Tag: ransomware
-
New HybridPetya Ransomware Strikes Before Boot
Tags: ransomwareHybridPetya is ransomware that bypasses UEFI Secure Boot to encrypt systems before they start. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/new-hybridpetya-ransomware-strikes-before-boot/
-
Sophos Threat-Hunter-Analyse: Neue Ransomware-Gruppe sorgt für Aufsehen
Darüber hinaus umging die Gruppe eine EDR-Lösung mithilfe der BYOVD-Technik (Bring Your Own Vulnerable Driver). Konkret setzten sie einen anfälligen Baidu-Antivirus-Treiber (umbenannt in googleApiUtil64.sys) ein, der das Beenden beliebiger Prozesse erlaubt (CVE-2024-51324) und damit auch den Stopp des EDR-Agenten. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/sophos-threat-hunter-analyse-neue-ransomware-gruppe-sorgt-fuer-aufsehen/a42049/
-
Threat-Hunter-Analyse: Neue Ransomware-Gruppe mischt die Szene auf
Forscher der Sophos Counter Threat Unit (CTU) haben eine Bedrohungsgruppe, die sich selbst als Warlock Group bezeichnet, näher unter die Lupe genommen. Die Cyberkriminellen, die von den Forschern als GOLD SALEM verfolgt werden, kompromittieren seit März 2025 Netzwerke und setzen dabei ihre ‘Warlock-Ransomware” ein. Opfer reichen von kleinen kommerziellen Organisationen bis zu multinationalen Konzernen Die…
-
Ransomware HybridPetya hebelt UEFI Secure Boot aus
UEFI-Nachahmung von Petya/NotPetya unter Ausnutzung von CVE-2024-7344 auf VirusTotal entdeckt First seen on welivesecurity.com Jump to article: www.welivesecurity.com/de/eset-research/ransomware-hybridpetya-hebelt-uefi-secure-boot-aus/
-
NCC: How RaaS team-ups help Scattered Spider enhance its attacks
Scattered Spider’s alliances with ransomware-as-a-service gangs act as a force multiplier for the scope, and number, of its cyber attacks, according to NCC Group analysts First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366631376/NCC-How-RaaS-team-ups-help-Scattered-Spider-enhance-its-attacks
-
Lehren aus dem HoyaAngriff – Warum viele Krisenpläne in der Industrie scheitern
First seen on security-insider.de Jump to article: www.security-insider.de/krisenplaene-industrie-ransomware-a-1755523fd1fb3e591e711674b1899e4d/
-
You May Have to Wait a Little Longer for That Jaguar in the UK as Cyberattack Continues to Hamper Production
Jaguar Land Rover’s prolonged plant shutdown after a ransomware attack by Scattered Lapsus$ Hunters highlights the urgent need for cyber resilience. Experts stress leadership, supply chain security, and cultural commitment to cybersecurity as key to surviving modern attacks. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/09/you-may-have-to-wait-a-little-longer-for-that-jaguar-in-the-uk-as-cyberattack-continues-to-hamper-production/
-
Scattered Spider Tied to Fresh Attacks on Financial Services
Recent, Targeted Attacks Suggest Undercut Group’s Claimed ‘Going Dark’ Retirement. Elements of the notorious ransomware collective lately calling itself Scattered Lapsus$ Hunters appear to be targeting fresh victims, including a U.S. banking organization if not the sector at large, despite a member of the group claiming it would be going dark and retiring. First seen…
-
Fifteen Ransomware Gangs “Retire,” Future Unclear
Fifteen ransomware groups have claimed shutdown on BreachForums; experts warn of rebrands and copycats First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fifteen-ransomware-gangs-retire/
-
Schools are getting better at navigating ransomware attacks, Sophos finds
In 2025, 67% of global lower education providers said they stopped an attack before their stolen data was encrypted, the cybersecurity company reported. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/schools-ransomware-attacks-sophos/760231/
-
Emerging Yurei Ransomware Claims First Victims
The cybercrime group, named after Japanese ghosts but believed to be from Morocco, uses a modified version of the Prince-Ransomware binary that includes a flaw allowing for partial data recovery. However, an extortion threat remains. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/emerging-yurei-ransomware-claims-first-victims
