Ransomware News 1-  Úvod  2019  2018  0  1  2  3 

Update 11.02.2019 18:43:58

Úvod  Ransomware  Jak útočí  Klany  Techniky  Obrana  Popisky  Anti-Ramson Tool  Rescue plan  Anti-ransomware vaccine  RansomFree  Prevence  Video  Vývoj  Ransomware Articles

 

Ransom News

Datum

Název

Obrázek

Popis

22.6.19New [Locked] RansomwareVýsledek obrázku pro ransomwareMichael Gillespie is looking for a new ransomware that appends the [LOCKED] extension and drops a ransom note named UNLOCK INSTRUCTIONS.txt.
22.6.19New Hack Dharma Ransomware variantVýsledek obrázku pro ransomwareJakub Kroustek found a new Dharma Ransomware variant that appends the .HACK extension to encrypted files.
22.6.19New 0day Dharma Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie found a new Dharma Ransomware variant that appends the .0Day extension to encrypted files.
22.6.19Stop Decryptor updatedVýsledek obrázku pro ransomwareMichael Gillespie updated his Stop Decryptor to support the offline key for the .vesad extension variant.
22.6.19Release of GandCrab 5.2 Decryptor Ends a Bad Ransomware StoryGandCrab DecryptorIn collaboration with law enforcement agencies around the world, Bitdefender has released an updated decryptor for the GandCrab Ransomware that can decrypt files encrypted by versions 1, 4, and 5 through 5.2.
22.6.19New Horon STOP Djvu variantVýsledek obrázku pro ransomwareMichael Gillespie found a new variant of STOP Djvu ransomware that appends the .horon extension to encrypted files.
22.6.19New Orion version of Major RansomwareOrion Major RansomwareAmigo-A found a new variant of the Major Ransomware that appends the .orion extension on encrypted files and drops a ransom note named READ_ME.orion.
22.6.19WannaCash Decryptor updatedVýsledek obrázku pro ransomwareAlex Svirid updated his WannaCash Decryptor to support new variants.
22.6.19New Middleman RansomwareVýsledek obrázku pro ransomwareMichael Gillespie is looking for a new ransomware that appends the .middleman2020 extension and drops a ransom note named !INSTRUCTI0NS!.TXT.
22.6.19New Copan DCRTR RansomwareDCRTRAmigo-A found a new variant of the DCRTR Ransomware that appends the .COPAN extension and drops ransom notes named HOW TO DECRYPT FILES.txt and HOW TO DECRYPT FILES.hta.
22.6.19Ryuk Ransomware Adds IP and Computer Name BlacklistingRyuk Ransom NoteA new variant of the Ryuk Ransomware has been discovered that adds IP address and computer blacklisting so that matching computers will not be encrypted.
22.6.19New Neras STOP Djvu variantVýsledek obrázku pro ransomwareMichael Gillespie found a new variant of STOP Djvu ransomware that appends the .neras extension to encrypted files.
22.6.19New Adage Phobos Ransomware variantVýsledek obrázku pro ransomwareM. Shahpasandi found a new variant of the Phobos Ransomware that appends the .id[********-****].[helpteam38@protonmail.com].adage exemsion to encrypted files.
22.6.19Florida city pays $600,000 to ransomware gang to have its data backVýsledek obrázku pro ransomwareThe city council for Riviera Beach, Florida, voted this week to pay more than $600,000 to a ransomware gang so city officials could recover data that has been locked and encrypted more than three weeks ago.
22.6.19DanaBot Banking Trojan Upgraded with 'Non Ransomware' ModuleNon RansomwareA new malicious campaign is distributing an upgraded variant of DanaBot that comes with a new ransomware module used to target potential victims from Italy and Poland via phishing emails which deliver malware droppers. Checkpoint also released a decryptor for this ransomware.
22.6.19Stop Decryptor updatedVýsledek obrázku pro ransomwareMichael Gillespie updated his Stop Decryptor to support the offline key for the .horon extension variant.
22.6.19New Ransomnix Ransomware variantRansomnixAmigo-A found a new variant of the Ransomnix Ransomware that appends the .dmo extension and drops a ransom note named HOW_TO_RETURN_FILES.txt.
22.6.19Sodinokibi Ransomware Spreads Wide via Hacked MSPs, Sites, and SpamSodinokibi Ransom NoteWith the GandCrab Ransomware operation shutting down, affiliates are looking to fill the hole left behind with other ransomware. Such is the case with the Sodinokibi Ransomware, whose affiliates are using a wide range of tactics to distribute the ransomware and earn a commission.
22.6.19New LooCipher Ransomware Spreads Its Evil Through SpamLooCipherA new ransomware called LooCipher has been discovered that is actively being used in the wild to infect users. While it is not known exactly how this ransomware is being distributed, based on some of the files that were found, we believe it is through a spam campaign.
22.6.19New Truke STOP Djvu variantVýsledek obrázku pro ransomwareMichael Gillespie found a new variant of STOP Djvu ransomware that appends the .truke extension to encrypted files.
22.6.19New Bitch RansomwareBitch RansomwareMalwareHunterTeam found a new ransomware that calls itself "Bitch Ransomware". Nuff said.
16.6.19New Myskle and Boston STOP Djvu RansomwareVýsledek obrázku pro ransomwareMichael Gillespie found a new variants of the STOP Djvu Ransomware that append the .myskle or .boston extensions to encrypted files.
16.6.19STOP Decryptor UpdatedVýsledek obrázku pro ransomwareMichael Gillespie updated his STOP Decryptor to contain the offline key for the .heroset variant.
16.6.19New Zoh Dharma Ransomware variantVýsledek obrázku pro ransomwareJakub Kroustek found a new variant of the Dharma Ransomware that appends the .zoh extension to encrypted files.
16.6.19JSWorm Ransomware 3.1 ReleasedJSWorm 3.1Amigo-A discovered JSWorm Ransomware 3.1 that uses a new ransom note named JSWORM-DECRYPT.hta. Still uses the .jsworm extension.
16.6.19New Muslat STOP Djvu RansomwareVýsledek obrázku pro ransomwareMichael Gillespie found a new variant of the STOP Djvu Ransomware that appends the .muslat extension to encrypted files.
16.6.19Food Bank Hit By Ransomware, Needs Your Charity to RebuildVýsledek obrázku pro ransomwareRansomware attacks hit indiscriminately and sometimes they may affect charitable organizations that can’t afford to surrender to the demand. Auburn Food Bank in King County, Washington, fell victim to a ransomware strain known as GlobeImposter 2.0, which encrypted all computers on their network.
16.6.19How Cybercriminals Recruited Young Romanian WomanVýsledek obrázku pro ransomwareIn this excerpt from Kate Fazzini’s “Kingdom of Lies,” one former Romanian hacker tells how she got into the biz.
16.6.19New Gerosan STOP Djvu RansomwareVýsledek obrázku pro ransomwareMichael Gillespie found a new variant of the STOP Djvu Ransomware that appends the .gerosan extension to encrypted files.
16.6.19New Html Dharma Ransomware variantVýsledek obrázku pro ransomwareJakub Kroustek found a new variant of the Dharma Ransomware that appends the .html extension to encrypted files.
16.6.19Bisquilla Ransomware discoveredBisquilla RansomwareJack found the Bisquilla Ransomware, which appears to be in dev as it does not encrypt.
16.6.19New Cephalo Ransomware discoveredVýsledek obrázku pro ransomwareDaniel Gallagher discovered a ransomware being distributed through a LNK file that contains a PowerShell command.
16.6.19Ransomware identification for the judicious analystVýsledek obrázku pro ransomwareMalware detection is a simple yes- or no-answer to the question: Is this file malicious?
Or in case of ransomware detection: Is this file ransomware? Identification on the other hand will provide an aswer to the question: Which malware or ransomware family is this?
16.6.19Ransomware halts production for days at major airplane parts manufacturerVýsledek obrázku pro ransomwareASCO, one of the world's largest suppliers of airplane parts, has ceased production in factories across four countries due to a ransomware infection reported at its plant in Zaventem, Belgium.
16.6.19New SD 1.1 RansomwareSD 1.1 RansomwareA new ransomware called SD 1.1 was posted on the BleepingComputer forums and was identified by Amigo-A, The ransomware appends the .[Unlock11@protonmail.com].enc extension.
16.6.19pyLocky Decryptor Released by French AuthoritiesVýsledek obrázku pro ransomwareA decryptor for pyLocky Ransomware versions 1 and 2 has been released by French authorities that allows victim to decrypt their files for free.
16.6.19New Vesad STOP Djvu RansomwareVýsledek obrázku pro ransomwareMichael Gillespie found a new variant of the STOP Djvu Ransomware that appends the .vesad extension to encrypted files.
16.6.19STOP Decryptor UpdatedVýsledek obrázku pro ransomwareMichael Gillespie updated his STOP Decryptor to contain the offline key for the .boston, .muslat, and .gerosan extension.
16.6.19New Harma Dharma Ransomware variantVýsledek obrázku pro ransomwareJakub Kroustek found a new variant of the Dharma Ransomware that appends the .harma extension to encrypted files.
16.6.19Armageddon Ransomware DiscoveredArmageddon Ransomware S!Ri discovered the Armageddon Ransomware. This ransomware does not encrypt all files on the PC.
