Showing posts sorted by relevance for query ransomware. Sort by date Show all posts
Showing posts sorted by relevance for query ransomware. Sort by date Show all posts

16 February 2022

Follow the money: Russian Cybercriminals Drive Significant Ransomware and Cryptocurrency-based Money Laundering Activity

Russia has long been home to some of the most skilled hackers in the world. According to cybersecurity investigators like Brian Krebs, this is largely due to the country’s excellence in computer science education, combined with low economic prospects even for those who are skilled in the field. Given this background, it may not be surprising that Russia leads the way in ransomware. But the degree to which Russia-based ransomware strains dominate is quite shocking. 

Before we dive into the data, a quick explainer - we generally tie specific ransomware strains to Russian cybercriminals based on one of three criteria:

1) Evil Corp is a Russia-based cybercriminal organization that has been prolific in ransomware, and whose leadership is believed to have ties to the Russian government. 

2) The Commonwealth of Independent States (CIS) is an intergovernmental organization of Russian-speaking, former Soviet countries. Many ransomware strains contain code that prevents the encryption of files if it detects the victim’s operating system is located in a CIS country. In other cases, ransomware operators have even given over decryptors to return file access after learning they inadvertently targeted a Russian organization. We can attribute CIS-avoiding strains to Russian cybercriminals, though with a lesser degree of confidence, as some of them may be based in other CIS countries.

3) There are several other ransomware characteristics that can indicate a strain is likely based in Russia. Examples include ransomware strains that share documents and announcements in the Russian language, or whose affiliates are believed to be located in Russia with a high degree of confidence. 

Overall, roughly 74% of ransomware revenue in 2021 - over $400 million worth of cryptocurrency - went to strains we can say are highly likely to be affiliated with Russia in some way. 

Blockchain analysis combined with web traffic data also tells us that after ransomware attacks take place, most of the extorted funds are laundered through services primarily catering to Russian users.

www.chainalysis.com


22 December 2020

Microsoft and McAfee headline newly-formed 'Ransomware Task Force'

A group made up of 19 security firms, tech companies, and non-profits, headlined by big names such as Microsoft and McAfee, have announced on Monday plans to form a new coalition to deal with the rising threat of ransomware.

Named the Ransomware Task Force (RTF), the new group will focus on assessing existing technical solutions that provide protections during a ransomware attack.

The RTF will commission expert papers on the topic, engage stakeholders across industries, identify gaps in current solutions, and then work on a common roadmap to have issues addressed among all members.

The end result should be a standardized framework for dealing with ransomware attacks across verticals, one based on an industry consensus rather than individual advice received from lone contractors.

In other news: The US Federal Bureau of Investigations says it is aware of incidents where the DoppelPaymer ransomware gang has resorted to cold-calling companies in order to intimidate and coerce victims into paying ransom demands.

www.zdnet.com


18 July 2025

Police dismantle DiskStation ransomware gang targeting NAS devices, arrest suspected ringleader


"Operation Elicius", a joint international law enforcement operation involving Europol and police forces in Italy, France, and Romania, has successfully dismantled a Romanian ransomware gang that targeted network-attached storage (NAS) devices and arrested its suspected leader.

The so-called "DiskStation Security" ransomware group has targeted and compromised NAS devices - particularly those manufactured by Synology - since 2021, leaving the data of businesses and non-profit organisations encrypted, and demanding a ransom for its recovery...

...Synology has been advising users on how to protect their NAS devices from ransomware attacks for several years.  Much of the advice revolves around minimising the exposure of NAS devices to the internet, hardening password security, and ensuring that regular backups are made of critical data.

The accounts used to secure NAS devices are no different from any other when it comes to security - you should ensure that passwords are unique, and not easy-to-crack.  Attackers will often use automated tools to brute force their way into poorly-secured devices, or take advantage of users who have used easy-to-guess, predictable passwords.

