Security News

Security expert weighs in on cybersecurity regulation and ransomware attacks of US cities
2020-05-26 20:00

Bryson Bort, founder and CEO of cybersecurity company SCYTHE, fears "death by a thousand paper cuts" more than than a digital apocalypse. He also shares his views on how well cyber-deterrence works.

The ransomware that attacks you from inside a virtual machine
2020-05-22 16:07

To ensure their 49 kB Ragnar Locker ransomware ran undisturbed, the crooks behind the attack bought along a 280 MB Windows XP virtual machine to run it in. VirtualBox is hypervisor software that can run and administer one or more virtual guest computers inside a host computer.

Forget BYOD, this is BYOVM: Ransomware tries to evade antivirus by hiding in a virtual machine on infected systems
2020-05-22 16:00

With antivirus tools increasingly wise to common infection tricks, one group of extortionists has taken the unusual step of stashing their ransomware inside its own virtual machine. According to Vikas Singh, Gabor Szappanos, and Mark Loman at Sophos, criminals have slotted the file-scrambling Ragnar Locker nasty into a virtual machine running a variant of Windows XP, called MicroXP. Then, once the crooks have infiltrated a victim's network and gained administrative access - typically via a weak RDP box or through a compromised managed services provider - they download the VM, along with Oracle's VirtualBox hypervisor to run it, on each machine they can get into.

Forget BYOD, this is BYOVM: Ransomware tries to evade antivirus by hiding in a virtual machine on infected systems
2020-05-22 16:00

With antivirus tools increasingly wise to common infection tricks, one group of extortionists has taken the unusual step of stashing their ransomware inside its own virtual machine. According to Vikas Singh, Gabor Szappanos, and Mark Loman at Sophos, criminals have slotted the file-scrambling Ragnar Locker nasty into a virtual machine running a variant of Windows XP, called MicroXP. Then, once the crooks have infiltrated a victim's network and gained administrative access - typically via a weak RDP box or through a compromised managed services provider - they download the VM, along with Oracle's VirtualBox hypervisor to run it, on each machine they can get into.

Ragnar Locker Ransomware Uses Virtual Machines for Evasion
2020-05-22 14:06

The Ragnar Locker ransomware has been deploying a full virtual machine to ensure that it can evade detection, Sophos reveals. As part of a recently observed attack, the ransomware was executed inside an Oracle VirtualBox Windows XP virtual machine.

Hackers Attempted to Deploy Ransomware in Attacks Targeting Sophos Firewalls
2020-05-22 12:14

Malicious actors targeting a zero-day vulnerability in Sophos XG Firewall appliances last month attempted to deploy ransomware after Sophos started taking measures to neutralize the attack. One of the files deployed by the attackers would act as a "Dead man switch," to launch a ransomware attack when a specific file would be deleted on unpatched firewalls during a reboot or power-cycle, the security company reveals.

NetWalker Ransomware Gang Hunts for Top-Notch Affiliates
2020-05-20 17:37

The NetWalker ransomware - the scourge behind one of the recent Toll Group attacks - has transitioned to a ransomware-as-a-service model, and its operators are placing a heavy emphasis on targeting and attracting technically advanced affiliates, according to researchers. "NetWalker now claims a singular preference for network infiltration, which is novel to the Russian-speaking ransomware community," explained the researchers, who added that in the advertisements on underground forums for the RaaS offering, the NetWalker group explicitly says that it prefers affiliates "Who prioritize quality, not quantity" and stating that they have an interest "Only in experienced, Russian-speaking network intruders - not spammers - with a preference for immediate, consistent work."

Ransomware has gone nuclear: To avoid any fallout yourself, tune in online this month to hear from KnowBe4
2020-05-20 16:00

We've been hearing about ransomware for years now. In the past few months, ransomware has gone nuclear.

Ransomware has gone nuclear: To avoid any fallout yourself, tune in online this month to hear from KnowBe4
2020-05-20 16:00

We've been hearing about ransomware for years now. In the past few months, ransomware has gone nuclear.

Ransomware Gang Arrested for Spreading Locky to Hospitals
2020-05-18 21:20

A cybercriminal gang have been arrested for spreading the Locky ransomware among hospitals, among other crimes. These attacks were directed against several public institutions both in Bucharest and elsewhere, and more were planned.