Two Waves Of Cerber Ransomware Hitting U.S., UK

_CyberGhosT_

Level 53
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
Doug Olenick Doug Olenick, Online Editor
June 21, 2016
Check Point tracks two waves of Cerber ransomware hitting U.S., UK
The two spikes took place in between April 4-18 and then again between May 17-30.
The two spikes took place in between April 4-18 and then again between May 17-30.
Updated: A team of Check Point researchers have tracked two large waves of attacks using Cerber ransomware in the last few months with more spikes in the number of incidents expected.

While Cerber has been steadily used since earlier this year, two spikes took place in between April 4-18 and then again between May 17-30, Check Point reported. In each case the majority of attacks hit targets in the United States, 41 percent; Turkey, 15 percent; and the U.K., nine percent. Seven other nations also experienced an uptick in the number of attacks during these two periods, but at a much lower rate.

"We have no doubt that we will continue to see spikes in Cerber's activity," the report stated.

Check Point estimates the number of attacks that have taken place at about 600..

The research firm also detailed its reasoning behind why the attack took place in waves.

“It allows the attackers to control their operation closely for a short period of time, without the need for constant management, which can require large resources. Second, striking in waves enables the attackers to make necessary code changes, improving their malware and evasion techniques between bursts. Since static security solutions focus on signatures of the malware, attackers can morph their malware until it is unrecognized by these signatures, rendering them useless. Lastly, this pattern can also be caused by changes in the distribution infrastructure,” said Gadi Naveh, a threat prevention researcher with Check Point to SCMagazine.com via email.

One change that does coincide with these events Cerber has recently been spotted being advertised as a ransomware as a service on several Russian dark web forums.

Updated with Check Points estimate on the number of attacks.
0
RELATED ARTICLES
Talking ransomware gets more bite, Cerber now has 'hash factory' and DDoS capabilities
Variant of Cerber ransomware features bot capabilities that could launch DDoS attacks
Cerber ransomware on sale in Russian darknet with new scripting features
Attacker obtains credentials of nearly 100K users of Cerberus app
 

_CyberGhosT_

Level 53
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
I never can get the news I find to paste the images for some reason.
Anyone have any tips feel free to PM me.
PeAcE
 
  • Like
Reactions: Deleted member 2913

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top