Security News > 2021 > August > Vice Society ransomware joins ongoing PrintNightmare attacks
The Vice Society ransomware gang is now also actively exploiting Windows print spooler PrintNightmare vulnerability for lateral movement through their victims' networks.
PrintNightmare added to Vice Society's arsenal.
Recently, Cisco Talos researchers observed Vice Society ransomware operators deploying a malicious Dynamic-link library to exploit two PrintNightmare flaws.
Vice Society ransomware encrypts both Windows and Linux systems using OpenSSL, as ransomware expert Michael Gillespie found in mid-June when the first samples surfaced.
Vice Society is actively exploiting PrintNightmare to spread laterally across victim networks.
To defend against these ongoing attacks, you should apply any available PrintNightmare patches as soon as possible and implement the workarounds provided by Microsoft for the CVE-2021-36958 zero-day to remove the attack vector.
News URL
Related news
- BianLian Threat Actors Exploiting JetBrains TeamCity Flaws in Ransomware Attacks (source)
- JetBrains is still mad at Rapid7 for the ransomware attacks on its customers (source)
- Stanford: Data of 27,000 people stolen in September ransomware attack (source)
- Nissan confirms ransomware attack exposed data of 100,000 people (source)
- TeamCity Flaw Leads to Surge in Ransomware, Cryptomining, and RAT Attacks (source)
- What the Latest Ransomware Attacks Teach About Defending Networks (source)
- Lessons from a Ransomware Attack against the British Library (source)
- Jackson County in state of emergency after ransomware attack (source)
- Panera Bread week-long IT outage caused by ransomware attack (source)
- The Week in Ransomware - April 5th 2024 - Virtual Machines under Attack (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-08-12 | CVE-2021-36958 | Unspecified vulnerability in Microsoft Windows <p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. | 7.8 |