New ransomware campaign encrypts files even if the ransom is paid

Nearly 50 Linux and Windows servers have been affected by these attacks Ransomware attacks became popular (for the worst reasons) in a brief lapse of time. News about attacks such as WannaCry, Petya and NotPetya preceded a substantial increase in the number of small campaigns using similar techniques to extort unsuspecting Internet users. Recently, ethical hacking researchers have disclosed the […]

Locky ransomware campaign launched 20M attacks in a single day

Another ‘Aggressive’ Locky ransomware campaign launched with 20 million attacks in a single day. Barracuda Advanced Technology Group (BATG) has identified an ‘aggressive’ Locky ransomware threat launched in about 20 million attacks on the very first day, and the campaign seemingly has started just yet. On Tuesday BATG stated that it was ‘actively monitoring an […]

Locky ransomware campaign exploits fears of data stolen in OPM hack

Emails tell victims they need to download an attachment to view “suspicious activity” – then infects them with ransomware. In the immediate aftermath of a major data breach, cybercriminals will often look to take advantage of the situation by sending phishing emails warning people their credentials aren’t safe and that they must login through a […]

New ransomware campaign pilfers passwords before encrypting gigabytes of data

Surreptitious attacks often prey on people visiting legitimate sites. A new wave of crypto ransomware is hitting Windows users courtesy of poorly secured websites. Those sites are infected with Angler, the off-the-shelf, hack-by-numbers exploit kit that saves professional criminals the hassle of developing their own attack. The latest round is especially nasty because before encryption, […]

Multiple Campaigns Exploit VMware Vulnerability to Deploy Crypto Miners and Ransomware

A now-patched vulnerability in VMware Workspace ONE Access has been observed being exploited to deliver both cryptocurrency miners and ransomware on affected machines. “The attacker intends to utilize a victim’s resources as much as possible, not only to install RAR1Ransom for extortion, but also to spread GuardMiner to collect cryptocurrency,” Fortinet FortiGuard Labs researcher Cara […]

Iranian hackers use ransomware to hide espionage campaign targeting Israel

Cybersecurity specialists report detecting a hacking group operating from Iran that has deployed multiple attacks and cyber espionage campaigns against Israeli organizations pretending to be a ransomware operation. This hacker group was identified as Agrius and would have been launching attacks since late last year. Amitai Ben Shushan Ehrlich, researcher at security firm SentinelOne, says: […]

Hackers Launching Ransomware and CryptoMiner via Love_You MalSpam Campaign

The worst alliance of Ransomware and the CryptoMiner family in a spread spree, early January 2019. Malware Spam or MalSpam is the term used to designate malware that is delivered via email messages. Malicious spam (MalSpam) using zipped JavaScript (.js) files as email attachments–this is a well-established tactic used by cybercriminals to distribute malware. The […]

SamSam Ransomware Campaigns Highly Active in 2018 and Heavily Targets Organizations

SamSam ransomware campaigns continue to launch attacks against various organizations sectors including Government, Healthcare and Industrial control sectors. Unlike other Ransomware, SamSam trying to exploiting the critical vulnerabilities in the target organization network instead of using wide spreading Spam approach to compromise the target that used by other ransomware families. The SamSam ransomware group behind […]

Hackers Launching GandCrab Ransomware via New Fallout Exploit Kit using Malvertising Campaign

Cybercriminals now using new Fallout Exploit Kit for launching GandCrab Ransomware via Malvertising Campaign that targets many victims around the world. This malvertising campaign mainly affected users in  Japan, Korea, the Middle East, Southern Europe, Asia Pacific region and other countries. Along with this Exploit kit, there are additional domains, regions, and payloads associated with the campaign […]

Attackers profited more than $300,000 with new SamSam Ransomware Campaign

SamSam Ransomware campaign evolution continues and this time a new variant but there is no difference in the encryption mechanism when compared to old variants. With the new variant some string obfuscation and anti-analysis techniques added to make detection difficult. The SamSam ransomware campaign targetting multiple industries including Government, Healthcare, ICS and also the individuals […]

Facebook and LinkedIn Spam Campaign Spreads Locky Ransomware

An ongoing spam campaign is using boobytrapped image files to download and infect users with the Locky ransomware, Israeli security firm Check Point reports. aMalware authors are spreading malicious image files via these two platforms. When users detect the automatic download, if they access the malformed image, malicious code will install the Locky ransomware on […]

CryptFile2 Ransomware Returns in High Volume URL Campaigns

Proofpoint researchers originally discovered the CryptFIle2 ransomware in March [1]. At the time, it was spreading via exploit kits (EKs); however, beginning on August 3, 2016, we detected the first large-scale email campaign distributing CryptFIle2, allowing a degree of targeting not generally possible with EKs. This ongoing campaign appears to be targeting primarily state and […]

Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky

By mid-July 2016, the Afraidgate campaign stopped distributing CryptXXX ransomware. It is now distributing the “.zepto” variant of Locky. Afraidgate has been using Neutrino exploit kit (EK) to distribute malware after Angler EK disappeared in early June 2016. As we previously reported, this campaign continues to utilize gate domains using name servers from afraid.org. Changing […]

Intense Nemucod Malware Campaign Spreads Teslacrypt Ransomware

TeslaCrypt ransomware infections continue to surge. We reported last week about the first signs of a new TeslasCrypt ransomware campaign that was slowly starting to shape up. Now, after only a few days have gone by, it appears that initial reports are correct, and we are in the midst of a large-scale TeslaCrypt attack. As initially […]

Infostealers, Exploit Kits & Ransomware, Just Your Typical Malware Campaign

A look inside your typical malware campaign.In an optimal scenario, when you get infected with malware, you think it’s only one virus. Unfortunately, in the real world it’s not so, and security analysts from Heimdal Security have unveiled details about a malware campaign that starts with infostealers, goes through exploit kits, and finishes with computers […]