16.6.19New Poop Ransomware?RansomwarePetrovic found a new ransomware that appends the .poop extension to encrypted files. It is quite ugly too.
16.6.19GandCrab is covering up their tracksGandCrab cleaning upCapsLo0ck noticed that the Gandcrab devs have asked Exploit.in to delete their posts on the site.
9.6.19GandCrab Ransomware Shutting Down After Claiming to Earn $2.5 BillionGandCrab PostAfter almost a year and a half, the operators behind the GandCrab Ransomware are shutting down their operation and affiliates are being told to stop distributing the ransomware.
9.6.19Dodger Ransomware discoveredDodger RansomwareMalwareHunterTeam discovered a new ransomware called Dodger that appends the .dodger extension and shows this not very nice screen.
9.6.19New Lanset and Redmat Stop Ransomware variantsVýsledek obrázku pro ransomwareMichael Gillespie found new variants of the STOP Djvu Ransomware that appends the .lanset and .redmat extensions to encrypted files.
9.6.19New BSC Dharma Ransomware variantVýsledek obrázku pro ransomwareJakub Kroustek found a new Dharma Ransomware variant that appends the .bsc extension to encrypted files.
9.6.19Strange Bits: Sodinokibi Spam, CinaRAT, and Fake G DATAVýsledek obrázku pro ransomwareSodinokibi ransomware was known so far for being installed via Oracle WebLogic exploit (see Talos' article). A new campaign uses spam emails with attached MS Office Word document to download Sokinokibi to the target system. JamesWT found the first sample, Sculabs another one[1]. The email pretends to be a warning letter from the fee collection center of public-law broadcasting institutions in the Federal Public of Germany and demands 213.50 EUR payment.
9.6.19Baltimore ransomware perp pinky-swears he didn’t use NSA exploitVýsledek obrázku pro ransomwareOver the past few weeks, a Twitter account that has since been confirmed by researchers to be that of the operator of the ransomware that took down Baltimore City's networks May 4 has posted taunts of Baltimore City officials and documents demonstrating that at least some data was stolen from a city server. Those documents were posted in response to interactions I had with the ransomware operator in an attempt to confirm that the account was not a prank.
9.6.19New Davda Stop Ransomware foundVýsledek obrázku pro ransomwareMichael Gillespie found a new variant of the STOP Djvu Ransomware that appends the .davda extension to encrypted files.
9.6.19Baltimore’s bill for ransomware: Over $18 million, so farVýsledek obrázku pro ransomwareIt has been a month since the City of Baltimore's networks were brought to a standstill by ransomware. On Tuesday, Mayor Bernard "Jack" Young and his cabinet briefed press on the status of the cleanup, which the city's director of finance has estimated will cost Baltimore $10 million—not including $8 million lost because of deferred or lost revenue while the city was unable to process payments. The recovery remains in its early stages, with less than a third of city employees issued new log-in credentials thus far and many city business functions restricted to paper-based workarounds.
9.6.19New Pidom and Poret Stop Ransomware variantsVýsledek obrázku pro ransomwareMichael Gillespie found new variants of the STOP Djvu Ransomware that appends the .pidom and .poret extensions to encrypted files.
9.6.19New Kjh Dharma Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie found a new variant of the Dharma Ransomware that appends the .kjh extension to encrypted files.
9.6.19New Wannacash Ransomware variantVýsledek obrázku pro ransomwareAlex Svirid found a new WannaCash Ransomware variant that changes an encrypted file's name to "файл зашифрован (original_filename) .punisher"
9.6.19The RIG Exploit Kit is Now Pushing the Buran RansomwareBuran Ransom NoteThe RIG exploit kit is now infecting victim's computers with a new ransomware variant called Buran. This ransomware is a variant of the Vega ransomware that was previously being distributed through Russian malvertising campaigns.
9.6.19New Heroset Stop Ransomware foundVýsledek obrázku pro ransomwareMichael Gillespie found a new variant of the STOP Djvu Ransomware that appends the .heroset extension to encrypted files.
9.6.19STOP Djvu Decryptor udpatedVýsledek obrázku pro ransomwareMichael Gillespie has updated his STOP Djvu decrypter to include the offline keys for the .stone, .lanset, .davda, .poret, .pidon extensions.
9.6.19New GlobeImposter 2 variantVýsledek obrázku pro ransomwareMichael Gillespie found a new GlobeImposter 2 variant that appends the .{dresdent@protonmail.com}DDT extension to encrypted files.
9.6.19New Euclid RansomwareVýsledek obrázku pro ransomwareMichael Gillespie found a new ransomware called Euclid uploaded to ID Ransomware that appends the .euclid extension and drops a ransom note named how to recovery.txt.
9.6.19Hackers Won’t Let Up in Their Attack on U.S. CitiesVýsledek obrázku pro ransomwareWSJ reports that there were two intrusions in Baltimore city networks; one by an actor that used EternalBlue to move around the network and the other was the one who installed RobbinHood and did not use EternalBlue."Local governments across the country are facing a growing threat of cyberattacks and escalating ransom demands, as an attack in this city has crippled thousands of computers for a month."
2.6.19In-dev GottaCry RansomwareGottaCryMalwareHunterTeam found a new ransomware called GottaCry that is in-development.
2.6.19SysFrog Ransomware discoveredVýsledek obrázku pro ransomwareMichael Gillespie spotted a ransomware that appends the .sysfrog extension to encrypted files and drops a ransom note named how_to_decrypt.txt.
2.6.19New QBX Dharma Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie spotted a new Dharma Ransomware variant that appends the .qbx extension to encrypted files.
2.6.19New Mogera STOP Djvu variantVýsledek obrázku pro ransomwareMichael Gillespie found a new STOP Djvu Ransomware variant that appends the .mogera extension to encrypted files.
2.6.19New ZOH Dharma Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie spotted a new Dharma Ransomware variant that appends the .zoh extension to encrypted files.
2.6.19New BEETS Dharma Ransomware variantVýsledek obrázku pro ransomwareJakub Kroustek spotted a new Dharma Ransomware variant that appends the .beets extension to encrypted files.
2.6.19New Rezuc STOP Djvu variantVýsledek obrázku pro ransomwareMichael Gillespie found a new STOP Djvu Ransomware variant that appends the .rezuc extension to encrypted files.
2.6.19New Eric RansomwareVýsledek obrázku pro ransomwareMichael Gillespie spotted a new ransomware that appends the .ERIS extension and drops a ransom note named @ READ ME TO RECOVER FILES @.txt.
2.6.19New GlobeImposter variantVýsledek obrázku pro ransomwareGrujaRS found a new GlobeImposter variant that appends the .LotR extension and drops a ransom note named NEW_WAVE.html.
2.6.19MBR-based NMoreira Boot RansomwareNoMeira Boot variantDave Logue found a variant of the NMoreira Ransomware that appears to be targeting the MBR.
2.6.19Fake WannaCry RansomwareWannaCryMalwareHunterTeam found a fake WannaCry Ransomware that looks like it was made a joke, school assignment, or for "fun".
2.6.19New Harma Dharma Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie spotted a new Dharma Ransomware variant that appends the .harma extension to encrypted files.
2.6.19STOP Ransomware Decryptor updatedVýsledek obrázku pro ransomwareMichael Gillespie updated his STOP Djvu Ransomware decryptor to support the offline keys for the .skymap, .mogera, and .rezuc variants.
2.6.19New Buran Ransomware spottedVýsledek obrázku pro ransomwareMichael Gillespie spotted a new ransomware on ID-Ransomware that utilizes what looks like a GUID for the extension. For example, .3674AD9F-5958-4F2A-5CB7-F0F56A8885EA. It also drops a ransom note named !!! YOUR FILES ARE ENCRYPTED !!!.TXT.
2.6.19Sodinokibi Ransomware Pushed via Foreclosure Warning SpamSodinokibi RansomwareA malspam campaign targeting potential German victims is actively distributing Sodinokibi ransomware via spam emails disguised as foreclosure notifications with malicious attachments which pose as foreclosure notifications.
2.6.19Maze Ransomware Says Computer Type Determines Ransom AmountMaze RansomwareA variant of the Maze Ransomware, otherwise known as the ChaCha Ransomware, has been spotted being distributed by the Fallout exploit kit. An interesting feature of this ransomware is that it says the ransom amount will be different depending on whether the victim is a home computer, server, or workstation.
2.6.19New Stone STOP Djvu variantVýsledek obrázku pro ransomwareMichael Gillespie found a new STOP Djvu Ransomware variant that appends the .stone extension to encrypted files.
2.6.19New RotorCrypt Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie found a new RotorCrypt Ransomware variant that appends the !__prontos@cumallover.me__.bak extension.

