Browsing tag

Locky ransomware

Avira spotted a new strain of the dreaded Locky Ransomware in the wild

Avira firm detected a new strain of the Locky ransomware that is spreading through malicious attachments disguised as legitimate Libre and Office documents. Researchers at Avira Virus Lab detected a new strain of the Locky ransomware that is spreading through malicious attachments disguised as legitimate documents from productivity applications like Microsoft Word and Libre Office. The new Lock […]

Everything you Need to Know About The Evolution of Locky Ransomware

The onset of Locky Ransomware campaign was thought to be evolutionary, but around the clock the campaign has grown to be revolutionary. We had been monitoring and sharing Locky campaign updates since last month till date. It was observed that almost 23 million messages were sent in last 24-hour period, making it one of the largest […]

Beware!! Dangerous Locky Ransomware Spreading Via Dropbox Link and Compromise Your PC

Nowadays Trending Dangerous Ransomware “Locky” Discovered that used to spreading via Malicious Email Spam campaign with attached malicious JavaScript (.js) that links to fake Dropbox pages. The Locky Ransomware re-emerging continuously day by day with new email distribution campaign and its has reported by many Security Research Firm and identified as one of the Fastly Spreading Malware […]

Experts spotted a malware campaign using HoeflerText Popups to push RAT Malware

Experts spotted a new EITest campaign leveraging HoeflerText Popups to target Google Chrome users and push NetSupport Manager RAT or Locky ransomware Security expert Brad Duncan with both the SANS Internet Storm Center and Palo Alto Networks’ Unit 42, has spotted a malware campaign leveraging bogus popups that alert users to a missing web-font. The crooks are targeting Google […]

Boobytrapped Word File Installs Locky Ransomware When You Close the Document

Summer vacation is over! During the past week, security researchers have discovered several distribution campaigns pushing the Locky ransomware via different methods, including a new variant that features one hell of a clever trick. Spotted by Malwarebytes researcher Marcelo Rivero, this distribution campaign comes from the Locky group that uses the affiliate ID #5. On-close Word […]

Locky Ransomware Attacks Ramp Up

***UPDATE*** In the past 24 hours we have seen over 23 million messages sent in this attack, making it one of the largest malware campaigns that we have seen in the latter half of 2017. Malicious email campaign As many US workers were arriving to their offices, a massive malicious email campaign began attempting to reach […]

Cerber Ransomware Comes again to Steal Passwords from Browsers and Crypto Wallets

Cerber ransomware which gained popularity and evolved one of the fast growing ransomware families that infiltrate the system and encrypts various file types including .jpg, .doc, .raw, .avi, etc. It adds a .cerber extension to each encrypted file. Following successful infiltration, Cerber demands a ransom payment to decrypt these files. Also Read A complete Lookback […]

Beware! Hackers Are Spreading Locky Ransomware Using Facebook Messenger

Short Bytes: The notorious hackers are using Facebook messenger to spread dangerous Locky ransomware. They are sending malicious .SVG files in Messenger to lure the users into downloading further malware. The users need to immediately check their Chrome extensions and look for suspecting entries. They are also advised to change the Facebook passwords. Security researchers have […]

Watch out, Locky ransomware spread via SVG images on Facebook Messenger

Researchers have discovered a new hacking campaign leveraging on Facebook Messenger to spread the Locky ransomware via SVG images. The Locky Ransomware is spread via a downloader, experts noticed that it is able to bypass Facebook defense measures by pretending to be a harmless  image file. The campaign was first spotted during the weekend by the malware […]

Locky Ransomware’s new .SHIT Extension shows that you can’t Polish a Turd

To further show how ransomware is such a pile of crap, a new version of Locky has been released that appends the .shit extension on encrypted files. Like previous variants, this ransomware is installed using a DLL that is executed by Rundll32.exe. Once executed, it will encrypt targeted file types and append the .shit extension to the name of encrypted files. Rundll32.exe […]

Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky

By mid-July 2016, the Afraidgate campaign stopped distributing CryptXXX ransomware. It is now distributing the “.zepto” variant of Locky. Afraidgate has been using Neutrino exploit kit (EK) to distribute malware after Angler EK disappeared in early June 2016. As we previously reported, this campaign continues to utilize gate domains using name servers from afraid.org. Changing […]

Locky Ransomware now relies on JavaScript instead downloaders

A new wave of Locky malware emails have been making the rounds since yesterday — July 20, 2016 — with a critical new development, whereby the Windows executable is now embedded in JavaScript. Essentially, the attached JavaScript file has evolved from being a downloader component into becoming the actual ransomware. These JavaScript variants were detected […]

Biggest Spam Flood in Years Distributes Locky Ransomware

Spam wave originated from Indian and Vietnamese IPs. Multiple security firms are reporting on a gigantic wave of spam email that delivers malicious JavaScript file attachments, laced with downloaders for the Locky ransomware. Until now, two different companies reported on this event, ESET and Proofpoint, the latter even going as far as calling it as one […]

LOCKY VARIANT CHANGES C2 COMMUNICATION, FOUND IN NUCLEAR EK

Security experts warn companies need to brace for new harder-to-detect and more determined variants of the Locky ransomware spotted recently in the wild. The news comes just as reported Locky ransomware attacks have waned in recent weeks. Locky is now trying to evade detection by changing the way the ransomware communicates from an infected computer […]

Locky Ransomware – Latest global Cyber Security incident

If you receive a mail masquerading as a company’s invoice and containing a Microsoft Word file, think twice before clicking on it. Doing so could cripple your system and could lead to a catastrophic destruction. Hackers are believed to be carrying out social engineering hoaxes by adopting eye-catching subjects in the spam emails and compromised […]