20 | Michael Gillespie spotted a new Flamingo Ransomware variant that appends the .LIZARD extension and drops a ransom note named #READ ME.TXT. | ||
22.11.20 | Michael Gillespie found a new STOP Djvu ransomware variant that appends the .epor extension. | ||
22.11.20 | Cold storage giant Americold hit by cyberattack, services impacted | Cold storage giant Americold is currently dealing with a cyberattack impacting their operations, including phone systems, email, inventory management, and order fulfillment. | |
22.11.20 | Dozens of ransomware gangs partner with hackers to extort victims | Ransomware-as-a-service (RaaS) crews are actively looking for affiliates to split profits obtained in outsourced ransomware attacks targeting high profile public and private organizations. | |
22.11.20 | Capcom confirms data breach after gamers' data stolen in cyberattack | Japanese game giant Capcom has announced a data breach after confirming that attackers stole sensitive customer and employee information during a recent ransomware attack. | |
22.11.20 | xiaopao found a new variant of the VoidCrypt Ransomware that appends the .honor extension. | ||
22.11.20 | DarkSide ransomware's Iranian hosting raises U.S. sanction concerns | Ransomware negotiation firm Coveware has placed the DarkSide operation on an internal restricted list after the threat actors announced plans to host infrastructure in Iran. | |
22.11.20 | dnwls0719 found a new HiddenTear variant that appends the .ZqVIkE extension and drops a ransom note named @READ_ME@.txt. | ||
22.11.20 | Michael Gillespie found a new STOP Djvu ransomware variant that appends the .vvoa extension. | ||
22.11.20 | Retail giant Cencosud hit by Egregor Ransomware attack, stores impacted | Chilean-based multinational retail company Cencosud has suffered a cyberattack by the Egregor ransomware operation that impacts services at stores. | |
15.11.20 | Michael Gillespie found a ransomware group known as "LV" utilizing REvil software. | ||
15.11.20 | Michael Gillespie found a new STOP ransomware variant that appends the .vvoa extension to encrypted files. | ||
15.11.20 | Cisco Talos has recently discovered a new version of the CRAT malware family. This version consists of multiple RAT capabilities, additional plugins and a variety of detection-evasion techniques. In the past, CRAT has been attributed to the Lazarus Group, the malicious threat actors behind multiple cyber campaigns, including attacks against the entertainment sector. | ||
15.11.20 | DarkSide ransomware is creating a secure data leak service in Iran | The DarkSide Ransomware operation claims they are creating a distributed storage system in Iran to store and leak data stolen from victims. To show they mean business, the ransomware gang has deposited $320 thousand on a hacker forum. | |
15.11.20 | Steelcase furniture giant down for 2 weeks after ransomware attack | Office furniture giant Steelcase says that no information was stolen during a Ryuk ransomware attack that forced them to shut down global operations for roughly two weeks. | |
15.11.20 | A ransomware group has now started to run Facebook advertisements to pressure victims to pay a ransom. | ||
15.11.20 | xiaopao found a new ransomware that appends the .devos extension. This is different than Phobos, which also utilized this extension. | ||
15.11.20 | Recent ransomware wave targeting Israel linked to Iranian threat actors | Two recent ransomware waves that targeted Israeli companies have been traced back to Iranian threat actors. | |
15.11.20 | JAMESWT found a new AgeLocker ELF ransomware (targets QNAP devices) that adds the .kmd suffix to encrypted files. | ||
15.11.20 | S!ri found a new ransomware that appends the .howareyou extension to encrypted files. | ||
15.11.20 | Taiwanese laptop maker Compal Electronics suffered a DoppelPaymer ransomware attack over the weekend, with the attackers demanding an almost $17 million ransom. | ||
15.11.20 | Lukáš Zobal found the new Dusk 2 ransomware variant that appends the .DUSK extension to encrypted files and drops a ransom note named README.txt. | ||
15.11.20 | Michael Gillespie found a new STOP ransomware variant that appends the .agho extension to encrypted files. | ||
15.11.20 | Fake Microsoft Teams updates lead to Cobalt Strike deployment | Ransomware operators are using malicious fake ads for Microsoft Teams updates to infect systems with backdoors that deployed Cobalt Strike to compromise the rest of the network. | |
15.11.20 | When Threat Actors Fly Under the Radar: Vatet, PyXie and Defray777 | While researching these malware families, we found that there were several consistencies between Vatet, PyXie and Defray777 that strongly suggest that all three malware families were created, and are currently maintained by, the same financially motivated threat group. | |
15.11.20 | How Ryuk Ransomware operators made $34 million from one victim | One hacker group that is targeting high-revenue companies with Ryuk ransomware received $34 million from one victim in exchange for the decryption key that unlocked their computers. | |