26.5.19

New ransomware discoveredVýsledek obrázku pro ransomwareMichael Gillespie found a new ransomware that appends the .[epta.mcold@gmail.com] and drops a ransom note named !INSTRUCTI0NS!.TXT,
26.5.19New in-dev EZDZ RansomwareVýsledek obrázku pro ransomwareMalwareHunterTeam found a new in-dev ransomware called EZDZ that utilizes the .EZDZ extension and drops a ransom note named HELP_PC.EZDZ-REMOVE.txt.
26.5.19New Radman STOP Djvu Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie found a new STOP Djvu Ransomware variant that appends the .radman extension.
26.5.19New Ferosas STOP Djvu Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie found a new STOP Djvu Ransomware variant that appends the .ferosas extension.
26.5.19New TOR13 Dharma variantVýsledek obrázku pro ransomwareJakub Kroustek found a new Dharma Ransomware variant that appends the .TOR13 extension to encrypted files.

26.5.19

Cryptocurrent scam pushing ransomwareVýsledek obrázku pro ransomwareFrost found an Ether scam distributing a new ransomware.
26.5.19JSWorm 2.0 Ransomware Decryptor Gets Your Files Back For FreeJSWorm DecryptorA decryptor for the JSWorm 2.0 Ransomware has been released by Emsisoft this week that allows victims to decrypt their files for free. If you become infected with JSWorm 2.0, do not pay the ransom and instead follow the instructions below.
26.5.19Louisville Regional Airport Authority hit by 'ransomware' attackVýsledek obrázku pro ransomwareWDRB reports: "The Louisville Regional Airport Authority said it fell victim to ransomware Monday morning."
26.5.19GetCrypt Ransomware Brute Forces Credentials, Decryptor ReleasedGetCryptA new ransomware called GetCrypt is being installed through malvertising campaigns that redirect victims to the RIG exploit kit. Once installed, GetCrypt will encrypt all of the files on a computer and then demand a ransom payment to decrypt the files.
26.5.19Hackers Are Holding Baltimore Hostage: How They Struck and What’s NextVýsledek obrázku pro ransomwareA NY Times article by Niraj Chokshi covering Baltimore being hit by the RobbinHood ransomware. Also includes a quote from your favorite ransomware information site :)

26.5.19

New Rectot STOP Djvu Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie found a new STOP Djvu Ransomware variant that appends the .rectot extension.
26.5.19New Les Scarab Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie found a new Scarab Ransomware variant that appends the .les# extension and drops a ransom note named как расшифровать файлы les#.TXT.
26.5.19Wiper disguised as ransomware distributed via emailVýsledek obrázku pro ransomwarehonkone found an email pushing a malicious executable. Bart analyzed and determined it was a ransomware, but Michael Gillespie stated it was actually a wiper. The fun of malware.
26.5.19STOP Djvu Decryptor updatedVýsledek obrázku pro ransomwareMichael Gillespie updated the STOP Djvu decryptor to support the offline IDs for .ferosas, .rectot, and .INFOWAIT variants.  
26.5.19Sodinokibi Ransomware Poised to Impact Larger EnterprisesVýsledek obrázku pro ransomwareCoveware states:"Given the sophisticated attack vector and the investment the developers of Sodinokibi have made to their payment TOR site, this variant seems to be poised to become a popular choice among ransomware distributors."
26.5.19New Good Dharma variantVýsledek obrázku pro ransomwareJakub Kroustek found a new Dharma Ransomware variant that appends the .GOOD extension to encrypted files.
26.5.19NordFox Ransomware discoveredNordfoxGrujaRS discovered the NordFox Ransomware, which appends the .legacy extension to encrypted files and drops a ransom note named READ_ME.txt.
26.5.19New Skymap STOP Djvu Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie found a new STOP Djvu Ransomware variant that appends the .skymap extension.