-
‘HybridPetya’ Ransomware Bypasses Secure Boot
The malware, which has traits of Petya ransomware and the infamous NotPetya wiper, is designed to target UEFI-based systems, according to researchers. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/hybridpetya-ransomware-bypasses-secure-boot
-
Ransomware attackers used incorrectly stored recovery codes to disable EDR agents
All target organizations are different, but ransomware attackers are highly adaptive and appreciate and will exploit any mistake you make. The latest Akira … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/09/16/akira-ransomware-disable-edr/
-
Ransomware attackers used incorrectly stored recovery codes to disable EDR agents
All target organizations are different, but ransomware attackers are highly adaptive and appreciate and will exploit any mistake you make. The latest Akira … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/09/16/akira-ransomware-disable-edr/
-
Ukrainian Fugitive Added to EU Most Wanted List for LockerGoga Ransomware
Ukrainian fugitive Volodymyr Tymoshchuk, linked to LockerGoga ransomware, has been added to the EU Most Wanted list as global authorities pursue him. First seen on hackread.com Jump to article: hackread.com/lockergoga-ransomware-eu-most-wanted-list-doj-reward/
-
HybridPetya-Ransomware knackt Windows Secure Boot
Die Ransomware HybridPetya nutzt eine bereits gepatchte Microsoft-Lücke, um die UEFI Secure Boot-Funktion auszuhebeln.Forscher des Cybersicherheitsunternehmens ESET haben eine neue Ransomware namens HybridPetya aufgespürt, die der berüchtigten Petya- und NotPetya-Malware ähnelt. Wie ihre Vorgänger zielt die Schadsoftware auf die Master File Table (MFT) ab eine zentrale Datenbank auf NTFS-Partitionen, die alle Dateien und Verzeichnisse katalogisiert.Im…
-
HybridPetya-Ransomware knackt Windows Secure Boot
Die Ransomware HybridPetya nutzt eine bereits gepatchte Microsoft-Lücke, um die UEFI Secure Boot-Funktion auszuhebeln.Forscher des Cybersicherheitsunternehmens ESET haben eine neue Ransomware namens HybridPetya aufgespürt, die der berüchtigten Petya- und NotPetya-Malware ähnelt. Wie ihre Vorgänger zielt die Schadsoftware auf die Master File Table (MFT) ab eine zentrale Datenbank auf NTFS-Partitionen, die alle Dateien und Verzeichnisse katalogisiert.Im…
-
SmokeLoader Employs Optional Plugins to Steal Data and Launch DoS Attacks
Active since 2011, SmokeLoader (also known as Smoke or Dofoil) has cemented its reputation as a versatile malware loader engineered to deliver second-stage payloads, including trojans, ransomware, and information stealers. Over the years, it has evolved to evade detection and optimize payload delivery, extending its reach through an extensible plugin framework capable of credential harvesting,…
-
KillSec Ransomware Hits Brazilian Healthcare Software Provider
The ransomware gang breached a major element of the healthcare technology supply chain and stole sensitive patient data, according to researchers. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/killsec-ransomware-brazil-healthcare-software-provider
-
Uvalde school district says ransomware attack forcing closure until Thursday
Public schools will be closed for several days in Uvalde, Texas, after a ransomware attack affected access to crucial systems such as phones, camera monitoring, visitor management and more. First seen on therecord.media Jump to article: therecord.media/uvalde-texas-school-district-temporarily-closing-ransomware
-
HybridPetya Mimics NotPetya, Adds UEFI Compromise
Tags: ransomwareHybridPetya ransomware mimics Petya/NotPetya, with an added UEFI bootkit and Secure Boot bypass First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hybridpetya-mimics-notpetya-uefi/
-
Scattered Spider’s ‘retirement’ announcement: genuine exit or elaborate smokescreen?
