Security News > 2022 > July > New 0mega ransomware targets businesses in double-extortion attacks

A new ransomware operation named '0mega' targets organizations worldwide in double-extortion attacks and demands millions of dollars in ransoms.
0mega is a new ransomware operation launched in May 2022 and has attacked numerous victims since then.
A ransomware sample for the 0mega operation hasn't yet been found, therefore there's not much information on how files are encrypted.
These ransom notes are customized per victim, usually containing the company name and describing the different types of data stolen in attacks.
These ransom notes include a link to a Tor payment negotiation site with a "Support" chat that victims can use to contact the ransomware gang.
Like almost all enterprise-targeting ransomware operations, 0mega runs a dedicated data leak site that the threat actors use to publish stolen data if a ransom is not paid.
News URL
Related news
- Ransomware gangs exploit Paragon Partition Manager bug in BYOVD attacks (source)
- Hackers Exploit Paragon Partition Manager Driver Vulnerability in Ransomware Attacks (source)
- Hunters International ransomware claims attack on Tata Technologies (source)
- Toronto Zoo shares update on last year's ransomware attack (source)
- Ransomware gang creates tool to automate VPN brute-force attacks (source)
- SANS Institute Warns of Novel Cloud-Native Ransomware Attacks (source)
- ⚡ THN Weekly Recap: Router Hacks, PyPI Attacks, New Ransomware Decryptor, and More (source)
- BlackLock ransomware claims nearly 50 attacks in two months (source)
- TechRepublic EXCLUSIVE: New Ransomware Attacks are Getting More Personal as Hackers ‘Apply Psychological Pressure” (source)
- Texas State Bar warns of data breach after INC ransomware claims attack (source)