18.5.19

New STOP Djvu variant discoveredVýsledek obrázku pro ransomwareMichael Gillespie found a new STOP Djvu variant that adds the .codnat extension to encrypted files.
18.5.19New Dharma variants releasedVýsledek obrázku pro ransomwareJakub Kroustek found new variants of the Dharma Ransomware that append the .qbtex and the .yG extension to encrypted files.
18.5.19New STOP Djvu variant discoveredVýsledek obrázku pro ransomwareMichael Gillespie found a new STOP Djvu variant that adds the .codnat1 extension to encrypted files.
18.5.19WannaCry still present on 1.7 million machinesVýsledek obrázku pro ransomware2 years after WannaCry and there’s still 1.7M machines with SMB exposed to the Internet!
18.5.19New DrWeb Dharma variant releasedVýsledek obrázku pro ransomwareJakub Kroustek found a new variant of the Dharma Ransomware that appends the .drweb extension to encrypted files.
18.5.19New STOP Djvu variant discoveredVýsledek obrázku pro ransomwareMichael Gillespie found a new STOP Djvu variant that adds the .bufas extension to encrypted files.
18.5.19Wesker Encrypter discoveredWeskerMichael Gillespie found the Wesker Encrypter that does not add an extension but drops ransom notes name !!!INSTRUCTION_RNSMW!!!.txt.

18.5.19

New ChaCha Ransomware variantChaChaMichael Gillespie found a new ChaCha Ransomware variant that appends a random 6-7 char extension and drops a ransom note named DECRYPT-FILES.html.
18.5.19Non Ransomware discoveredNon RansomwareGrujaRS found the Non Ransomware that appends the .non extension and drops a ransom note named HowToBackFiles.txt. Possibly in-dev as the ransom note does not include an email address.
18.5.19New Dharma variants releasedVýsledek obrázku pro ransomwareJakub Kroustek found new variants of the Dharma Ransomware that append the .jack and .PLUT extensions to encrypted files.
18.5.19JSWorm Ransomware sends a shoutout to researchersShoutoutThe JSWorm Ransomware sent a shoutout in its code to MalwareHunterTeam, S!Ri, and Amigo-A.
18.5.19Possible new Desktop Ransomware variantDesktop RansomwareGrujaRS found a new ransomware that could be a variant of the Desktop Ransomware. This ransomware prepends the Locked. string to encrypted file's names.
18.5.19THE TRADE SECRET: Firms That Promised High-Tech Ransomware Solutions Almost Always Just Pay the HackersVýsledek obrázku pro ransomwareAs ransomware attacks crippled businesses and law enforcement agencies, two U.S. data recovery firms claimed to offer an ethical way out. Instead, they typically paid the ransom and charged victims extra.
18.5.19New DDOS Dharma variant releasedVýsledek obrázku pro ransomwareJakub Kroustek found a new variant of the Dharma Ransomware that appends the .DDOS extension to encrypted files.

18.5.19

New Oops Scarab Ransomware variantScarab Ransom NoteAmigo-A found a new Scarab Ransomware variant that appends the .Oops extension and drops a ransom note named HOW TO RECOVER ENCRYPTED FILES.TXT.
18.5.19New Mamba Phobos Ransomware variantPhobos Mamba variantGrujaRS found a new Phobos Ransomware variant that appends the .mamba extension to encrypted files.
18.5.19New Cry Dharma variant releasedVýsledek obrázku pro ransomwareJakub Kroustek found a new variant of the Dharma Ransomware that appends the .cry extension to encrypted files.
18.5.19New STOP Djvu variant discoveredVýsledek obrázku pro ransomwareMichael Gillespie found a new STOP Djvu variant that adds the .dotmap extension to encrypted files.
18.5.19The Reality Of RansomwareVýsledek obrázku pro ransomware"About 1.5 million ransomware attacks occur annually, putting individuals and corporations in a no-win situation. ProPublica technology reporter Renee Dudley joins host Krys Boyd to explain how these attacks work, how firms can sometimes recover the stolen data, and how sometimes the solution is just to pay up.Her recent story on the topic is a joint investigation with The Guardian."
18.5.19New Ge0l0Gic RansomwareGeologic RansomwareGrujaRS found the Ge0l0Gic Ransomware that appends the .ge0l0gic extension and drops a ransom note named .ge0l0gic_readme.txt.
18.5.19ZQ Ransomware decryptor updatedVýsledek obrázku pro ransomwareEmsisoft has updated their ZQ Ransomware decryptor to support the w_unblock24@qq.com].ws variant.
18.5.19New 4k Dharma variant releasedVýsledek obrázku pro ransomwareJakub Kroustek found a variant of the Dharma Ransomware that appends the .4k extension to encrypted files.
18.5.19Baltimore Ransomware still affecting city servicesBaltimore servicesCatalin Cimpanu states "A list of what's still down, almost 2 weeks after the attack:"
18.5.19STOP Djvu Decrypter updatedVýsledek obrázku pro ransomwareMichael Gillespie released an update for his STOP Decrypter to support the offline IDs for the .shadow, .fordan, .codnat, and .dotmap extensions.

11.5.19

New MegaCortex Ransomware Found Targeting Business Networks

MegaCortex Ransom Note

A new ransomware has been discovered called MegaCortex that is targeting corporate networks and the workstations on them. Once a network is penetrated, the attackers infect the entire network by distributing the ransomware using Windows domain controllers.

11.5.19

New STOP Ransomware variant

Výsledek obrázku pro ransomware

Amigo-A found a new STOP Djvu Ransomware variant that appends the .sarut extension to encrypted files.

11.5.19

New Navi Scarab Ransomware variant

Výsledek obrázku pro ransomware

Alex Svirid found a new Scarab Ransomware variant that appends the .Navi extension to encrypted files.

11.5.19

New BAT Dharma variant

Výsledek obrázku pro ransomware

Jakub Kroustek found a new Dharma ransomware variant that appends the .bat extension to encrypted files.

11.5.19

New Scarab Ransomware variant

Scarab Ransom Note

Amigo-A found a new Scarab Ransomware variant that appends the kes$ extension and drops a ransom nte named Инструкция по расшифровке.TXT.

11.5.19

New Scarab Ransomware variant

Zorro Ransom Note

Amigo-A found a new Scarab Ransomware variant that appends the .zoro extension and drops a ransom nte named !!! RESTORE DATA !!!.TXT.

11.5.19

New Dharma variants

Výsledek obrázku pro ransomware

Jakub Kroustek found a bunch of new Dharma ransomware variants that append the ,qbix, .aa1, and .wal extension to encrypted files.

11.5.19

Yara rules created for the MegaCortex Ransomware

Výsledek obrázku pro ransomware

Marc Rivero López created Yara rules to detect the MegaCortex ransomware and the Rietspoof loader. This MegaCortex rule is posted here and the Rietspoof rule is here.

