Security News > 2020 > June > Hakbit Ransomware Attack Uses GuLoader, Malicious Microsoft Excel Attachments
A ransomware campaign, dubbed Hakbit, is targeting mid-level employees across Austria, Switzerland and Germany with malicious Excel attachments delivered via the popular email provider GMX. The spear-phishing based campaign is low volume and so far targeted the pharmaceutical, legal, financial, business service, retail, and healthcare sectors.
In this campaign, when GuLoader runs, it then downloads and executes Hakbit, a known ransomware that encrypts files using AES-256 encryption.
Hakbit is believed to be linked to the Thanos ransomware - In a recent analysis of the Thanos ransomware, Recorded Future researchers assessed "With high confidence" that ransomware samples tracked as Hakbit are built using the Thanos ransomware builder developed by Nosophoros.
Regardless, researchers say that the campaign is indivitive of several "Consistent" low-volume and often boutique ransomware campaigns that have hit victims since January 2020.
"Hakbit exemplifies a people-centric ransomware campaign tailored to a specific audience, role, organization, and in the user's native language."
News URL
Related news
- Microsoft: Ransomware Attacks Growing More Dangerous, Complex (source)
- Ransomware attackers hop from on-premises systems to cloud to compromise Microsoft 365 accounts (source)
- JPCERT shares Windows Event Log tips to detect ransomware attacks (source)
- Ransomware attack forces UMC Health System to divert some patients (source)
- DOJ, Microsoft seize 107 domains used in Russia's Star Blizzard phishing attacks (source)
- Microsoft and DOJ disrupt Russian FSB hackers' attack infrastructure (source)
- Microsoft issues 117 patches – some for flaws already under attack (source)
- Microsoft Detects Growing Use of File Hosting Services in Business Email Compromise Attacks (source)
- Underground ransomware claims attack on Casio, leaks stolen data (source)
- Casio confirms customer data stolen in a ransomware attack (source)