In honor of Thomas Paine and other Founders & Immigrants. In memory of my daddy Horst Bingel and my mom Irma Bingel
Friday, January 06, 2023
Ransomware decryption tool: Victims of MegaCortex can now unlock their files for free
Wednesday, September 07, 2022
Stealthy Linux malware Shikitega starts off small but gradually takes control
2) Server vs. desktop
The malware is delivered in a multi-stage infection chain, where each module responds to commands from the previous part of the payload and downloads and executes the next one.
By downloading the payload bit by bit – starting with a module that is just a few hundred bytes – Shikitega can avoid being uncovered by anti-virus software. It also uses a polymorphic encoder to make it more difficult to detect. ...
The initial method of infection is still unknown, but the malware gradually downloads more and more modules to provide full functionality, starting with the initial dropper, then going through several stages – including downloading Mettle, a Metasploit offensive security tool, which allows the attacker to deploy a wide range of attacks. ..."
To achieve persistence, the malware will download and execute a total of 5 shell scripts. It persists in the system by setting 4 crontabs, two for the current logged in user and the other two for the user root. ..."
Monday, July 04, 2022
Why are ransom attacks using encryption still so successful?
Theoretically, if you keep separate and secure copies of data and divide/separate data appropriately, ransomware attacks ought to fail or be less dangerous?
How often do you make copies of the data and how to clean these copies from any malware? How fast can you restore the data after a successful ransomware attack?
Regular and frequent data backups have been around for several decades.
I suspect, e.g. Google or Amazon with their data cloud services are already doing a great job to prevent ransomware attacks, but how do they do it? Or were these companies hiding successful cyber attacks on their cloud data storage?
What am I missing?