Tyler McLellan, Robert Dean, Justin Moore, Nick Harbour, Mike Hunhoff, Jared Wilson, Jordan Nuce of FireEye report: Mandiant observed DARKSIDE affiliate UNC2465 accessing at least one victim through a Trojanized software installer downloaded from a legitimate website. While this victim organization detected the intrusion, engaged Mandiant for incident response, and avoided ransomware, others may be…
Category: Malware
SCOOP: UnitingCare paid hundreds of thousands of dollars to REvil for decryption key and deletion of files
On April 25, UnitingCare Queensland (UCQ) was the victim of a ransomware attack that impacted multiple Queensland hospitals and aged care centres. The next day, they posted a notice on their web site informing people as to what was happening and its impact. And on May 5, they posted a second update where they revealed…
Russian National Convicted of Charges Relating to Kelihos Botnet
A federal jury in Connecticut convicted a Russian national on Tuesday for operating a “crypting” service used to conceal “Kelihos” malware from antivirus software, enabling hackers to systematically infect victim computers around the world with malicious software, including ransomware. According to court documents and evidence introduced at trial, Oleg Koshkin, 41, formerly of Estonia, operated…
Cl0p affiliated hackers exposed in Ukraine, $500 million in damages estimated
Vilius Petkauskas reports: Ukrainian police reported uncovering a group of hackers who used ransomware software to extort money from foreign businesses, mainly in the United States and South Korea. Authorities claim that hackers used Cl0p encryption software to decipher stolen data and demanded ransom for the access key. According to the police, suspects used double-extorsion,…
Ca: Humber River Hospital hit by ransomware variant, prompt response prevented encryption and exfiltration
Humber River Hospital in Toronto was hit with a ransomware attack in the early hours of the morning of June 14. Their response was organized, immediate, and reportedly very effective. The following is a statement prominently displayed on their web site today: Code Grey- Update On June 14, 2021, at about 0200 hrs we experienced…
OK: Stillwater Medical Center officials investigating electronic security breach
KOCO5 has a brief item involving Stillwater Medical Center: Stillwater Medical Center officials say they recently discovered an electronic security breach that affected some of their systems. A social media post said they “immediately took steps to ensure the security of our environment, launched an investigation with the assistance of a computer forensic firm and notified law…