Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

The Week In Ransomware – November 6th 2020 – Video Games And Liquor!

The Week In Ransomware – November 6th 2020 – Video Games And Liquor!

This week, it has been busy with attacks worldwide and one of the largest ransomware operations officially shutting down.

The week started with the official announcement from the infamous Maze operation that they were shutting down. BleepingComputer has learned that many of the affiliates are now moving over to a newer ransomware operation called Egregor.

We also learned of a new ransomware called RegretLocker that uses the Windows Virtual Storage APIs to mount virtual machine hard disks (VHDs) to encrypt each file contained in them individually.

Finally, we saw attacks on game developer Capcom, liquor make Campari, and a wide-scale assault on the Brazilian government networks.

Contributors and those who provided new ransomware information and stories this week include: @fwosar@Ionut_Ilascu@VK_Intel@demonslay335@PolarToffee@BleepinComputer@DanielGallagher@Seifreed@LawrenceAbrams@serghei@malwrhunterteam@FourOctets@struppigel@malwareforme@jorntvdw@_CPResearch_@pancak3lullz@Securelist@BitMateus@coveware@smelly__vx@campuscodi@MarceloRivero@M_Shahpasandi@Amigo_A_, and @Kangxiaopao.

November 2nd 2020

Maze ransomware shuts down operations, denies creating cartel

​The infamous Maze ransomware gang announced today that they have officially closed down their ransomware operation and will no longer be leaking new companies’ data on their site.

Also Read: Data Centre Regulations Singapore: Does It Help To Progress?

Maze

New Jigsaw Ransomware

MalwareHunterTeam found a new Jigsaw Ransomware variant that appends the .evil extension.

November 3rd 2020

Leading toy maker Mattel hit by ransomware

​Toy industry giant Mattel disclosed that they suffered a ransomware attack in July that impacted some of its business functions but did not lead to data theft.

New RegretLocker ransomware targets Windows virtual machines

A new ransomware called RegretLocker uses a variety of advanced features that allows it to encrypt virtual hard drives and close open files for encryption.

RegretLocker

Blackbaud sued in 23 class action lawsuits after ransomware attack

Leading cloud software provider Blackbaud has been sued in 23 proposed consumer class action cases in the U.S. and Canada related to the ransomware attack that the company suffered in May 2020.

Also Read: What Is A Governance Framework? The Importance And How It Works

November 4th 2020

Scam PSA: Ransomware gangs don’t always delete stolen data when paid

Ransomware gangs are increasingly failing to keep their promise to delete stolen data after a victim pays a ransom.

Ransomware Demands continue to rise as Data Exfiltration becomes common, and Maze subdues

The Coveware Quarterly Ransomware Report describes ransomware incident response trends during Q3 of 2020. Ransomware groups continue to leverage data exfiltration as a tactic, though trust that stolen data will be deleted is eroding as defaults become more frequent when exfiltrated data is made public despite the victim paying. In Q3, Coveware saw the Maze group sunset their operations as the active affiliates migrated to Egregor (a fork of Maze). We also saw the return of the original Ryuk group, which has been dormant since the end of Q1.

REvil ransomware gang ‘acquires’ KPOT malware

Ransomware gang who claims to have earned $100 million buys the source code of the KPOT information stealer trojan for $6,500.

New STOP Ransomware variant

Michael Gillespie found a new variant of the STOP ransomware that appends the .vpsh extension to encrypted files.

Lock2Bits rebrands as LuckyDay

Toffee discovered that Lock2Bits is rebranding as LuckyDay. The ransomware uses the .luckyday extension and a ransom note named File Recovery.txt.

New DCRTR Ransomware variant

Michael Gillespie found a new variant of the DCRTR ransomware that appends the .termit extension to encrypted files.

New GlobeImposter variant

M. Shahpasandi found a GlobeImposter 2 variant that appends the .CC4H extension.

Strange Bulgarian ransomware

xiaopao found a new ransomware that appends the strange extension of .pethya zaplat zasifrovano.pethya zaplat zasifrovano.pethya zaplat zasifrovano.

Strange

November 5th 2020

Capcom hit by Ragnar Locker ransomware, 1TB allegedly stolen

Japanese game developer Capcom has suffered a ransomware attack where threat actors claim to have stolen 1TB of sensitive data from their corporate networks in the US, Japan, and Canada.

Campari hit by Ragnar Locker Ransomware, $15 million demanded

Italian liquor company Campari Group was hit by a Ragnar Locker ransomware attack, where 2 TB of unencrypted files was allegedly stolen. To recover their files, Ragnar Locker is demanding $15 million.

Brazil’s court system under massive RansomExx ransomware attack

Brazil’s Superior Court of Justice was hit by a ransomware attack on Tuesday during judgment sessions that were taking place over video conference.

Babax stealer rebrands to Osno, installs rootkit

Babax not only changes its name but also adds a Ring 3 rootkit and lateral spreading capabilities. Furthermore it has a ransomware component called OsnoLocker. Is this combination as dangerous as it sounds?

New Tripoli ransomware

Michael Gillespie found a new ransomware called Tripoli that appends the .crypted extension and drops a HOW_FIX_FILES.htm ransom note.

New LockDown ransomware

Marcelo Rivero found a new ransomware called LockDown that appends the .sext and drops a ransom note named HELP_DECRYPT_YOUR_FILES.txt.

New Vaca ransomware variant

xiaopao found a new Vaca ransomware variant that appends the .locked3dllkierff extension.

New Beiguo MBRLocker found

xiaopao found a new MBRLocker that is “Powered by Beiguo.”

MBRLocker

November 6th 2020

New Pay2Key ransomware encrypts networks within one hour

A new ransomware called Pay2Key has been targeting organizations from Israel and Brazil, encrypting their networks within an hour in targeted attacks still under investigation.

Pay2Key

RansomExx ransomware also encrypts Linux systems

With companies commonly using a mixed environment of Windows and Linux servers, ransomware operations have increasingly started to create Linux versions of their malware to ensure they encrypt all critical data.

New ZIMBA Dharma ransomware variant

Michael Gillespie found a new Dharma ransomware variant that appends the .zimba extension to encrypted files.

New RexCrypt ransomware

Michael Gillespie found a new ransomware called RexCrypt that appends the .RexCrypt extension and drops a ransom note named How-To-Decrypt-My-Files.hta.

New Fusion Nefilim variant

Michael Gillespie found a new Nefilim ransomware variant that appends the .FUSION extension and drops a ransom note named FUSION-README.txt.

That’s it for this week! Hope everyone has a nice weekend!

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us