Donline supports dozens of business & home clients in specifying, building, deploying & ongoing management of Synology NAS devices. They are excellent, reliable, cost effective devices to manage your network & data. HOWEVER, as with all IT: internet connectivity, credentials, patching, etc - MUST be carefully managed. Got questions about IT? Contact Donline.

www.fortra.com


23 August 2019

How to avoid ransomware attacks: 10 tips


Nigerian princes are no longer the only menaces lurking in an employee's inbox. For healthcare organizations, schools, government agencies and many businesses, ransomware attacks—an especially sinister type of malware delivered through spear phishing emails that locks up valuable data assets and demands a ransom to release them—are a rapidly-growing security threat.

"We're currently seeing a massive explosion in innovation in the types of ransomware and the ways it's getting into organizations," says Rick McElroy, security strategist for cyber security company Carbon Black Enterprise Response. "It's a big business, and the return on investment to attackers is there—it's going to get worse."

To prevent a ransomware attack, experts say IT and information security leaders should do the following:

  1. Keep clear inventories of all of your digital assets and their locations, so cyber criminals do not attack a system you are unaware of.
  2. Keep all software up to date, including operating systems and applications.
  3. Back up all information every day, including information on employee devices, so you can restore encrypted data if attacked.
  4. Back up all information to a secure, offsite location.
  5. Segment your network: Don't place all data on one file share accessed by everyone in the company.
  6. Train staff on cyber security practices, emphasizing not opening attachments or links from unknown sources.
  7. Develop a communication strategy to inform employees if a virus reaches the company network.
  8. Before an attack happens, work with your board to determine if your company will plan to pay a ransom or launch an investigation.
  9. Perform a threat analysis in communication with vendors to go over the cyber security throughout the lifecycle of a particular device or application.
  10. Instruct information security teams to perform penetration testing to find any vulnerabilities.

13 January 2023

Royal Mail hit by Russia-linked ransomware attack

 

Severe disruption to Royal Mail's overseas deliveries has been caused by ransomware linked to Russian criminals, the BBC has been told.

The cyber-attack has affected the computer systems Royal Mail uses to despatch deliveries abroad. Royal Mail has been warning customers since Wednesday of disruption due to a "cyber-incident". Its latest advice is for people not to try to send international letters and parcels until the issue is resolved.

Ransomware is malicious computer software that encrypts data and locks up systems. The ransomware used in the attack is "Lockbit", according to a source close to the investigation. Computer security firms say the software has been developed and used by criminal gangs with links to Russia.

www.bbc.co.uk


29 July 2019

Ransomware attacks on UK businesses soar 195%


The UK has been the biggest target for ransomware attacks for the first half of 2019 with the number rising 195%, as compared to the 59% reduction in attacks of the same kind in 2018, it has been claimed.

SonicWall, which authored the report, said the number of recorded attacks sits at 6.4 million for the first half of the year and has been largely attributed to the growing preference of criminals for ransomware as a service (RaaS), as well as open-source malware kits becoming cheaper and more readily available online.

"Globally, cybercriminals continue to pivot toward new tactics and that's bad news because ransomware-as-a-service allows less programming-skilled actors into the malware game, and some targets are twice-victimised," said Bill Conner, SonicWall CEO.


12 January 2022

Hotel chain switches from Windows and Mac to Chrome OS to recover from ransomware attack

A Scandinavian hotel chain that fell victim to a ransomware attack last month said it took a novel approach to recover from the incident by switching all affected systems to Chrome OS.

Nordic Choice Hotels, which operates 200 hotels across Northern Europe, fell victim to a ransomware attack on December 2, when hackers encrypted some of its internal systems using the Conti ransomware strain.

The attack prevented staff from accessing guest reservation data and from issuing key cards to newly arriving guests, as one of the hotel’s guests told The Record in an interview last month.

But in a press release, Nordic Choice said that instead of contacting the hackers and negotiating a ransom for the decryption key that would have unlocked the infected devices, the hotel chose to migrate its entire PC fleet from Windows to Chrome OS.

Nordic Choice said they used a tool called CloudReady, which can prepare and port old Windows and macOS computers to Chrome OS setups.

www.therecord.media


25 July 2019

Synology urges all users to take immediate action to protect data from ransomware attack



TAIPEI, Taiwan - July 23, 2019 Synology recently found that several users were under a ransomware attack, where admins' credentials were stolen by brute-force login attacks, and their data was encrypted as a result. We investigated and found that the causes of these attacks were due to dictionary attacks instead of specific system vulnerabilities. This large-scale attack was targeted at various NAS models from different vendors; therefore we strongly recommend users check network and account settings to protect data from ransomware.

