KEEP IN TOUCH
Subscribe to our mailing list to get free tips on Data Protection and Cybersecurity updates weekly!





Between law enforcement operations, REvil’s second shut down, and ransomware gangs’ response to the hacking of their servers, it has been quite the week.
This week’s biggest news is the Reuters report that international law enforcement operation took over REvil’s Tor infrastructure, which ultimately led to theย shutdown of the ransomware againย last Sunday.
Since then, reactions have been coming in from other ransomware operations, such asย Groove,ย Conti, andย Arvin Club.
DarkSide also appears to have reacted to the law enforcement operation by attempting toย cash out $7 million in Bitcoinย sitting in a wallet.
This week we also learned of anย attackย on the Sinclair Broadcast Groupย that disrupted the broadcasting of shows and newscasts. This attack was conducted by a new Evil Corp ransomware known asย Macaw Ransomware who has been seen demanding a $40 million ransomย from an unidentified victim.
Also Read: NDA Data Protection: The Importance, Its Meaning And Laws
Interesting research we saw this week is that theย Karma Ransomware is a rebrand of Nemtyย and how FIN7 created a fake company to hire legitimate security professionals to conduct ransomware attacks unknowingly.
Contributors and those who provided new ransomware information and stories this week include:ย @malwrhunterteam,ย @malwareforme,ย @FourOctets,ย @BleepinComputer,ย @VK_Intel,ย @fwosar,ย @struppigel,ย @PolarToffee,ย @LawrenceAbrams,ย @billtoulas,ย @Seifreed,ย @demonslay335,ย @jorntvdw,ย @Ionut_Ilascu,ย @DanielGallagher,ย @serghei,ย @Trustwave,ย @josephmenn,ย @Bing_Chris,ย @coveware,ย @uuallan,ย @GelosSnake,ย @elliptic,ย @SentinelOne,ย @geminiadvisory,ย @ddd1ms,ย @GelosSnake,ย @siri_urz, andย @fbgwls245.
The REvil ransomware operation has likely shut down once again after an unknown person hijacked their Tor payment portal and data leak blog.
dnwls0719ย found the J3ster that appends theย .j3sterย extension to encrypted files and drops a ransom note namedย j3ster readme.txt.
TV stations owned by the Sinclair Broadcast Group broadcast television company went down over the weekend across the US, with multiple sources telling BleepingComputer a ransomware attack caused the downtime.
A joint announcement from the Ministry of Health and the National Cyber Directorate in Israel describes a spike in ransomware attacks over the weekend that targeted the systems of nine health institutes in the country.
The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) published today an advisory with details about how the BlackMatter ransomware gang operates.
Also Read: Invasion Of Privacy Elements And Its Legal Laws To Comply
Threat analysts at Sentinel Labs have found evidence of the Karma ransomware being just another evolutionary step in the strain that started as JSWorm, became Nemty, then Nefilim, Fusion, Milihpen, and most recently, Gangbang.
A free decryptor for the BlackByte ransomware has been released, allowing past victims to recover their files for free.
S!Riย found the in-development Foxxy Ransomware that appends theย .foxxyย extension to encrypted files.

Allan Liska’sย book on ransomware is available for pre-order on Amazon!
Evil Corp has launched a new ransomware called Macaw Locker to evade US sanctions that prevent victims from making ransom payments.
The FIN7 hacking group is attempting to join the highly profitable ransomware space by creating fake cybersecurity companies that conduct network attacks under the guise of pentesting.
The ransomware group REvil was itself hacked and forced offline this week by a multi-country operation, according to three private sector cyber experts working with the United States and one former official.
As of publication we are well into National Cyber Security Awareness month and this past quarter has seen an unprecedented amount of domestic and international activity from government and law enforcement to counter the operations of ransomware actors. Despite these initiatives, ransomware actors continue peppering enterprises with more attacks than ever. What we are doing is not working, at least not yet. Why?
Almost $7 million worth of Bitcoin in a wallet controlled by DarkSide ransomware operators has been moved in what looks like a money laundering rollercoaster.
The Groove ransomware gang is calling on other extortion groups to attack US interests after law enforcement took down REvil’s infrastructure last week.
The Italian data protection authority Garante per la Protezione dei Dati Personali (GPDP) has announced an investigation into a data breach of the countryโs copyright protection agency.
dnwls0719 found a new STOP ransomware variant that appends theย .zapsย extension to encrypted files.