News

Emotet is Back Again Using New Lure Text in the Documents

Delaware, USA – January 14, 2020 – Emotet malware finished its winter vacation, and immediately after returning to service launched spam campaigns targeting 80+ countries. This time, the Emotet operators went on vacation shortly before Christmas, on December 21, but unlike the summer break, the command-and-control infrastructure continued functioning. Three weeks later, on Monday morning, […]

Albany International Airport Suffers Sodinokibi Attack

Delaware, USA – January 13, 2020 – Albany International Airport’s systems suffered a ransomware attack on Christmas and the airport authority decided to pay the ransom to restore data on the airport’s servers and its backup servers. Sodinokibi (aka REvil) affiliates compromised managed service provider, LogicalNet, from whose network the airport systems were infected. The […]

TrickBot Now Delivers PowerTrick Post-Exploitation Toolkit

Delaware, USA – January 10, 2020 – TrickBot authors continue to develop post-exploitation tools to spread laterally across networks of high-profile targets. Just a month ago, experts discovered Anchor malware which is used as an attack framework for enterprise environments and to which TrickBot gang provides access to both ordinary cybercriminals and state-sponsored cyberespionage groups. […]

Iranian Hackers Deploy New Data Wiping Malware – Dustman

Delaware, USA – January 9, 2020 – Iranian APT group used the new data wiper to attack computer systems of the Bahraini national oil company Bapco. According to the National Cybersecurity Authority of Saudi Arabia, the cyberattack was carried out on December 29, but the adversaries managed to infect only part of the Bapco computer […]

Predator the Thief Gets Fileless Features in New Year Update

Delaware, USA – January 8, 2020 – The increasingly popular infostealer on the eve of the new year was updated to version 3.3.4 and received additional anti-analysis and fileless capabilities. Predator the Thief has been used by attackers since the summer of 2018. The malware was capable of stealing credentials and browser data, taking screenshots […]

Clop Ransomware Can Terminate Hundreds of Windows Processes

Delaware, USA – January 6, 2020 – Clop ransomware was first discovered last February and this ‘spin-off’ of the CryptoMix ransomware was originally designed to attack individuals. Just a month later, the attackers turned Clop into a tool for attacks on corporate systems: before encrypting files, the malware started to terminate a number of services […]

US Restaurant Chain Landry’s Discloses Data Breach

Delaware, USA – January 3, 2020 – The popular US restaurant chain notifies its customers of credit card stealing malware discovered in the company’s network. A few years ago, Landry’s already suffered a similar incident, after which the company implemented a payment processing solution that uses end-to-end encryption technology, which significantly reduced the scale of […]

Microsoft Takes Control of 50 Domains Used by Thallium

Delaware, USA – January 2, 2020 – Microsoft got a court order allowing them to take down the domains used by the cyberespionage group Thallium. The group is active since 2012 and linked with the North Korean government, its operations are closely related to the activities of the Lazarus group. Thallium primarily attacks organizations in […]

Cybercriminals Exploit CVE-2019-11510 to Breach Telecoms and Financial Companies

Delaware, USA – December 30, 2019 – Financial and telecommunications companies in Eastern Europe and Central Asia were breached by the undefined threat actor in a series of cyberattacks. According to Kaspersky Lab, the cybercriminals are interested in huge sums, they attempted to steal several million dollars from each financial organization, and in the networks […]

Entercom Communications Corporation is Hit Again

Delaware, USA – December 26, 2019 – Over the past few months, Entercom has become the second time the target of a cyberattack: in September, the radio network suffered a ransomware attack and attackers demanded $500,000 for decrypting the files. As a result of that attack, the radio network lost about $1.4 million and spent […]