"We believe this is an organized attack. After an intensive investigation into this matter, we found that the attacker used botnet addresses to hide the real source IP," said Ken Lee, Manager of Security Incident Response Team at Synology Inc. "After collecting admin account passwords with brute-force attacks, the attack was launched on July 19 and caught users off guard. We therefore informed TWCERT/CC and CERT/CC immediately of this matter in hopes of accelerating the collaborative efforts to resolve this incident."

Since this attack is not related to system security vulnerabilities, it is recommended that Synology users utilize built-in network and account management settings to enhance system security level, preventing malicious attacks from the Internet.

"We urge all Synology users to take immediate action to protect their NAS from the ransomware attack," said Hewitt Lee, Director of Product Management at Synology Inc. "Users' data security is always our priority. For those who are not using Synology NAS, we still recommend you take corresponding actions to protect your precious data."

Synology are a great company with fantastic NAS devices. However, any piece of IT is only as secure as it's weakest link. Use a trivial password & expect to lose control of your device and data! ALWAYS use complex passwords & never reuse passwords!


20 June 2019

Florida city pays $600,000 to ransomware gang to have its data back


The city council for Riviera Beach, Florida, voted this week to pay more than $600,000 to a ransomware gang so city officials could recover data that has been locked and encrypted more than three weeks ago.

The city's decision, as reported by CBS News, came after officials came to the conclusion that there was no other way to recover the city's files.

Access to Riviera City data has been locked since May 29, this year, when a Riviera Beach police department employee opened an email and unleashed ransomware on the city's network.

The ransomware locked files and shut down all the city's services. Operations have been down ever since, with the exception of 911 services, which were able to continue to operate, although limited.

The city's website, email server, billing system, and everything else has been down ever since, with all city communications being done in person, over the telephone, or via posters.

The city has been having a hard time recovering from the incident ever since.

Do not EVER pay these crooks: you just end up sticking a big target on your head! Instead: keep your system up to date, patch, backup, don't click on random links. Seek professional advice if unsure. Stay safe out there folks!


13 May 2017

Info on the NHS (etc) WannaCry RansomWare attack


The Windows vulnerability is not a zero-day flaw, but one for which Microsoft had made available a security patch on 14 March 2017 - almost exactly two months before. The patch was to the Server Message Block protocol used by Windows.

Organisations that lacked this security patch were affected for this reason, and there is so far no evidence that any were specifically targeted by the ransomware developers. Any organisation still running the end-of-life Windows XP, would be particularly at risk, as no security patches for that have been issued by Microsoft since April 2014. As of 2016, thousands of computers in 42 separate NHS trusts in England were reported to be still running Windows XP.

This, dear readers, is why you need to be running up to date, patched systems, protected by quality antivirus software. Don't say that you haven't been warned...


14 January 2022

REvil ransomware gang arrested in Russia

Authorities in Russia say they have dismantled the ransomware crime group REvil and charged several of its members.

The United States had offered a reward of up to $10m (£7.3m) for information leading to the gang members, following ransomware attacks.

Russia's intelligence bureau FSB said the group had "ceased to exist". However, it does not appear that any Russian members of the gang will be extradited to the United States.

The agency said it had acted after being provided with information about the REvil gang by the US. According to the Russian state news service Tass, REvil "developed malicious software" and "organised the theft of money from the bank accounts of foreign citizens".

The FSB said it had seized more than 426 million rubles (£4m), including about £440,000 worth of crypto-currency. It also seized more than 20 "premium cars" which had been purchased with the proceeds of crime.

www.bbc.co.uk


29 June 2017

RansomWare can destroy your data. When did you last backup?


The criminals behind the RansomWare attacks that we have seen recently state that they will restore access to your data if you pay their "fees". However, I wouldn't recommend it.

