Security News > 2020 > June > Hakbit Ransomware Attack Uses GuLoader, Malicious Microsoft Excel Attachments

A ransomware campaign, dubbed Hakbit, is targeting mid-level employees across Austria, Switzerland and Germany with malicious Excel attachments delivered via the popular email provider GMX. The spear-phishing based campaign is low volume and so far targeted the pharmaceutical, legal, financial, business service, retail, and healthcare sectors.
In this campaign, when GuLoader runs, it then downloads and executes Hakbit, a known ransomware that encrypts files using AES-256 encryption.
Hakbit is believed to be linked to the Thanos ransomware - In a recent analysis of the Thanos ransomware, Recorded Future researchers assessed "With high confidence" that ransomware samples tracked as Hakbit are built using the Thanos ransomware builder developed by Nosophoros.
Regardless, researchers say that the campaign is indivitive of several "Consistent" low-volume and often boutique ransomware campaigns that have hit victims since January 2020.
"Hakbit exemplifies a people-centric ransomware campaign tailored to a specific audience, role, organization, and in the user's native language."
News URL
Related news
- US indicts Black Kingdom ransomware admin for Microsoft Exchange attacks (source)
- Hidden Threats: How Microsoft 365 Backups Store Risks for Future Attacks (source)
- Texas State Bar warns of data breach after INC ransomware claims attack (source)
- Microsoft Warns of Tax-Themed Email Attacks Using PDFs and QR Codes to Deliver Malware (source)
- Microsoft: Windows CLFS zero-day exploited by ransomware gang (source)
- Microsoft: Windows CLFS Vulnerability Could Lead to ‘Widespread Deployment and Detonation of Ransomware’ (source)
- Sensata Technologies hit by ransomware attack impacting operations (source)
- Ransomware attack cost IKEA operator in Eastern Europe $23 million (source)
- Microsoft Defender will isolate undiscovered endpoints to block attacks (source)
- Kidney dialysis firm DaVita hit by weekend ransomware attack (source)