On Sunday, a piece of the DoppelPaymer ransomware infected systems of the Mexican state-owned oil company Petróleos Mexicanos (Pemex) taking down part of its network.
The ransom amount for Pemex is 565 BTC currently…
— MalwareHunterTeam (@malwrhunterteam) November 12, 2019
Also, DoppelPaymer's TOR site's text was updated sometimes & now have this:
"Also, we have gathered all your private sensitive data.
So if you decide not to pay, we would share it.
It may harm your business reputation."pic.twitter.com/BoHi1lVigF
According to the company, less than 5% of the computers in its network were infected with ransomware.
“
The Petróleos Mexicanos claims that it
— Petróleos Mexicanos (@Pemex) November 12, 2019
Pemex opera con normalidad. pic.twitter.com/IF7kf6VIEk
Pemex confirmed that its infrastructure, like all major national and international government and financial organizations, is under unceasing targeted attacks, for this reason, it is continuing to improve its security measures.
The DoppelPaymer ransomware is a forked version of the BitPaymer ransomware likely developed by some members of the cybercrime gang tracked as TA505.
[adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – ransomware, Petróleos Mexicanos (Pemex))
[adrotate banner=”5″]
[adrotate banner=”13″]