Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

The Week In Ransomware – May 7th 2021 – Attacking Healthcare

The Week In Ransomware – May 7th 2021 – Attacking Healthcare

While ransomware attacks continued throughout the week, for the most part, it has been quieter than usual, with only a few new variants released.

The biggest news was the attack on health care giant Scripps Health whose operations were severely impacted by a ransomware attack.

We also saw a new ransomware called N3TW0RM targeting Israeli companies using an interesting client-server encryption method.

Finally, we learned that Cuba Ransomware is now partnered with Hancitor to compromise and encrypt corporate networks more quickly.

Contributors and those who provided new ransomware information and stories this week include: @jorntvdw@Ionut_Ilascu@malwareforme@LawrenceAbrams@PolarToffee@serghei@demonslay335@DanielGallagher@malwrhunterteam@FourOctets@struppigel@VK_Intel@fwosar@BleepinComputer@Seifreed@Intel_by_KELA@AndreGironda@GroupIB_GIB@SophosLabs@AltShiftPrtScn@M0teki@fbgwls245@pcrisk@chum1ng0@PogoWasRight@3xp0rtblog@ProferoSec@SecurityJoes@cPeterr, and @y_advintel.

May 3rd 2021

Health care giant Scripps Health hit by ransomware attack

Nonprofit health care provider Scripps Health in San Diego is currently dealing with a ransomware attack that forced the organization to suspend user access to its online portal and switch to alternative methods for patient care operations.

N3TW0RM ransomware emerges in wave of cyberattacks in Israel

A new ransomware gang known as ‘N3TW0RM’ is targeting Israeli companies in a wave of cyberattacks starting last week.

Also Read: How To Comply With PDPA: A Checklist For Businesses

New Nitro Ransomware variant

MalwareHunterTeam found a new Nitro Ransomware variant calling itself  ‘ArchAngel Ransomware.’

New Galaxy Ransomware

Yelisey Boguslavskiy discovered that a new Galaxy Ransomware operation was getting ready to launch and would be stealing data from victims.

New Henry Ransomware

dnwls0719 found the new Henry Ransomware that appends the .henry217 extension.

May 4th 2021

New WastedLocker variant

dnwls0719 found a WastedLocker variant that appends the .saverswasted extension.

New Toxin Ransomware sold on hacker forums

3xp0rt noticed that a new Toxin Ransomware was being promoted on hacking forums.May 5th 2021

New STOP Ransomware variant

Michael Gillespie has found a new STOP Ransomware variant that appends the .rejg extension.

Cuba Ransomware Group on a Roll

At the end of 2020, our team, made up of SecurityJoes and Profero incident responders, led an investigation into a complex attack in which hundreds of machines were encrypted, knocking the victim company offline completely. The threat actors behind the attack deployed the Cuba ransomware across the corporate network, using a mixture of PowerShell scripts, SystemBC, and Cobalt Strike to propagate it. Cuba Ransomware utilizes the symmetric ChaCha20 algorithm for encrypting files, and the asymmetric RSA algorithm for encrypting key information

They Told Their Therapists Everything. Hackers Leaked It All

“If we receive €200 worth of Bitcoin within 24 hours, your information will be permanently deleted from our servers,” the email said in Finnish. If Jere missed the first deadline, he’d have another 48 hours to fork over €500, or about $600. After that, “your information will be published for all to see.”

May 6th 2021

A student pirating software led to a full-blown Ryuk ransomware attack

A student’s attempt to pirate an expensive data visualization software led to a full-blown Ryuk ransomware attack at a European biomolecular research institute.

Darkside Ransomware Overview

This is my report for one of the latest Windows samples of Darkside Ransomware v1.8.6.2!

May 7th 2021

Data leak marketplaces aim to take over the extortion economy

Cybercriminals are embracing data-theft extortion by creating dark web marketplaces that exist solely to sell stolen data.

Cuba Ransomware partners with Hancitor for spam-fueled attacks

The Cuba Ransomware gang has teamed up with the spam operators of the Hancitor malware to gain easier access to compromised corporate networks.

New GoNNaCry ransomware

dnwls0719 found a ransomware that appends the .GoNNaCry extension.

Insurer AXA halts ransomware crime reimbursement in France

In an apparent industry first, the global insurance company AXA said Thursday it will stop writing cyber-insurance policies in France that reimburse customers for extortion payments made to ransomware criminals.

Also Read: In Case You Didn’t Know, ISO 27001 Requires Penetration Testing

That’s it for this week! Hope everyone has a nice weekend!

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us