7.11.20 | Michael Gillespie found a new Nefilim ransomware variant that appends the .FUSION extension and drops a ransom note named FUSION-README.txt. | ||
7.11.20 | Michael Gillespie found a new ransomware called RexCrypt that appends the .RexCrypt extension and drops a ransom note named How-To-Decrypt-My-Files.hta. | ||
7.11.20 | Michael Gillespie found a new Dharma ransomware variant that appends the .zimba extension to encrypted files. | ||
7.11.20 | With companies commonly using a mixed environment of Windows and Linux servers, ransomware operations have increasingly started to create Linux versions of their malware to ensure they encrypt all critical data. | ||
7.11.20 | A new ransomware called Pay2Key has been targeting organizations from Israel and Brazil, encrypting their networks within an hour in targeted attacks still under investigation. | ||
7.11.20 | xiaopao found a new MBRLocker that is "Powered by Beiguo." | ||
7.11.20 | xiaopao found a new Vaca ransomware variant that appends the .locked3dllkierff extension. | ||
7.11.20 | Marcelo Rivero found a new ransomware called LockDown that appends the .sext and drops a ransom note named HELP_DECRYPT_YOUR_FILES.txt. | ||
7.11.20 | Michael Gillespie found a new ransomware called Tripoli that appends the .crypted extension and drops a HOW_FIX_FILES.htm ransom note. | ||
7.11.20 | Babax not only changes its name but also adds a Ring 3 rootkit and lateral spreading capabilities. Furthermore it has a ransomware component called OsnoLocker. Is this combination as dangerous as it sounds? | ||
7.11.20 | Brazil's court system under massive RansomExx ransomware attack | Brazil's Superior Court of Justice was hit by a ransomware attack on Tuesday during judgment sessions that were taking place over video conference. | |
7.11.20 | Campari hit by Ragnar Locker Ransomware, $15 million demanded | Italian liquor company Campari Group was hit by a Ragnar Locker ransomware attack, where 2 TB of unencrypted files was allegedly stolen. To recover their files, Ragnar Locker is demanding $15 million. | |
7.11.20 | Capcom hit by Ragnar Locker ransomware, 1TB allegedly stolen | Japanese game developer Capcom has suffered a ransomware attack where threat actors claim to have stolen 1TB of sensitive data from their corporate networks in the US, Japan, and Canada. | |
7.11.20 | xiaopao found a new ransomware that appends the strange extension of .pethya zaplat zasifrovano.pethya zaplat zasifrovano.pethya zaplat zasifrovano. | ||
7.11.20 | M. Shahpasandi found a GlobeImposter 2 variant that appends the .CC4H extension. | ||
7.11.20 | Michael Gillespie found a new variant of the DCRTR ransomware that appends the .termit extension to encrypted files. | ||
7.11.20 | Toffee discovered that Lock2Bits is rebranding as LuckyDay. The ransomware uses the .luckyday extension and a ransom note named File Recovery.txt. | ||
7.11.20 | Michael Gillespie found a new variant of the STOP ransomware that appends the .vpsh extension to encrypted files. | ||
7.11.20 | Ransomware gang who claims to have earned $100 million buys the source code of the KPOT information stealer trojan for $6,500. | ||
7.11.20 | Ransomware Demands continue to rise as Data Exfiltration becomes common, and Maze subdues | The Coveware Quarterly Ransomware Report describes ransomware incident response trends during Q3 of 2020. Ransomware groups continue to leverage data exfiltration as a tactic, though trust that stolen data will be deleted is eroding as defaults become more frequent when exfiltrated data is made public despite the victim paying. In Q3, Coveware saw the Maze group sunset their operations as the active affiliates migrated to Egregor (a fork of Maze). We also saw the return of the original Ryuk group, which has been dormant since the end of Q1. | |
7.11.20 | Scam PSA: Ransomware gangs don't always delete stolen data when paid | Ransomware gangs are increasingly failing to keep their promise to delete stolen data after a victim pays a ransom. | |
7.11.20 | Blackbaud sued in 23 class action lawsuits after ransomware attack | Leading cloud software provider Blackbaud has been sued in 23 proposed consumer class action cases in the U.S. and Canada related to the ransomware attack that the company suffered in May 2020. | |
7.11.20 | New RegretLocker ransomware targets Windows virtual machines | A new ransomware called RegretLocker uses a variety of advanced features that allows it to encrypt virtual hard drives and close open files for encryption. | |
7.11.20 | Toy industry giant Mattel disclosed that they suffered a ransomware attack in July that impacted some of its business functions but did not lead to data theft. | ||
7.11.20 | MalwareHunterTeam found a new Jigsaw Ransomware variant that appends the .evil extension. | ||
7.11.20 | Maze ransomware shuts down operations, denies creating cartel | The infamous Maze ransomware gang announced today that they have officially closed down their ransomware operation and will no longer be leaking new companies' data on their site. |