Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

Hello World

Cyber Lock

This has been a busy week with large scale attacks targeting local governments, new variants released, and another ransomware stating that they will use stolen data as leverage to get victims to pay.

Like we do every week, we saw a sprinkling of new Dharma, STOP, and other variants released, but the big news is with existing ransomware.

Maze Ransomware admitted to hacking the City of Pensacola and ransoming their data for $1 million. We also had an unknown ransomware attack the City of New Orleans yesterday, but according to a press briefing by the mayor, a ransom demand has not been found.

Finally, we had some interesting news about the Snatch and Ryuk Ransomware infections. 

Snatch is now rebooting victim's to the Windows Safe Mode to bypass AV software and Ryuk has released a buggy decryptor that deletes the last byte of data in large files.

Contributors and those who provided new ransomware information and stories this week include: @jorntvdw@malwareforme@fwosar@demonslay335@PolarToffee@malwrhunterteam@Seifreed@BleepinComputer@DanielGallagher@LawrenceAbrams@struppigel@FourOctets@serghei@Ionut_Ilascu@Damian1338@emsisoft@cylanceinc@Sophos, and @VK_Intel.

December 7th 2019

New GESD STOP Djvu Ransomware variant

Michael Gillespie found a new variant of the STOP Djvu Ransomware variant that appends the .gesd extension.

December 9th 2019

Pensacola, Florida Hit by Cyber Attack, City Services Impacted

The city of Pensacola is struggling to recover from a cyber attack that hit its computer network over the weekend. Some services are still affected but no critical ones.

Snatch Ransomware Reboots to Windows Safe Mode to Bypass AV Tools

Researchers discovered a new Snatch ransomware strain that will reboot computers it infects into Safe Mode to disable any resident security solutions and immediately starts encrypting files once the system loads.

Ryuk Ransomware Decryptor Is Broken, Could Lead to Data Loss

Due to recent changes in the Ryuk Ransomware encryption process, a bug in the decryptor could lead to data loss in large files.

Clop tries to bypass Kaspersky

Vitali Kremez analyzed a new variant of the Clop Cryptomix Ransomware that attempts to bypass the Kaspersky Product Suite.

Kaspersky bypass

New MERL STOP Djvu Ransomware variant

Michael Gillespie found a new variant of the STOP Djvu Ransomware variant that appends the .merl extension.

December 10th 2019

New ASD Dharma Ransomware variant

Jakub Kroustek found a new variant of the Dharma Ransomware that appends the .asd extension to encrypted files.

December 11th 2019

Ransomware Hits Florida PRIDE On Saturday, Systems Still Down

Prison Rehabilitative Industries and Diversified Enterprises Inc (PRIDE) was hit by a ransomware attack on Saturday, December 7. The nonprofit organization's website and affected systems are still down.

Maze Ransomware Behind Pensacola Cyberattack, $1M Ransom Demand

The operators behind the Maze Ransomware have claimed responsibility for the cyberattack affecting the City of Pensacola, Florida, but state that they are not affiliated with the recent shooting at NAS Pensacola.

Zeppelin Ransomware Targets Healthcare and IT Companies

A new variant of the VegaLocker/Buran Ransomware called Zeppelin has been spotted infecting U.S. and European companies via targeted installs.

December 12th 2019

Another Ransomware Will Now Publish Victims' Data If Not Paid

The operators of the REvil Ransomware, otherwise known as Sodinokibi, have announced that they will use stolen files and data as leverage to get victims to pay ransoms.

Maze Ransomware Demands $6 Million Ransom From Southwire

Maze Ransomware operators claim responsibility for another cyber attack, this time against leading wire and cable manufacturer Southwire Company, LLC (Southwire) from Carrollton, Georgia.

The State of Ransomware in the US: Report and Statistics 2019

In 2019, the U.S. was hit by an unprecedented and unrelenting barrage of ransomware attacks that impacted at least 948 government agencies, educational establishments and healthcare providers at a potential cost in excess of $7.5 billion.

New DMR Ransomware discovered

MalwareHunterTeam found the DMR Ransomware that appends the .DMR64 extension and drops a ransom note named !!! READ THIS !!!.hta.

DMR Ransomware

December 13th 2019

New Orleans Suffers Ransomware Attack, Emergency Services Intact

The City of New Orleans, Louisiana has suffered a ransomware attack that has led to the shut down of the city's servers and computer, but the city states emergency services remain intact.

New Ransomware appends .chch

@GrujaRS found a new ransomware that appends the .chch extension to encrypted files and drops a ransom note named READ_ME.TXT. Uses a contact email of This email address is being protected from spambots. You need JavaScript enabled to view it..

That's it for this week! Hope everyone has a nice weekend!