11.5.19

New STOP Ransomware variant

STOP Ransom Note

Amigo-A found a new STOP Djvu Ransomware variant that appends the .fedasot extension to encrypted files and drops a ransom note named _readme.txt.

11.5.19

New KBK GlobeImposter 2.0 variant

Výsledek obrázku pro ransomware

Michael Gillespie found a new GlobeImposter 2.0 Ransomware variant that appends the .{Killback@protonmail.com}KBK extension.

11.5.19

Ransomware hunt for the Recry Ransomware

Výsledek obrázku pro ransomware

Michael Gillespie is looking for a ransomware that appends the .recry1 extension and drops a ransom note named decryption_help.txt.

11.5.19

New STOP Ransomware variants

Výsledek obrázku pro ransomware

Michael Gillespie found new STOP Djvu Ransomware variants that appends the .forasom or .berost extensions to encrypted files.

11.5.19

Local Authorities in Texas and Maryland Hit by Ransomware

Výsledek obrázku pro ransomware

The servers of Baltimore City Hall and Amarillo, TX, Potter County were hit by ransomware attacks, with the former having shut down most servers while the latter already got some of its computing systems back online.

11.5.19

STOP Decryptor offline keys updated

Výsledek obrázku pro ransomware

Michael Gillespie updated STOP Decryptor with the offline keys for .roldat, .dutan, .sarut, .berost, and .forasom.

11.5.19

Dharma Ransomware Uses Legit Antivirus Tool To Distract Victims

Encrypted files

A new Dharma ransomware strain is using ESET AV Remover installations as a "smoke screen" technique designed to distract victims while their files are encrypted in the background as detailed by Trend Micro.

11.5.19

New MERS Dharma variant

Výsledek obrázku pro ransomware

Jakub Kroustek found a new Dharma ransomware variant that appends the .MERS extension to encrypted files.

11.5.19

New Blitzkrieg Ransomware

Výsledek obrázku pro ransomware

Amigo-A found the new Blitzkrieg Ransomware that appends the .bkc extension and drops a ransom note named HowToBackFiles.txt.

11.5.19

Imperial County officials to invest in rebuilding network following cyber attack

Výsledek obrázku pro ransomware

The hacker made a ransom demand of $1.2 million dollars in bitcoin to restore the network, a demand Imperial County decided not to pay.

11.5.19

Jokeroo Ransomware as a Service Pulls an Exit Scam

Jokeroo Exit scam

Since May 7th, 2019, the Tor sites for the Jokeroo Ransomware as a Service (RaaS) have started displaying a notice stating that their server was seized by the Royal Thai Police in conjunction with the Dutch National Police and Europol. It turns out that this notice is fake and the RaaS is performing an exit scam.

11.5.19

New BKC GlobeImposter 2.0 variant

Výsledek obrázku pro ransomware

Michael Gillespie found a new GlobeImposter 2.0 Ransomware variant that appends the [blellockr@godzym.me].bkc extension.

