Security News > 2024 > June > Ratel RAT targets outdated Android phones in ransomware attacks
An open-source Android malware named 'Ratel RAT' is widely deployed by multiple cybercriminals to attack outdated devices, some aiming to lock them down with a ransomware module that demands payment on Telegram.
This proves Ratel RAT is an effective attack tool against an array of different Android implementations.
The ransomware module in Rafel RAT is designed to execute extortion schemes by taking control of the victim's device and encrypting their files using a pre-defined AES key.
Check Point's researchers observed several ransomware operations involving Rafel RAT, including an attack from Iran that performed reconnaissance using Ratel RAT's other capabilities before running the encryption module.
Linux version of RansomHub ransomware targets VMware ESXi VMs. New Fog ransomware targets US education sector via breached VPNs. Over 90 malicious Android apps with 5.5M installs found on Google Play.
Finland warns of Android malware attacks breaching bank accounts.
News URL
Related news
- Surge in Magniber ransomware attacks impact home users worldwide (source)
- Keytronic reports losses of over $17 million after ransomware attack (source)
- Google fixes Android kernel zero-day exploited in targeted attacks (source)
- Ransomware gang targets IT workers with new RAT masquerading as IP scanner (source)
- UK health services call-handling vendor faces $7.7M fine over 2022 ransomware attack (source)
- McLaren hospitals disruption linked to INC ransomware attack (source)
- Six ransomware gangs behind over 50% of 2024 attacks (source)
- CISA warns of Jenkins RCE bug exploited in ransomware attacks (source)
- CISA Warns of Critical Jenkins Vulnerability Exploited in Ransomware Attacks (source)
- Most Ransomware Attacks Occur When Security Staff Are Asleep, Study Finds (source)