article thumbnail

The Long Run of Shade Ransomware

Security Affairs

Since the beginning of the year, security firms observed a new intense ransomware campaign spreading the Shade ransomware. Between January and February, a new, intense, ransomware campaign has been observed by many security firms. Trend of malicious JavaScript downloading Shade ransomware (source: ESET).

article thumbnail

Gootkit delivery platform Gootloader used to deliver additional payloads

Security Affairs

The Javascript-based infection framework for the Gootkit RAT was enhanced to deliver a wider variety of malware, including ransomware. The framework was improved to deploy a wider range of malware, including ransomware payloads. ” reads the analysis published by researchers Gabor Szappanos and Andrew Brandt from Sophos.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Crooks use hidden directories of compromised HTTPS sites to deliver malware

Security Affairs

Hacked websites were used for several malicious purposes, experts observed compromised WordPress and Joomla websites serving Shade /Troldesh ransomware, coin miners, backdoors, and some times were involved in phishing campaigns. ” reads the analysis from Zscaler. ” reads the analysis from Zscaler. jpg and msges.

CMS 109
article thumbnail

CISA warns of potential critical threats following attacks against Ukraine

Security Affairs

NotPetya and WannaCry ransomware—to cause significant, widespread damage to critical infrastructure.” ” Microsoft spotted a destructive malware, tracked as WhisperGate , that targeted government, non-profit, and IT entities in Ukraine with a wiper disguised as ransomware. ” reads the insights” document.

CMS 77
article thumbnail

List of data breaches and cyber attacks in June 2020 ­– 7 billion records breached

IT Governance

The Maine Information and Analysis Center breached in ‘Blue Leaks’ hack (unknown). Ransomware. UK electric firm Elexon hit by ransomware (unknown). Bernards Township, NJ, resuming operations after ransomware attack (unknown). International IT firm Excis targeted by ransomware (unknown). Data breaches.

article thumbnail

The Week in Cyber Security and Data Privacy: 13 – 19 November 2023

IT Governance

At the end of each month, these incidents – and any others that we find – will be used to inform our monthly analysis of data breaches and cyber attacks. a property management company in Kentucky Incident details: The ransomware group Hunters International has added Homeland, Inc. to its leak site.

article thumbnail

Dacls RAT, the first Lazarus malware that targets Linux devices

Security Affairs

The group is considered responsible for the massive WannaCry ransomware attack, a string of SWIFT attacks in 2016, and the Sony Pictures hack. And our analysis shows that this is a fully functional, covert and RAT program targeting both Windows and Linux platforms, and the samples share some key characters being used by Lazarus Group.”

CMS 79