11.5.19New STOP Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie found a new STOP Djvu Ransomware variant that appends the .fordan extension to encrypted files.
11.5.19MegaCortex, deconstructed: mysteries mount as analysis continuesVýsledek obrázku pro ransomwareIt’s been a week since we published our initial research on the ransomware calling itself MegaCortex. Our initial post was written over about a day and a half, as we started to observe an early outbreak on May 1. We have a lot of new information to share today.
11.5.19New Matrix Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie found a new Matrix Ransomware variant that appends the .QH24 extension and drops a ransom note named !QH24_INFO!.rtf.
11.5.19New FLKR Ransomware variantVýsledek obrázku pro ransomwareAlex Svirid found a new FLKR Ransomware variant that appends the .+jabber-theone@safetyjabber.com extension to encrypted files.
4.5.19Russian Legion Ransomware foundVýsledek obrázku pro ransomwareMalwareHunterTeam found a new HiddenTear variant called Russian Legion
4.5.19Sodinokibi Ransomware foundRansom NoteGrujaRS found the Sodinokibi Ransomware that assigned a random extension to each victim.
4.5.19BellevueInject RansomwareBellevue InjectMalwareHunterTeam found the BellevueInject CryptoWire variant that appears to target Bellevue College. Looks in-dev.
4.5.19STOP Djvu Decryptor updatedVýsledek obrázku pro ransomwareMichael Gillespie updated the STOP Djvu decryptor to include the offline IDs for .etols, .guvara, .norvas, .moresa, .verasto, and .hrosas.
4.5.19New Fredd Dharma variantVýsledek obrázku pro ransomwareMichael Gillespie spotted a new Dharma Ransomware variant that appends the .FREDD extension.
4.5.19BigBobRoss Ransomware decrypted updatedVýsledek obrázku pro ransomwareEmsisoft has updated their decryptor for the BigBobRoss Ransomware to support the .cheetah variant.
4.5.19New Prodecryptor RansomwareProdeCryptorGrujaRS found a new ransomware named Prodecryptor that appends the .Prodecryptor extension and drops a ransom note named ReadME-Prodecryptor@gmail.com.txt.
4.5.19New STOP Djvu variantVýsledek obrázku pro ransomwareMichael Gillespie found a new STOP Djvu variant that appends the .todarius extension to encrypted files.
4.5.19LockerGoga Ransomware Family Used in Targeted AttacksVýsledek obrázku pro ransomwareOnce again, we have seen a significant new ransomware family in the news. LockerGoga, which adds new features to the tried and true formula of encrypting victims’ files and asking for payment to decrypt them, has gained notoriety for the targets it has affected.
4.5.19Sodinokibi Ransomware Being Installed on Exploited WebLogic ServersSodinokibi Ransomware payment siteAttackers are exploiting a recently disclosed WebLogic vulnerability to install a new ransomware called Sodinokibi. As this vulnerability is trivial to exploit, it is important that server admins install the patch immediately in order to prevent infections or unauthorized access.
4.5.19GitHub-Hosted Malware Targets Accountants With RansomwareVýsledek obrázku pro ransomwareThreat actors ran a malvertising campaign on the Russian Yandex.Direct advertising network starting October 2018 to disseminate a malware cocktail designed to encrypt victims' data and steal cryptocurrency.
4.5.19New STOP Djvu ransomware variantsVýsledek obrázku pro ransomwareMichael Gillespie has found new STOP Djvu variants that append the .roldat or .hofos extensions to encrypted files.
4.5.19New .TXT Dharma VariantVýsledek obrázku pro ransomwareMichael Gillespie has spotted a new variant of the Dharma ransomware that uses the .txt extension for encrypted files. This going to confuse as a lot of people.
4.5.19Windows Server hosting provider still down a week after ransomware attackVýsledek obrázku pro ransomwareA ransomware infection has crippled the operations of a US-based web hosting provider for almost eight days now, several of the company's disgruntled customers have told ZDNet today.
4.5.19New Video Dharma variantVýsledek obrázku pro ransomwareJakub Kroustek found a new variant of the Dharma ransomware that appends the .video extension to encrypted files.
4.5.19New Zeropadypt RansomwareZeropadypt RansomwareAmigo_A_ found a new ransomware that fills "files with zeros".
4.5.19Emsisoft releases a decryptor for the ZQ RansomwareVýsledek obrázku pro ransomwareEmsisoft has released a decryptor for the ZQ Ransomware.
4.5.19New WannaOof RansomwareVýsledek obrázku pro ransomwareMalwareHunterTeam found a new ransomware called WannaOof that appends the .oof extension to encrypted files.
4.5.19STOP decryptor updated with further offline keysVýsledek obrázku pro ransomwareMichael Gillespie has updated his STOP decryptor with the offline keys for .kiratos and .todarius.
4.5.19Decryptor for MegaLocker and NamPoHyu Virus Ransomware ReleasedMegaLocker DecryptorEmsisoft has released a decryptor for the MegaLocker and NamPoHyu Virus ransomware that has been targeting exposed Samba servers. Victims can now use this decryptor to recover their files for free.
4.5.19New Wal Dharma variantVýsledek obrázku pro ransomwareMichael Gillespie has found a new Dharma variant that appends the .wal extension to encrypted files.
4.5.19New STOP Djvu ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie has found a new STOP Djvu variant that append the .dutan extension to encrypted files.
4.5.19“MegaCortex” ransomware wants to be The OneMega Cortex Ransom NoteA new ransomware that calls itself MegaCortex got a jolt of life on Wednesday as we detected a spike in the number of attacks against Sophos customers around the world, including in Italy, the United States, Canada, the Netherlands, Ireland, and France. The attackers delivering this new malware campaign employed sophisticated techiques in the attempt to infect victims.
27.4.19New STOP Djvu Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie found a new STOP Djvu ransomware variant that appends the .moresa extension to encrypted files.
27.4.19New Scarab Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie found a new variant of the Scarab Ransomware that appends the .croc and drops a ransom note named HELP_BY_CROC.TXT.
27.4.19New Paradise Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie found a new Paradise Ransomware variant that appends the .sambo extension and drops a ransom note named Instructions with your files.txt.
27.4.19New LDPR Dharma variantVýsledek obrázku pro ransomwareMichael Gillespie found a new Dharma Ransomware that appends the .LDPR extension to encrypted files.
27.4.19Someone made a payment to a WannaCry Ransomware walletVýsledek obrázku pro ransomwareSomeone just paid 0.0584 BTC ($309.26 USD) to a bitcoin wallet tied to #WannaCry ransomware.
27.4.19New Colorit RansomwareVýsledek obrázku pro ransomwareMichael Gillespie spotted a new ransomware that appends the .COLORIT on ID Ransomware.
27.4.19ST04: Ransomware Trends with Raj Samani and John FokkerVýsledek obrázku pro ransomwareRaj Samani, Chief Scientist and McAfee Fellow, and John Fokker, Head of Cyber Investigations for McAfee Advanced Threat Research, discuss various ransomware attacks and how it’s evolving.
27.4.19New STOP Djvu Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie found a new version of the STOP Djvu ransomware that appends the .verasto extension to encrypted files.
27.4.19New Scarab Ransomware variantVýsledek obrázku pro ransomwareAmigo-A found a new variant of the Scarab Ransomware that appends the .vally extension.
27.4.19New Major Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie found a new variant of the Major Ransomware that appends the .mars extesion and drops a ransom note named READ_ME.mars.
27.4.19Over 500% Increase in Ransomware Attacks Against BusinessesVýsledek obrázku pro ransomwareCybercriminals have started focusing their efforts on businesses during Q1 2019, with consumer threat detections decreasing by roughly 24% year over year while businesses have seen a 235% increase in the number of cyber attacks against their computing systems.
27.4.19New BigBobRoss Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie found a new BigBobRoss variant that appends the .cheetah extension that drops a ransom note named How to recover your files.txt.
27.4.19New STOP Djvu Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie found a new STOP Djvu Ransomware variant that appends the .hrosas extension to encrypted files.
27.4.19New Scarab Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie found a new Scarab Ransomware variant that appends the .[zoro4747@gmx.de].zoro and drops a ransom note named !!! RESTORE DATA !!!.TXT.
27.4.19New JSWorm variant discovered with a message for ID-RansomwareJSWormS!Ri found a new variant of the JSWorm that has a message for ID Ransomware.
27.4.19New GlobeImposter variantGlobeImposterGrujaRS found a new GlobeImposter variant that appends the .DOCM and drops a ransom note named Restore-My-Files.txt.
27.4.19Vulnerable Confluence Servers Get Infected with Ransomware, TrojansVýsledek obrázku pro ransomwareA critical Atlassian Confluence Server vulnerability is being remotely exploited by attackers to compromise both Linux and Windows servers, allowing them to drop GandCrab ransomware and the Dofloo (aka AES.DDoS, Mr. Black) Trojan.
27.4.19Snatch Ransomware discoveredVýsledek obrázku pro ransomwareGrujaRS found the Snatch Ransomware that appends the .hceem extension and drops a ransom note named RESTORE_HCEEM_DATA.txt.
27.4.19Signed Hermes Ransomware variant spottedVýsledek obrázku pro ransomwareMalwareHunterTeam found a signed Hermes Ransomware variant.
27.4.19New Kiratos Stop Djvu Ransomware variantVýsledek obrázku pro ransomwareAmigo-A found a new STOP Djvu ransomware variant that appends the .kiratos extension to encrypted files.
27.4.19A Closer Look at the RobbinHood RansomwareEnd of encryption messageThe RobbinHood Ransomware is the latest player in the ransomware scene that is targeting companies and the computers on their network. This ransomware is not being distributed through spam but rather through other methods, which could include hacked remote desktop services or other Trojans that provide access to the attackers.
20.4.19RobbinHood Ransomware Claims It's Protecting Your PrivacyRobbinHood RansomwareA new ransomware is in play called RobbinHood that is targeting entire networks and then encrypting all computers that they can gain access to. They then request a certain amount of bitcoins to decrypt a single computer or a larger amount to decrypt the entire network.
20.4.19New Locked RansomwareLocked RansomwarePetrovic found a new ransomware that appends the .locked extension and drops a ransom note named README[number].txt. Below is an image supplied by GrujaRS of this infection.
