KEEP IN TOUCH
Subscribe to our mailing list to get free tips on Data Protection and Cybersecurity updates weekly!
It has been a hectic week, with law enforcement conducting two successful law enforcement operations that will significantly impact ransomware.
This week’s biggest news is the law enforcement takedown of the Emotet botnet, followed by the seizing of Tor sites and the arrest of an affiliate for the very active Netwalker ransomware.
Emotet is a significant contributor to ransomware attacks as it installs malware that commonly leads to Ryuk, Conti, Egregor, and ProLock attacks.
This week’s other interesting news is the Avaddon ransomware gang beginning to use DDoS attacks to force victims to the negotiation table. IObit also continued to be harassed by the DeroHE ransomware developers who defaced their forums.
We also saw large enterprise attacks come back after the holidays with attacks on Palfinger and Dairy Farm.
Contributors and those who provided new ransomware information and stories this week include: @demonslay335, @Seifreed, @PolarToffee, @BleepinComputer, @serghei, @FourOctets, @Ionut_Ilascu, @struppigel, @malwareforme, @jorntvdw, @VK_Intel, @LawrenceAbrams, @DanielGallagher, @malwrhunterteam, @fwosar, @BrettCallow, @GrujaRS, @Amigo-A_, @petrovic082, @chum1ng0, @benkow_, @csis_cyber, @Kangxiaopao, @raby_mr, and @RakeshKrish12.
Also Read: How a Smart Contract Audit Works and Why it is Important
Another ransomware gang is now using DDoS attacks to force a victim to contact them and negotiate a ransom.
GrujaRS found a new ransomware called CobraLocker that drops a ransom note named readme.txt.
A ransomware gang continues to taunt Windows software developer IObit by hacking its forums to display a ransom demand.
Leading crane and lifting manufacturer Palfinger is targeted in an ongoing cyberattack that has disrupted IT systems and business operations.
Almost a year after the end of the operations of the Nemty ransomware, we are presenting some internal details of their operations between 2019 and 2020 in order to document the business model and the actors that evolved around that group.
Amigo-A found a new JohnBorn Ransomware that apppends the .johnborn@cock_li extension and drops a ransom note named RecoveryInstructions.txt.
xiaopao found new Xorist Ransomware variants that append the .@LyDarkr and .ZoToN extensions.
Massive pan-Asian retail chain operator Dairy Farm Group was attacked this month by the REvil ransomware operation. The attackers claim to have demanded a $30 million ransom.
xiaopao found a new Xorist Ransomware variant that appends the .CryptPethya extension.
xiaopao found new Xoris ransomware variants that append the .zaplat.za klic 2021 and .EnCryp13d extensions.
Law enforcement has started to distribute an Emotet module to infected devices that will uninstall the malware on April 25th, 2021.
Also Read: What Is A Governance Framework? The Importance And How It Works
The dark web websites associated with the Netwalker ransomware operation have been seized by law enforcement from the USA and Bulgaria.
The U.S. Justice Department announced today the disruption of the Netwalker ransomware operation and the indictment of a Canadian national for alleged involvement in the file-encrypting extortion attacks.
Petrovic found a new ransomware named Namaste that appends the ._enc extension to encrypted files.
Rakesh Krishnan found a new Ransomware-as-a-Service Egalyty that is based after Ranion.
Amigo-A found a new variant of the STOP Ransomware that appends the .pola extension to encrypted files.
The DarkSide ransomware operation issued a new “press release” stating that they will no longer attack certain organizations.
A new ransomware called Vovalex is being distributed through fake pirated software that impersonates popular Windows utilities, such as CCleaner.
xiaopao found new Paradise ransomware variant that appends the .Cukiesi extension to encrypted files.
xiaopao found the new WormLocker ransomware that does not append an extension to encrypted files.
Ravi found a new Dharma ransomware variant that appends the .NOV extension to encrypted files.