Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Friday, January 06, 2023

Ransomware decryption tool: Victims of MegaCortex can now unlock their files for free

Good news! Bravo! Next time don't despair! 😊

Ransomware decryption tool: Victims of MegaCortex can now unlock their files for free | ZDNET Joint venture by cybersecurity researchers and law enforcement agencies provides a free decryption tool for ransomware that has hit victims around the world.

Wednesday, September 07, 2022

Stealthy Linux malware Shikitega starts off small but gradually takes control

As a Linux user should I be concerned? Sounds quite scary and sophisticated! 

Until know, I thought that Linux was much less vulnerable than Windows especially when you operate Linux primarily in user mode only!

The article is unfortunately kind of unspecific about what Linux installations are  exactly affected: 
1) Administrator mode v. user mode
2) Server vs. desktop
So much for sloppy journalism although ZDNET is a technology oriented publication.

"A stealthy new form of malware is targeting Linux systems in attacks that can take full control of infected devices – and it is using this access to install crypto-mining malware. 
Dubbed Shikitega, the malware targets endpoints and Internet of Things devices that run on Linux operating systems and has been detailed by cybersecurity researchers at AT&T Alien Labs. ...
The malware is delivered in a multi-stage infection chain, where each module responds to commands from the previous part of the payload and downloads and executes the next one.
By downloading the payload bit by bit – starting with a module that is just a few hundred bytes – Shikitega can avoid being uncovered by anti-virus software. It also uses a polymorphic encoder to make it more difficult to detect. ...
The initial method of infection is still unknown, but the malware gradually downloads more and more modules to provide full functionality, starting with the initial dropper, then going through several stages – including downloading Mettle, a Metasploit offensive security tool, which allows the attacker to deploy a wide range of attacks. ..."

From the AT&T cybersecurity blog:
"... With a rise of nearly 650% in malware and ransomware for Linux this year, reaching an all-time high in the first half year of 2022, threat actors find servers, endpoints and IoT devices based on Linux operating systems more and more valuable and find new ways to deliver their malicious payloads. ...
To achieve persistence, the malware will download and execute a total of 5 shell scripts. It persists in the system by setting 4 crontabs, two for the current logged in user and the other two for the user root. ..."

This stealthy Linux malware starts off small but gradually takes control | ZDNET 'Sophisticated' Shikitega malware secretly exploits known vulnerabilities in Linux.




Monday, July 04, 2022

Why are ransom attacks using encryption still so successful?

Theoretically, if you keep separate and secure copies of data and divide/separate data appropriately, ransomware attacks ought to fail or be less dangerous? 

How often do you make copies of the data and how to clean these copies from any malware? How fast can you restore the data after a successful ransomware attack?

Regular and frequent data backups have been around for several decades.

I suspect, e.g. Google or Amazon with their data cloud services are already doing a great job to prevent ransomware attacks, but how do they do it? Or were these companies hiding successful cyber attacks on their cloud data storage?

What am I missing?

Tuesday, June 14, 2022

The unrelenting threat of ransomware and cyber attacks is pushing cybersecurity workers to quit

Is this hype or a serious concern? Probably, a bit of both! Staffing shortages may play a role and so forth.

"Security researchers have warned of "increasing and unsustainable stress levels" in the cybersecurity workforce resulting from persistent ransomware threats and looming, large-scale attacks, which are pushing security professionals towards abandoning the industry altogether.

A report by cybersecurity company Deep Instinct found that 46% of senior and executive-level cybersecurity professionals have considered quitting the industry due to stress. ..."

The unrelenting threat of ransomware is pushing cybersecurity workers to quit | ZDNet Cybersecurity professionals face immense pressure to keep businesses secure, and this stress is leading many to consider leaving the industry altogether.

Thursday, April 28, 2022

U.S. government offers $10 million bounty for Sandworm, the Russian hackers blamed for destructive cyberattacks

Somebody must be reading my blog posts. Just kidding! 

However, about two weeks ago I complained here about the lack of effective law enforcement against e.g. malware and ransomware and cyber attacks and possible state actors behind it.

Let the hunt begin! Bounty hunters to the rescue!

"The U.S. government has stepped up its hunt for six Russian intelligence officers, best known as the state-backed hacking group dubbed “Sandworm,” by offering a $10 million bounty for information that identifies or locates its members.
The Sandworm hackers — who work for a division of Russia’s GRU, the country’s military intelligence division — are known for launching damaging and destructive cyberattacks against critical infrastructure, including food supplies and the energy sector. ..."

US offers bounty for Sandworm, the Russian hackers blamed for destructive cyberattacks | TechCrunch

Thursday, April 14, 2022

Ransomware: These two gangs are behind half of all attacks

Apparently, the perpetrators are recognized and monitored over time. Only a few of them cause most of the damage. However the article below is totally mute about any law enforcement action and where these hackers are located.

That so few of these criminals are indicted is a great concern! If a significant number of these criminals are state actors or protected by certain countries, we should know more about it.

"Over half of all ransomware attacks reported during the first three months of this year are the work of just two cyber criminal outfits. 

According to analysis of recorded ransomware attacks between January and March 2022 by cybersecurity researchers at Digital Shadows, LockBit 2.0 and Conti were the two most active ransomware gangs during the three-month reporting period, accounting for 58% of all incidents. 

And of the two, LockBit is by far the most prolific, accounting for 38% of ransomware attacks. That's almost twice the number of recorded attacks by the Conti ransomware group, which accounted for 20% of campaigns in the same period. ..."

Ransomware: These two gangs are behind half of all attacks | ZDNet Two particular ransomware groups have been very busy- but there are other ransomware threats out there too.