Remove 12
Remove 2016 Remove Document Remove Healthcare Remove Risk
article thumbnail

Connecting the Bots – Hancitor fuels Cuba Ransomware Operations

Security Affairs

It is known since at least 2016 for dropping Pony and Vawtrak. An example of spam email content Clicking the malicious link obviously leads to downloading a weaponized document. As always, the document contains instructions on how to remove “protection”: Figure 2. The keys are encrypted with RSA-4096 algorithm.