Tags: ai, breach, crowdstrike, cybersecurity, data, data-breach, disinformation, google, group, hacking, infrastructure, international, law, mandiant, password, ransomware, tactics, threatLaw enforcement pressure: real but limited impact: The letter explicitly acknowledged the mounting international pressure that supposedly drove their decision.”We want to share a thought for the eight people that have been raided or arrested in relations to these campaigns, Scattered Spider and/or ShinyHunters groups since beginning on April 2024 and thereafter 2025, and especially…
-
New ransomware Yurei adopts open-source tools for double-extortion campaigns
Tags: access, attack, authentication, backup, breach, ciso, cloud, control, data, edr, extortion, flaw, intelligence, Internet, mfa, network, open-source, phishing, powershell, ransomware, resilience, risk, service, switch, threat, tool, windowsBigger risks beyond downtime: The double-extortion ransomware appears to be an early version, as it has loopholes. Ransomware often targets and deletes shadow copies to block victims from using Windows’ built-in recovery options. But Yurei did not delete the shadow copies, which, if enabled, can allow the victim to restore their files to a previous…
-
Scattered Spider’s ‘retirement’ announcement: genuine exit or elaborate smokescreen?
Tags: ai, breach, crowdstrike, cybersecurity, data, data-breach, disinformation, google, group, hacking, infrastructure, international, law, mandiant, password, ransomware, tactics, threatLaw enforcement pressure: real but limited impact: The letter explicitly acknowledged the mounting international pressure that supposedly drove their decision.”We want to share a thought for the eight people that have been raided or arrested in relations to these campaigns, Scattered Spider and/or ShinyHunters groups since beginning on April 2024 and thereafter 2025, and especially…
-
BlackNevas Ransomware Encrypts Files, Exfiltrates Corporate Data
Countries with most cyberattacks stopped highlighting global cyber defense efforts, including key regions in Asia-Pacific and North America. BlackNevas has released a comprehensive attack strategy spanning three major regions, with the Asia-Pacific area bearing the heaviest burden of attacks at 50% of total operations. The group’s primary targets in this region include major economies such as…
-
Top 10 Best Ransomware Protection Companies in 2025
As per a recent Sophos report from July 2025, 53% of Indian organizations impacted by ransomware paid the ransom, though the median payment saw a significant drop to around $481,636 (approximately ₹4 crore). However, the average recovery cost, excluding ransom, soared to $1.01 million (roughly ₹8.4 crore). These figures highlight that even if ransoms are…
-
Yurei Ransomware Uses PowerShell to Deploy ChaCha20 File Encryption
A newly discovered ransomware group called Yurei has emerged with sophisticated encryption capabilities, targeting organizations through double-extortion tactics while leveraging open-source code to rapidly scale operations. First observed on September 5, 2025, this Go-based ransomware employs the ChaCha20 encryption algorithm and PowerShell commands to compromise victim systems, marking another evolution in the ransomware-as-a-service ecosystem. Flow…
-
Security Affairs newsletter Round 541 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. FBI warns of Salesforce attacks by UNC6040 and UNC6395 groups HybridPetya ransomware bypasses UEFI Secure Boot…
-
HybridPetya ransomware bypasses UEFI Secure Boot echoing Petya/NotPetya
HybridPetya ransomware bypasses UEFI Secure Boot to infect EFI partitions, echoing the infamous Petya/NotPetya attacks of 20162017. ESET researchers discovered a new ransomware called HybridPetya on the platform VirusTotal. The malware echoes the infamous Petya/NotPetya malware, supporting additional capabilities, such as compromising UEFI-based systems and exploiting CVE”‘2024″‘7344 to bypass UEFI Secure Boot on outdated systems. >>Interestingly, the…
-
HybridPetya ransomware bypasses UEFI Secure Boot echoing Petya/NotPetya
HybridPetya ransomware bypasses UEFI Secure Boot to infect EFI partitions, echoing the infamous Petya/NotPetya attacks of 20162017. ESET researchers discovered a new ransomware called HybridPetya on the platform VirusTotal. The malware echoes the infamous Petya/NotPetya malware, supporting additional capabilities, such as compromising UEFI-based systems and exploiting CVE”‘2024″‘7344 to bypass UEFI Secure Boot on outdated systems. >>Interestingly, the…