20.4.19New Proyecto X RansomwareProyecto XMalwareHunterTeam found a ransomware called Proyecto X that appends the .robinhood extension to encrypted files.
20.4.19Android Sauron Locker Ransomware discoveredSauron LockerLukas Stefanko found a new Android ransomware called Sauron Locker that locks device and replaces background wallpaper for ransom note.
20.4.19Ransom amounts rise 90% in Q1 as Ryuk increasesVýsledek obrázku pro ransomwareCoveware's Q1 Ransomware Marketplace report aggregates anonymized ransomware data from cases handled and resolved by Coveware’s Incident Response Team. Unlike surveys, which rely on sentiment, this report is created solely from a standardized set of data collected from every case. By aggregating and sharing this data we believe large and small enterprises can better protect themselves from the persistent and ever-evolving ransomware threat.
20.4.19'NamPoHyu Virus' Ransomware Targets Remote Samba ServersRansom NoteA new ransomware family called NamPoHyu Virus or MegaLocker Virus is targeting victims a bit differently than other ransomware. Instead of an executable running on a victim's computer, the attacker is running the ransomware locally and having it remotely encrypt accessible Samba servers.
20.4.19New Phoenix Phobos Ransomware variantPhoenix PhobosGrujaRS found a new variant of the Phobos Ransomware that appends the .phoenix extension to encrypted files and drops a ransom note named info.txt.
20.4.19New Exploit Paradise Ransomware variantVýsledek obrázku pro ransomwareAmigo-A found a new Paradise Ransomware variant that appends the .exploit extension to encrypted files.
20.4.19New Burn Scarab Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie found a new Scarab Ransomware variant that appends the .burn extension to encrypted files.
20.4.19Cube Ransomware HuntVýsledek obrázku pro ransomwareMichael Gillespie is looking for a new ransomware that appends the .cube extension and drops a ransom note named READ_ME.cube.
20.4.19New CRABSLKT Scarab Ransomware variantScarab RansomwareAmigo-A found a new Scarab Ransomware variant that appends the .CRABSLKT and drops a ransom note named HOW TO RECOVER ENCRYPTED FILES.TXT.
20.4.19Cyber-security firm Verint hit by ransomwareVýsledek obrázku pro ransomwareThe Israel offices of US cyber-security firm Verint have been hit by ransomware, according to a screenshot taken by a Verint employee that started circulating online earlier today.
20.4.19DLL Cryptomix Ransomware Variant Installed Via Remote DesktopCryptoMix Ransom NoteThe CryptoMix ransomware is still alive and kicking as a new variant has been spotted being spread in the wild. This new version appends the .DLL extension to encrypted files and is said to be installed through hacked remote desktop services.
20.4.19New norvas STOP Djvu RansomwareVýsledek obrázku pro ransomwareMichael Gillespie found a new STOP Djvu Ransomware variant that appends the .norvas extension to encrypted files.
20.4.19Weekly Ransomware Market Share from CovewareWeekly Ransomware Market ShareCoveware notes that Ryuk attacks have continued to decline in prevalence since last week. New Variants of Dharma and Phobos continue to hit smaller enterprises via RDP in the US. A slew of GandCrab attacks hit enterprises in Western Europe via CVE’s that allow remote code execution
20.4.19Jokeroo jokers modify a GandCrab executable?Jokeroo GandCrabJakub Kroustek discovered an unpacked GandCrab 5.3 executable that contains strings from the Jokeroo RaaS. It is not known if it's the GandCrab devleopers poking fun at another ransomware developers or the jokers behind Jokeroo playing with GandCrab.
13.4.19Genesee County, Michigan Recovering from Ransomware AttackVýsledek obrázku pro ransomwareGenesee County, Michigan was hit with a ransomware attack on Tuesday and the county has been working non-stop to get their systems back online. Unfortunately, this process turned out to be more difficult than expected and system are still down.
13.4.19Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga RansomwareVýsledek obrázku pro ransomwareRecently, FireEye Managed Defense detected and responded to a FIN6 intrusion at a customer within the engineering industry, which seemed out of character due to FIN6’s historical targeting of payment card data. The intent of the intrusion was initially unclear because the customer did not have or process payment card data. Fortunately, every investigation conducted by Managed Defense or Mandiant includes analysts from our FireEye Advanced Practices team who help correlate activity observed in our hundreds of investigations and voluminous threat intelligence holdings. Our team quickly linked this activity with some recent Mandiant investigations and enabled us to determine that FIN6 has expanded their criminal enterprise to deploy ransomware in an attempt to further monetize their access to compromised entities.
13.4.19New .btix Dharma variantVýsledek obrázku pro ransomwareJakub Kroustek discovered a new variant of the Dharma ransomware that appends the .btix extension to encrypted files.
13.4.19New raldug STOP Djvu variantVýsledek obrázku pro ransomwareAmigo-A found a new variant of the STOP Djvu ransomware that appends the .raldug extension to encrypted file names.
13.4.19AsuraHTTP Bot with Ransomware capabilitiesAsuraHTTPMalwareHunterTeam discovered a LiteHTTP Bot renamed as AsuraHTTP with some Ransomware code added to it.
13.4.19Planetary Ransomware Decryptor Gets Your Files Back For FreePlanetary DecryptorA decryptor for the Planetary Ransomware family was released by Emsisoft this week that allows victims to decrypt their files for free. This ransomware family is named Planetary because it commonly uses the names of planets for the extensions added to encrypted file's names.
13.4.19Anubis Android Trojan Spotted with Almost Functional Ransomware ModuleVýsledek obrázku pro ransomwareAn Android application which steals PayPal credentials, encrypts files from the device's external storage, and locks the screen using a black screen was spotted in the Google Play Store by ESET malware researcher Lukas Stefanko.
13.4.19GET YOUR DATA BACK WITHOUT PAYING RANSOMVýsledek obrázku pro ransomware"We reached out to three battle-weary ransomware knights — Wosar (whose day job is at Emsisoft), Lawrence Abrams from Bleeping Computer (a computer help site started in 2004) and Michael Gillespie, who founded the free ID Ransomware service three years ago — for tips on how individuals and businesses can thwart the thievery. They all had surprisingly similar advice"
13.4.19Turkish Aurora offline variantAuroraMalwareHunterTeam discovered a new Turkish Aurora offline variant that adds the .cryptoid extension to encrypted files.
13.4.19GoRansom pushed by maldocVýsledek obrázku pro ransomwareenSilo found a ransomware written in Go that is being pushed by a malicious Word document. Appears to be a research project.
13.4.19Distributor of the Reveton Police Ransomware Jailed by UK's NCARevetonA key member of a crime group behind the notorious Reveton Police Trojan that locked users out of Windows unless they paid a ransom has now found himself locked up in jail.
13.4.19How did a teenager become the UK’s biggest cyber criminal?Výsledek obrázku pro ransomwareBBC radio discusses:
Zain Qaiser made hundreds of thousands blackmailing porn users from his parents’ house.
13.4.19STOP Djvu Decryptor updatedSTOP DecryptorMichael Gillespie updated his STOP Djvu decryptor to support the offline IDs for the .grovat, .raldug, and .roland variants.
13.4.19New Extortion Email Threatens to Install WannaCry and DDoS Your NetworkVýsledek obrázku pro ransomwareA new extortion email scam campaign is underway that states that your computer was hacked and that it was discovered you were hiding your taxes. The alleged hackers then demand 2 bitcoins or they will notify the "Tax Department", DDoS your network, and then install the WannaCry ransomware.
13.4.19How to Save Ransomware Encrypted Files for DecryptionVýsledek obrázku pro ransomwareCoveware writes: When ransomware strikes and restoring from backups is not an option, a victim often feels that paying the ransom is the only option. Often, victims realize that they can indeed live without the data that has been encrypted, and are able to wait for a potential free decryption solution to be published. Given how unpredictable the release of free decryptor tools is, how should ransomware victims plan their recovery? What can they do to increase their chances of a full recovery?
13.4.19New Bitcoin666 RansomwareVýsledek obrázku pro ransomwareMalwareHunterTeam found a new ransomware that appends the .bitcoin666@cock.li.word extension to encrypted files.
13.4.19New .gate Dharma variantVýsledek obrázku pro ransomwareMichael Gillespie spotted a new Dharma variant that uses the .gate extension.
13.4.19New langolier Scarab variantVýsledek obrázku pro ransomwareAmigo-A found a new Scarab variant that appends the .langolier extension to encrypted files and drops a ransom note named HOW TO RECOVER ENCRYPTED FILES.TXT.
13.4.19New guvara and etols STOP Djvu Ransomware variantsVýsledek obrázku pro ransomwareMichael Gillespie found new variants of the STOP Djvu Ransomware that append the .guvara and .etols extensions.
13.4.19Emsisoft released a decryptor for the CryptoPokemonVýsledek obrázku pro ransomwareEmsisoft released a decryptor for the CryptoPokemon Ransomware that appends the .CRYPTOPOKEMON extension.
13.4.19New fuchsia Scarab Ransomware variantVýsledek obrázku pro ransomwareAmigo-A found a new Scarab variant that appends the .fuchsia extension and drops a ransom note named DECRYPT FILES.TXT.
13.4.19New Love Dharma variantVýsledek obrázku pro ransomwareJakub Kroustek found a new variant of the Dharma ransomware that appends the .LOVE extension.
13.4.19New Tokog Scarab Ransomware variantVýsledek obrázku pro ransomwareAmigo-A found a new Scarab variant that appends the .tokog extension and drops a ransom note named HOW TO RECOVER ENCRYPTED FILES.TXT.
13.4.19SadComputer Ransomware discoveredSadComputerMalwareHunterTeam found the SadComputer ransomware which appends the .sad extension and drops a ransom note named sadcomputer_note.txt.
13.4.19Weekly Ransomware Market Share from CovewareWeekly Ransomware Market ShareAccording to Coveware, Ryuk cases have slowed a bit, though are still a substantial portion of new cases. GandCrab v5.2 has picked up slightly in April. Phobos and Dharma continue to hold the largest share of attacks affecting enterprises.
13.4.19New browec STOP Djvu Ransomware variantsVýsledek obrázku pro ransomwareMichael Gillespie found a new variant of the STOP Djvu Ransomware that appends the .browec extension.

