/* ---- Google Analytics Code Below */
Showing posts with label Ransomeware. Show all posts
Showing posts with label Ransomeware. Show all posts

Monday, May 09, 2022

A Look at Ransomware

 No End in sight?

Researchers Share In-Depth Analysis of PYSA Ransomware Group

April 18, 2022Ravie Lakshmanan in ThehackerNews

An 18-month-long analysis of the PYSA ransomware operation has revealed that the cybercrime cartel followed a five-stage software development cycle from August 2020, with the malware authors prioritizing features to improve the efficiency of its workflows.

This included a user-friendly tool like a full-text search engine to facilitate the extraction of metadata and enable the threat actors to find and access victim information quickly.

"The group is known to carefully research high-value targets before launching its attacks, compromising enterprise systems and forcing organizations to pay large ransoms to restore their data," Swiss cybersecurity company PRODAFT said in an exhaustive report published last week.

PYSA, short for "Protect Your System, Amigo" and a successor of the Mespinoza ransomware, was first observed in December 2019 and has emerged as the third most prevalent ransoware strain detected during the fourth quarter of 2021.

Since September 2020, the cybercriminal gang is believed to have exfiltrated sensitive information belonging to as many as 747 victims until its servers were taken offline earlier this January. ....'

Tuesday, March 01, 2022

Defeating Ransomware

Still booming, some general thoughts on protection. 

Three Ways to Defeat Ransomware, By Jeff Orloff on March 01, 2022 in SecurityWeek

Ransomware is very difficult to stop, mostly because the attackers are adept at locking up a network long before anybody in an organization even sees a ransom note.  In many attacks, the malware combines an encryption payload with automated propagation. 

This potent combination can be delivered using various attack techniques which enable threat actors to bypass delivery and execution security measures by leveraging compromised credentials. The ransomware is then able to rapidly encrypt the data of one endpoint after another — until a network is crippled.

Over the past few years, the growing sophistication of the ransomware ‘industry’ has spawned niche players and specialized variants. For example, Hades (a variant of WastedLocker) almost exclusively targets large organizations — a practice known as “big game hunting.” .... ' 

Saturday, February 26, 2022

Ransomware used in Ukraine Attacks

Such tools will likely become tools in other kinds of cyberattacks.

Ransomware Used as Decoy in Destructive Cyberattacks on Ukraine in SecurityWeek  By Ionut Arghire

The cyberattacks employed HermeticWiper, a piece of malware that was designed solely to damage the Master Boot Record (MBR) of the target system, rendering the machine unusable.

Once executed, the wiper adjusts its settings to gain read access control to any file, then gains the privileges required to load and unload device drivers, disables crash dumps to cover its tracks, disables the Volume Shadow Service (VSS), and loads a benign partition manager which it abuses to corrupt the MBR.

The wiper uses different corruption methods based on the version of Windows running on the machine and partition type (FAT or NTFS). HermeticWiper can damage both MBR and GPT drives and triggers a system reboot to complete the data wiping process, researchers with Cisco’s Talos division note.

Although executed on February 23, hours before Russia launched an invasion of Ukraine, the attacks appear to have been in preparation for months.

The network of one organization in Ukraine was compromised on December 23, 2021, with a web shell installed on January 16, more than one month before HermeticWiper was deployed, Symantec reports. .... '