1) What guarantee do you have that they will do anything at all other than take your money?
2) They have already had their malware in your PC - maybe something nasty is still there?
3) Are you perpetuating their criminal business model - showing that crime pays?
4) Have you just stuck a big target on your head, and said that you are willing to engage with these crooks & their schemes?

The best option is to prepare for disaster by regularly backing up your data, so it can be restored if the worst does happen. Of course, it isn't just RansomWare that can strike: Hard Disk Drives can fail, virus / malware infections, physical theft of a PC, power surges, etc...

PCs are relatively cheap, software can be reinstalled, but your data is generally irreplaceable. 

These two USB devices are ideal for backing up your data:
Kingston 64 GB Flash Drive at: www.amazon.co.uk
Western Digital 2 TB External Hard Drive at: www.amazon.co.uk
Just make sure that whatever you buy is big enough to store all of your data: 
documents, pictures, music, videos, etc - while allowing room for growth.

Contact Donline for help and advice on how to backup and protect your data.

13 May 2017

"Accidental hero" finds kill switch to stop spread of WannaCry RansomWare cyber-attack


An “accidental hero” has halted the global spread of the WannaCry ransomware, reportedly by spending a few dollars on registering a domain name hidden in the malware.

However, a UK cybersecurity researcher tweeting as @malwaretechblog, with the help of Darien Huss from security firm Proofpoint, found and activated a “kill switch” in the malicious software.

The switch was hardcoded into the malware in case the creator wanted to stop it spreading. This involved a very long nonsensical domain name that the malware makes a request to – just as if it was looking up any website – and if the request comes back and shows that the domain is live, the kill switch takes effect and the malware stops spreading.

“I saw it wasn’t registered and thought, ‘I think I’ll have that’,” he is reported as saying. The purchase cost him $10.69. Immediately, the domain name was registering thousands of connections every second.

The kill switch won’t help anyone whose computer is already infected with the ransomware, and and it’s possible that there are other variants of the malware with different kill switches that will continue to spread.


15 September 2020

Australian Cyber Security Centre says: don't pay the crooks to unlock files encrypted during a RansomWare attack!


Paying a ransom does not guarantee decryption of data. Open source reporting indicates several instances where an entity paid the ransom but the keys to decrypt the data were not provided. The ACSC has also seen cases where the ransom was paid, the decryption keys were provided, but the adversary came back a few months later and deployed ransomware again. The likelihood that an Australian organisations will be retargeted increases with every successful ransom payment.

It is generally much easier and safer to restore data from a backup than attempting to decrypt ransomware affected data.


01 July 2021

UK arm of international charity The Salvation Army hit by ransomware attack

Criminals infected The Salvation Army in the UK with ransomware and siphoned the organisation's data, The Register has learned.

A Salvation Army spokesperson confirmed the evangelical Christian church and charity was compromised, and said it alerted regulators in the UK. She told us: “We are investigating an IT incident affecting a number of our corporate IT systems. We have informed the Charity Commission and the Information Commissioner’s Office, are also in dialogue with our key partners and staff and are working to notify any other relevant third parties... We can also confirm that our services for the vulnerable people who depend on us are not impacted and continue as normal.”

Sally Army staff and volunteers should keep a close eye on bank statements for mysterious transactions, and for correspondence suggesting new accounts have been opened with financial service providers. Ransomware gangs typically resell stolen information to other criminals for further exploitation.

www.theregister.com


20 February 2023

Microsoft Defender for Business - help secure what matters

Good enough isn’t enough when it comes to protecting your business from ransomware, malware, phishing, and other threats. Get enterprise-grade endpoint security—designed specifically for small and medium businesses with up to 300 employees—with Microsoft Defender for Business.

CLICK HERE to watch a two-minute video

With a 300 percent increase in ransomware attacks in the last year, and with more than 50 percent of them reaching small businesses, it’s more important than ever to build a secure foundation for your company.

Stay productive and help ensure business continuity with an easy-to-use, cost-effective endpoint security solution that works with your IT—Microsoft Defender for Business. Proactively protect your customers and data with:

Wizard-driven setup with recommended policies to secure devices and servers.

Threat and vulnerability management, with automated, built-in intelligence.

