The Week in Ransomware - June 17th 2022 - Have I Been Ransomed?

Gandalf_The_Grey

Level 76
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,596
Ransomware operations are constantly evolving their tactics to pressure victims to pay. For example, this week, we saw a new extortion tactic come into play with the creation of dedicated websites to extort victims with searchable data.

The new extortion tactic was introduced by the ALPHV gang, aka BlackCat, who created a searchable, clearweb site that contained the stolen data for employees and hotel guests for a particular victim.

Using this website, employees of the company could search for their names to see if their data was stolen, including Social Security Numbers, phone numbers, etc.

Other interesting news this week was learning that AvosLocker and Ceber2021 are using recent Atlassian Confluence exploits to gain initial access to corporate networks. We also learned that Hello XD ransomware is dropping a 'MicroBackdoor' on devices while encrypting.

Sadly, we also learned of some attacks this week, with RansomHouse extorting Africa's largest supermarket chain, Shoprite, and a California school district paying a 400k ransom to Quantum.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top