malware

Pierluigi Paganini May 25, 2021
Apple addresses three zero-day flaws actively exploited in the wild

Apple has addressed three zero-day vulnerabilities in macOS and tvOS actively exploited in the wild by threat actors. Apple has released security updates to address three zero-day vulnerabilities affecting macOS and tvOS which have been exploited in the wild. The macOS flaw has been exploited by the XCSSET malware to bypass security protections. “Apple is […]

Pierluigi Paganini May 25, 2021
Audio equipment maker Bose Corporation discloses a ransomware attack

The audio equipment manufacturer Bose Corporation said it was the victim of a ransomware attack that took place earlier this year, on March 7. Bose Corporation has announced it was the victim of a ransomware attack that took place earlier this year, on March 7. According to the breach notification letter filed by Bose, the […]

Pierluigi Paganini May 24, 2021
Zeppelin ransomware gang is back after a temporary pause

Operators behind the Zeppelin ransomware-as-a-service (RaaS) have resumed their operations after a temporary interruption. Researchers from BleepingComputer reported that operators behind the Zeppelin ransomware-as-a-service (RaaS), aka Buran, have resumed their operations after a temporary interruption. Unlike other ransomware, Zeppelin operators do not steal data from the victims and don’t run a leak site. Zeppelin ransomware […]

Pierluigi Paganini May 21, 2021
Insurance giant CNA Financial paid a $40 million ransom

The US insurance giant CNA Financial reportedly paid a $40 million ransom to restore access to its files following a ransomware attack.  CNA Financial, one of the largest insurance companies in the US, reportedly paid a $40 ransom to restore access to its files following a ransomware attack that took place in March. According to Bloomberg, […]

Pierluigi Paganini May 21, 2021
Bitcoins of DarkSide ransomware gang still locked in hacker forum’s escrow

After DarkSide ransomware gang shut down operations, multiple affiliates have complained about not receiving the payments for successful breaches. The decision of the DarkSide ransomware gang to shut down operations is causing chaos among its network of affiliates, who have complained about not receiving the payments for their successful breaches. The affiliated are asking the […]

Pierluigi Paganini May 20, 2021
STRRAT RAT spreads masquerading as ransomware

Microsoft warns of a malware campaign that is spreading a RAT dubbed named STRRAT masquerading as ransomware. Microsoft Security Intelligence researchers uncovered a malware campaign that is spreading a remote access trojan (RAT) tracked as STRRAT. The RAT was designed to steal data from victims while masquerading as a ransomware attack. The Java-based STRRAT RAT […]

Pierluigi Paganini May 19, 2021
Conti ransomware gang also breached Ireland Department of Health (DoH)

Conti ransomware also breached the network of Ireland’s Department of Health (DoH) but the ransomware failed to encrypt the systems. Last week, Conti ransomware gang targeted the Ireland’s Health Service Executive that was forced to shut down its IT systems on Friday after being targeted with a significant ransomware attack. The Health Service Executive opted to […]

Pierluigi Paganini May 19, 2021
DarkSide ransomware made $90 million since October 2020

Researchers from blockchain analysis firm Elliptic estimated that Darkside ransomware gang has made over $90 million from its attacks. Experts from blockchain analysis firm Elliptic estimated that the Darkside ransomware gang has earned over $90 million from ransom payments from its victims since October 2020. The researchers examined the Bitcoin wallets used by ransomware gang […]

Pierluigi Paganini May 18, 2021
Analysis of NoCry ransomware: A variant of the Judge ransomware

Researchers at Tesorion released a decryptor for Judge ransomware that also decrypts files encrypted by the NoCry ransomware. In January this year, we published a blog post on our analysis of the Judge ransomware. We announced a free decryptor for Judge victims in this blog post, which is available through the NoMoreRansom initiative. Our decryptor has been helping […]

Pierluigi Paganini May 18, 2021
Discovery of Simps Botnet Leads To Ties to Keksec Group

Uptycs’ threat research team discovered a new botnet, tracked as Simps botnet, attributed to Keksec group, which is focused on DDOS activities Uptycs’ threat research team has discovered a new Botnet named ‘Simps’ attributed to Keksec group primarily focussed on DDOS activities. We discovered the Simps Botnet binaries downloaded via shell script sample and Remote Code […]