Next-generation antivirus protection.

Simple, streamlined experiences that give actionable insights and recommendations.

A solution that works seamlessly with your Microsoft 365 plan.

Contact Donline to find out how Microsoft Defender for Business can protect your organisation.

www.microsoft.com



28 June 2017

RansomWare attacks: who wrote the original code? The answer might surprise you!...


EternalBlue, sometimes stylized as ETERNALBLUE, is an exploit generally believed to have been developed by the U.S. National Security Agency (NSA). It was leaked by the Shadow Brokers hacker group on the 14 April 2017, and was used as part of the worldwide WannaCry ransomware attack on 12 May 2017. The exploit was also used to help carry out the 2017 Petya cyberattack on the 27 June 2017.

EternalBlue exploits a vulnerability in Microsoft's implementation of the Server Message Block (SMB) protocol. This vulnerability is denoted by entry CVE-2017-0144 in the Common Vulnerabilities and Exposures (CVE) catalog. The vulnerability exists because the SMB version 1 (SMBv1) server in various versions of Microsoft Windows accepts specially crafted packets from remote attackers, allowing them to execute arbitrary code on the target computer.

Please ensure that you are running up to date, patched systems, 
Contact Donline if you need help & advice on protecting your systems & data. 

30 September 2021

In RansomWare news: crooks complain that crooks are acting like... crooks!

Security intelligence vendor Flashpoint claims to have found forum comments from customers of the REvil ransomware-as-a-service gang, and they’re not happy. The gang's malware may contain backdoors that REvil uses to restore encrypted files itself.

REvil's modus operandi is to rent its malware to other evildoers, in return for a hefty cut of any ransoms paid by victims.

Flashpoint writes that the "Exploit" forum has recently featured posts from a threat actor complaining about the backdoor, and the fact its presence meant that REvil could let its customers do all the hard work of arranging an infection, then subvert communications with victims and keep the entire ransom for itself.

Other chat in the forum, Flashpoint asserts, includes complaints about REvil's behaviour, and the futility of attempting to negotiate with the gang.

www.theregister.com


17 September 2021

Free REvil ransomware master decrypter released for past victims

A free master decryptor for the REvil ransomware operation has been released, allowing all victims encrypted before the gang disappeared to recover their files for free.

The REvil master decryptor was created by cybersecurity firm Bitdefender in collaboration with a trusted law enforcement partner.

While Bitdefender could not share details about how they obtained the master decryption key or the law enforcement agency involved, they told BleepingComputer that it works for all REvil victims encrypted before July 13th.

www.bleepingcomputer.com


26 March 2019

Massive hack attack? More like an act of war - apparently!


June 2017 saw one of the world’s most costly malware outbreaks ever. The NotPetya ransomware, initially spread via a malicious automatic update to a popular Ukrainian accounting software tool, hit companies around the world including advertising giant WPP, household goods manufacturer Reckitt Benckiser, FedEx subsidiary TNT Express, and international shipping logistics company Maersk.

Shipping conglomerate Maersk later estimated that the NotPetya ransomware cost them as much as $300 million in lost revenue. Reckitt Benckiser, the firm behind such brands as Nurofen and Durex, blamed the malware attack for a $100 million loss in revenue.

One of those organisations hit by NotPetya was multinational law firm DLA Piper. The business, with a presence in over 40 countries, reportedly had a “flat network structure globally”, allowing every data centre and Windows-based server on its network to be impacted by NotPetya.

Wiping its systems and starting again must have been costly, even before you start counting the 15,000 hours of extra overtime it reportedly paid its IT staff. So, it’s no surprise to hear that DLA Piper is interested in claiming back some of that expense from its insurers, Hiscox.

As The Times reports today, DLA Piper has started proceedings against Hiscox, saying that the insurance firm has failed to pay out for the damages and costs associated with the NotPetya attack - a claim which may amount to several million pounds.

From the sound of things, Hiscox is refusing to pay up because of the “act of war” exclusion clause commonly found in insurance policies. The UK government, you may recall, has officially stated that the Russian military was “almost certainly” behind the NotPetya attack.