Why ransomware threat actors go after small school districts with few resources still puzzles me. The districts may be “low-hanging fruit” from a security perspective, but they generally do not have the resources to pay big ransom demands. So why target them? My puzzlement notwithstanding, a number of ransomware teams do attack k-12 districts. DoppelPaymer…
Category: Malware
GenRx Pharmacy Breach Notice Shows How to Do It Right
This may be one of the best breach notifications I have ever read — for its plain language, clarity, and lack of attempt to spin. Not only did these folks respond promptly to an attack, but they had usable backups, stopped the attack quickly, and just…. handled this so well, it seems. Maybe they didn’t…
Ransomware attackers are making threatening phone calls to their victims, warns FBI
Catalin Cimpanu reports that ransomware threat actors are doing more than just calling their victims on the phone (as previously reported on this site and by ZDNet). Now at least one of the groups, DoppelPaymer, are allegedly threatening them. The incidents have been happening since February 2020, the FBI said in a PIN (private industry notification)…
FR: Services in Évreux and the agglomeration shut down after cyberattack
Laurent Philippot reports that the City of Evreux and the Évreux Portes de Normandie became victims of a ransomware attack about a week ago. At the present time, they locked down their systems to keep the attacker out, but that means that phones and internet are degraded or not working at this time. The mayor…
Microsoft says it identified 40+ victims of the SolarWinds hack, and more bad news…
Catalin Cimpanu reports: Microsoft said it identified more than 40 of its customers that installed trojanized versions of the SolarWinds Orion platform and where hackers escalated intrusions with additional, second-stage payloads. The OS maker said it was able to discover these intrusions using data collected by Microsoft Defender antivirus product, a free antivirus product built…
Ransomware masquerades as mobile version of Cyberpunk 2077
Lawrence Abrams reports: A threat actor is distributing fake Windows and Android installers for the Cyberpunk 2077 game that is installing a ransomware calling itself CoderWare. To trick users into installing malware, threat actors commonly distribute them as gamer installers, cheats, and cracks for copyrighted software. Read more on BleepingComputer.