Security News > 2020 > June > Hakbit Ransomware Attack Uses GuLoader, Malicious Microsoft Excel Attachments

Hakbit Ransomware Attack Uses GuLoader, Malicious Microsoft Excel Attachments
2020-06-23 14:39

A ransomware campaign, dubbed Hakbit, is targeting mid-level employees across Austria, Switzerland and Germany with malicious Excel attachments delivered via the popular email provider GMX. The spear-phishing based campaign is low volume and so far targeted the pharmaceutical, legal, financial, business service, retail, and healthcare sectors.

In this campaign, when GuLoader runs, it then downloads and executes Hakbit, a known ransomware that encrypts files using AES-256 encryption.

Hakbit is believed to be linked to the Thanos ransomware - In a recent analysis of the Thanos ransomware, Recorded Future researchers assessed "With high confidence" that ransomware samples tracked as Hakbit are built using the Thanos ransomware builder developed by Nosophoros.

Regardless, researchers say that the campaign is indivitive of several "Consistent" low-volume and often boutique ransomware campaigns that have hit victims since January 2020.

"Hakbit exemplifies a people-centric ransomware campaign tailored to a specific audience, role, organization, and in the user's native language."


News URL

https://threatpost.com/hackbit-ransomware-attack-uses-guloader-malicious-microsoft-excel-attachments/156826/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 723 805 4705 4715 3646 13871