ransomware

Pierluigi Paganini August 09, 2021
Australian Cyber Security Centre warns of a surge of LockBit 2.0 ransomware attacks

TheĀ Australian Cyber Security Centre (ACSC)Ā warns of a surge of LockBit 2.0 ransomware attacks against AustralianĀ organizations starting July 2021. TheĀ Australian Cyber Security Centre (ACSC)Ā warns of an escalation in LockBit 2.0 ransomware attacks against AustralianĀ organizations in multiple industry sectors starting July 2021. The Australian agency also published 2021-006: ACSC Ransomware Profile – Lockbit 2.0 which includes info […]

Pierluigi Paganini August 07, 2021
RansomEXX ransomware hit computer manufacturer and distributor GIGABYTE

Taiwanese manufacturer and distributor of computer hardware GIGABYTE was a victim of the RansomEXX ransomware gang. RansomEXX ransomware gang hit the Taiwanese manufacturer and distributor of computer hardware GIGABYTE and claims to have stolen 112GB of data. At the time of this writing, the leak site of the RansomEXX gang dosn’t include the company name, […]

Pierluigi Paganini August 06, 2021
BlackMatter ransomware also targets VMware ESXi servers

BlackMatter gang rapidly evolves, the group has developed a Linux version that allows operators to targets VMware’s ESXi VM platform. The BlackMatter ransomware gang has implemented a Linux encryptor to targets VMware ESXi virtual machine platform. This is the last ransomware in order of time that is able to target VM platforms, some of the […]

Pierluigi Paganini August 02, 2021
More evidence suggests that DarkSide and BlackMatter are the same group

Researchers found evidence that the DarkSide ransomware gang has rebranded as a new BlackMatter ransomware operation. BleepingComputer found evidence that after the clamorous Colonia Pipeline attack, the DarkSide ransomware gang has rebranded as a new BlackMatter ransomware operation. The experts analyzed encryption algorithms in a decryptor used by BlackMatter, which is actively attacking corporate entities. […]

Pierluigi Paganini July 27, 2021
South Africaā€™s logistics company Transnet SOC hit by a ransomware attack

TransnetĀ SOCĀ Ltd,Ā a largeĀ South AfricanĀ rail, port and pipeline company, announced it was hit by a disruptive cyber attack. South Africaā€™s logistics company Transnet SOC was hit last week by a disruptive cyberattack that halted its operations at all the portā€™s terminals. The attack took place on Thursday, 22 July. ā€œPort terminals are operational across the system, with […]

Pierluigi Paganini July 27, 2021
Hackers flooded the Babuk ransomware gangā€™s forum with gay porn images

The Babuk ransomware operators seem to have suffered a ransomware attack, threat actors flooded their forum gay orgy porn images. At the end of June, the Babuk Locker ransomware was leaked online allowing threat actors to use it to create their own version of the popular ransomware. The Babuk Locker operators halted their operations at the end […]

Pierluigi Paganini July 26, 2021
No More Ransom helped ransomware victims to save almost ā‚¬1B

The No More Ransom initiative celebrates its fifth anniversary, over 6 million victims of ransomware attacks recover their files for free saving almost ā‚¬1 billion in payments. No More Ransom is celebrating its 5th anniversary, the initiative allowed more than 6 million ransomware victims to recover their files for free saving roughly $1 billion in […]

Pierluigi Paganini July 23, 2021
Kaseya obtained a universal decryptor for REvil ransomware attack

The software provider Kaseya announced to have obtained a universal decryptor for the REvil ransomware. Earlier this month, a massive supply chain attack conducted by the REvil ransomware gangĀ hitĀ the cloud-based managed service provider platform Kaseya, impacting both other MSPs using its VSA software and their customers. The VSA tool is used by MSPs to perform […]

Pierluigi Paganini July 18, 2021
HelloKitty ransomware gang targets vulnerable SonicWall devices

BleepingComputer became aware that the recent wave of attacks targeting vulnerable SonicWall devices was carried out by HelloKitty ransomware operators. SonicWall this week has issued an urgent security alert to warn companies of ā€œan imminent ransomware campaingā€ targeting some of its equipment that reachedĀ end-of-lifeĀ (EoL). Threat actors could target unpatched devices belonging to Secure Mobile Access […]

Pierluigi Paganini July 12, 2021
Kaseya releases patches for flaws exploited in massive ransomware supply-chain attack

Kaseya has released a security update to address the VSA zero-day vulnerabilities exploited by REvil gang in the massive ransomware supply chain attack. Software vendor Kaseya has released a security update to fix the zero-day vulnerabilities in its VSA software that were exploited by the REvil ransomware gang in the massive ransomware supply chain attack. […]