It is not only schools in the US and the UK that have been affected by ransomware. A report from Minamiboso City in the Shiba Prefecture of Japan announced that the network used by the city’s primary and secondary schools had been attacked by ransomware. On July 19, the Minamiboso City Board of Education confirmed…
Category: Malware
HC3 Threat Profile: Evil Corp
The following is not a paragraph from a story about fictional cybercriminals called Evil Corp. The following paragraph is from a white paper released this week by the U.S. Department of Health & Human Services because there is a criminal enterprise known as Evil Corp that poses a serious threat to the healthcare sector. Typographical…
Cuba Ransomware Team claims credit for attack on Montenegro
When Montenegro claimed Russian hackers attacked them, most of us probably didn’t think about the Cuba ransomware team, but the Cuba group claimed credit for the attack. According to their listing, they received the files on August 19. Their wording may sound puzzling in saying that they “received” the files, but that’s consistent with other…
That ‘clean’ Google Translate app is actually Windows crypto-mining malware
Jeff Burt reports: Watch out: someone is spreading cryptocurrency-mining malware disguised as legitimate-looking applications, such as Google Translate, on free software download sites and through Google searches. The cryptomining Trojan, known as Nitrokod, is typically disguised as a clean Windows app and works as the user expects for days or weeks before its hidden Monero-crafting…
New Golang Ransomware Agenda Customizes Attacks
Mohamed Fahmy, Nathaniel Gregory Ragasa, Earle Maui Earnshaw, Bahaa Yamany, Jeffrey Francis Bonaobra, and Jay Yaneza write: We recently discovered a new piece of targeted ransomware that was created in the Go programming language and that explicitly targeted one of our customers. This was evidenced by the specific email addresses and credentials the ransomware used. Malware written in…
EmergeOrtho notifying 75,200 patients about ransomware incident
EmergeOrtho in North Carolina has started sending notification letters to patients whose protected health information may have been accessed during a ransomware attack in May. According to a notification template seen by DataBreaches, EmergeOrtho discovered and blocked a ransomware attack on May 18. Their letter does not specifically state whether any files were encrypted, and…