6.4.19

New Plant Matrix Ransomware variantVýsledek obrázku pro ransomwareStephen DeLucia discovered a new Matrix Ransomware variant that appends the .Plant extension.

6.4.19

RobLocker X discoveredRoblocker-xGrujaRS found a new ransomware called RobLocker X.

6.4.19

vxCrypter Is the First Ransomware to Delete Duplicate FilesvxCrypterThe vxCrypter Ransomware could be the first ransomware infection that not only encrypts a victim's data, but also tidy's up their computer by deleting duplicate files.

6.4.19

New York Albany Capital Hit by Ransomware AttackVýsledek obrázku pro ransomwareThe City of Albany, the capital of the U.S. state of New York, was hit by a ransomware attack on March 30, with city officials working over the weekend to respond to the incident.

6.4.19

Mira Ransomware decryptor releasedVýsledek obrázku pro ransomwareF-secure released a decryptor for the Planetary ransomware variant that appends the .Mira extension.

6.4.19

Pacman RansomwarePacman RansomwareMalwareHunterTeam found a new ransomware called.... Pacman. This ransomware prepends encrypted before the original extension.

6.4.19

Aurora decryptor releasedVýsledek obrázku pro ransomwareEmsisoft released a decryptor for the Aurora ransomware.

6.4.19

New STOP Djvu variantVýsledek obrázku pro ransomwareMichael Gillespie found a new variant of the STOP Djvu Ransomware that appends the .grovat extension to encrypted files.

6.4.19

Cyber Criminals Increasingly Target Small and Midsize BusinessesVýsledek obrázku pro ransomwareA report by Chubbs "examines the emergence of new #ransomware and #malware strains, including Emotet, Ryuk, and Credential Stuffing".

6.4.19

Norsk Hydro releases a documentary-like video on their LockerGoga cyberattackVýsledek obrázku pro ransomwareIn a unprecedented move, Norsk Hydro created a documentary-like video about the employees who discovered they were infected by LockerGoga.

6.4.19

New STOP Djvu variantVýsledek obrázku pro ransomwareMichael Gillespie found a new variant of the STOP Djvu Ransomware that appends the .roland extension to encrypted files.

6.4.19

Arizona Beverages knocked offline by ransomware attackVýsledek obrázku pro ransomwareArizona Beverages, one of the largest beverage suppliers in the U.S., is recovering after a massive ransomware attack last month, TechCrunch has learned.

6.4.19

MR.Z3B1 Jigsaw variantJigsawMalwareHunterTeam found a new Jigsaw Ransomware variant that appends the Contact onlineservices1@usa.com Hacked by Z3b1 your ID [MI0985547KE] .locked extension to encrypted files.

6.4.19

New hunt for Ransomware that appends ._CryptedVýsledek obrázku pro ransomwareMichael Gillespie is looking for a ransomware sample that appends the ._Crypted extension and drops a ransom note named _CRYPTED_README.html.

6.4.19

Seon Ransoware ver 0.2 foundSeon Ransomware ver 0.2JAMESWT found a new variant of the Seon Ransomware that brings it to "ver 0.2" and appends the .FIXT extension.

6.4.19

New ms13 Dharma variantVýsledek obrázku pro ransomwaresafety found a new variant of the Dharma ransomware that appends the .ms13 extension to encrypted files.

6.4.19

New Xwo Web Scanner Helps MongoLock Ransomware Find VictimsVýsledek obrázku pro ransomwareCode and infrastructure from two known malware families have been observed with a new threat named Xwo, which helps operators of the MongoLock ransomware discover unprotected web services reachable over the internet.

6.4.19

Planetary Ransomware decryptor releasedVýsledek obrázku pro ransomwareEmsisoft has released a new decryptor for the Planetary Ransomware. This decryptor will target ransomware variants that append the .mira, .yum, .Neptune, or .Pluto extension.

6.4.19

New ransomware huntVýsledek obrázku pro ransomwareMichael Gillespie is looking for ransomware samples that append the .bmps@tutanota.com.major or .bmps@tutanota.com.major extension.

6.4.19

New STOP Djvu variantVýsledek obrázku pro ransomwareMichael Gillespie found a new variant of the STOP Djvu Ransomware that appends the .refols extension to encrypted files.

6.4.19

FIN6 Group Diversifies Activity, Uses LockerGoga and Ryuk RansomwareVýsledek obrázku pro ransomwareFIN6 cybercrime group has taken a step toward increased monetization of their intrusions and added ransomware to its portfolio, choosing LockerGoga and Ryuk file encryption malware for the extortion jobs.

6.4.19

New Phobos Ransomware variantVýsledek obrázku pro ransomwareMichael Gillespie found a new Phobos variant that appends the .phoenix extension.
6.4.19New .carcn Dharma variantVýsledek obrázku pro ransomwareJakub Kroustek found a new variant of the Dharma ransomware that appends the .carcn extension.

0  1  2