Marco A. De Felice, aka amvinfe, writes: It happens very often nowadays to witness the sudden disappearance of ransomware groups that have been active for only a few months. In the last three years, we have counted at least twenty of them that have “vanished from the radar” of journalists and researchers. Some of these…
Category: Malware
Russian TrickBot malware dev sentenced to 64 months in prison
Following up on the case of Vladimir Dunaev, a Russian national who was extradited to the U.S. from Korea in 2021 and pleaded guilty in December 2023 for his role in creating and distributing Trickbot malware, Sergiu Gatlan reports: Russian national Vladimir Dunaev has been sentenced to five years and four months in prison for…
University of Twente Maps Decision-Making Process for Ransomware Victims
The UT investigated the decision-making process of victims who had to pay ransoms during ransomware attacks. UT researcher Tom Meurs and his colleagues analyzed 481 ransomware attacks, data from the Dutch police and a Dutch incident response party. Organizations with recoverable backups in particular were often better able to avoid paying ransoms. Data exfiltration led…
Federal government slaps targeted sanctions on Russian cybercriminal behind 2022 Medibank Private cyber attack
Heloise Vyas reports: The Australian government have cracked down on a Russian cybercriminal believed to behind a Medibank Private breach in 2022 which marked the “single most devastating attack” in the country’s history. In a joint press conference with the Foreign Affairs Minister, Deputy Prime Minister, and Cyber Security Minister, the Commonwealth declared it would,…
UPDATE: Ransomware attack affecting Tietoevry’s services for some customers in Sweden
21 January 2024 [UPDATED: 10:45 CET, January 21] One of Tietoevry’s several datacenters in Sweden was partially subject to a ransomware attack during the night of Jan 19-20. While overall recovery has progressed, services for the customers in scope remain impacted. The attack was limited to one part of one of our Swedish datacenters, impacting…
Primary Health & Wellness Center, LLC’s public notice of ransomware incident
In the process of researching breach reports submitted to HHS, DataBreaches came across a public notice for an incident affecting Primary Health & Wellness Center, LLC in Maryland. The covered entity is to be commended for the details and transparency in their notice, although they do not name the threat actor/group involved or any details…