article thumbnail

Nemty ransomware “LOVE_YOU” malspam campaign

Security Affairs

Security experts uncovered an ongoing campaign delivering Nemty Ransomware via emails disguised as messages from secret lovers. Researchers from Malwarebytes and X-Force IRIS have uncovered an ongoing spam campaign distributing the Nemty Ransomware via messages disguised as messages from secret lovers. zip’). Pierluigi Paganini.

article thumbnail

Cyclops Ransomware group offers a multiplatform Info Stealer

Security Affairs

Researchers from security firm Uptycs reported that threat actors linked to the Cyclops ransomware are offering a Go-based information stealer. The Cyclops group has developed multi-platform ransomware that can infect Windows, Linux, and macOS systems. ” reads the report. The data is then exfiltrated to the attacker’s server.”

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

New ransomware group Hive leaks Altus group sample files

Security Affairs

On June 14th, Altus Group, a commercial real estate software solutions firm, disclosed a security breach, now Hive ransomware gang leaked its files. Now, we have information that their data may have possibly been leaked by Hive – a new ransomware group. Files leaked online. SecurityAffairs – hacking, ransomware).

article thumbnail

Borat RAT, a new RAT that performs ransomware and DDoS attacks

Security Affairs

Cyble researchers discovered a new remote access trojan (RAT) named Borat capable of conducting DDoS and ransomware attacks. Researchers from threat intelligence firm Cyble discovered a new RAT, named Borat, that enables operators to gain full access and remote control of an infected system. Pierluigi Paganini.

article thumbnail

Hades ransomware gang targets big organizations in the US

Security Affairs

Experts identified Tor hidden services and clearnet URLs via various open-source reporting that could be associated with the activity of the Hades ransomware. Researchers from Crowdstrike speculate that the new variant is a successor to WastedLocker ransomware and linked the operations to Evil Corp operations. Pierluigi Paganini.

article thumbnail

Nemty ransomware operators launch their data leak site

Security Affairs

The operators behind the Nemty ransomware set up a data leak site to publish the data of the victims who refuse to pay ransoms. Nemty ransomware first appeared on the threat landscape in August 2019, the name of the malware comes after the extension it adds to the encrypted file names. Pierluigi Paganini.

article thumbnail

Bronze Starlight targets the Southeast Asian gambling sector

Security Affairs

Bronze Starlight is a nation-state group that was observed using ransomware as means for distraction or misattribution. Then the loaders retrieve a second-stage payload stored in password-protected ZIP archive from Alibaba buckets. The attackers used modified installers for chat applications to download a.NET malware loaders.