Prabhjote Gill reports: Another leading Indian pharmaceutical, Lupin, has reported a cybersecurity attack on its IT systems within two weeks of a ransomware attack on Dr Reddy’s Laboratories. “We have recently experienced an information security incident that has affected several of our internal IT systems. This has not impacted our core systems and operations,” Lupin…
Category: Malware
Don ‘t pay ransom on the promise your data will be deleted, because it won’t be — Coveware
In Coveware’s Q3 2020 report, there’s a section on criminals not keeping their word about deleting data if you’ll just pay them their extortion demands (imagine criminals not keeping their word — oh, the shock): PAYING A RANSOM MAY NOT STOP RANSOMWARE GROUPS FROM LEAKING THE EXFILTRATED DATA Coveware feels that we have reached a…
New RegretLocker ransomware targets Windows virtual machines
Lawrence Abrams reports: A new ransomware called RegretLocker uses a variety of advanced features that allows it to encrypt virtual hard drives and close open files for encryption. RegretLocker was discovered in October and is a simple ransomware in terms of appearance as it does not contain a long-winded ransom note and uses email for communication…
Hospital, Patients Seek Ransomware Attack Settlement Approval
Mary Anne Pazanowski reports: Saint Francis Healthcare System and the representatives of a class of over 90,000 patients is asking a federal court to approve the final settlement of a lawsuit growing out of a 2019 ransomware attack on a computer network that disrupted medical services and exposed patient records to unlawful access. Read more…
Campari Group victim of a malware attack
A Google translation of a report on Trend-Online: Campari Group informs that, presumably on 1 November 2020, it was the subject of a malware attack (computer virus), which was promptly identified. The Group’s IT department, with the support of IT security experts, immediately took action to limit the spread of malware in data and systems. Read…
Did REvil just acquire source code for the KPot stealer?
Cyjax notes: The source code for the KPot stealer has been auctioned off, with a representative of the REvil ransomware group being the sole public bidder. KPot first appeared in the darknet in mid-2018 as a Malware-as-a-Service (MaaS). It’s functionality included: Collect passwords, cookies, browsing history and autofill forms from Chrome, Firefox and Edge Collect…