
This has been a busy week with large scale attacks targeting local governments, new variants released, and another ransomware stating that they will use stolen data as leverage to get victims to pay.
Like we do every week, we saw a sprinkling of new Dharma, STOP, and other variants released, but the big news is with existing ransomware.
Maze Ransomware admitted to hacking the City of Pensacola and ransoming their data for $1 million. We also had an unknown ransomware attack the City of New Orleans yesterday, but according to a press briefing by the mayor, a ransom demand has not been found.
Finally, we had some interesting news about the Snatch and Ryuk Ransomware infections.
Snatch is now rebooting victim's to the Windows Safe Mode to bypass AV software and Ryuk has released a buggy decryptor that deletes the last byte of data in large files.
Contributors and those who provided new ransomware information and stories this week include: @jorntvdw, @malwareforme, @fwosar, @demonslay335, @PolarToffee, @malwrhunterteam, @Seifreed, @BleepinComputer, @DanielGallagher, @LawrenceAbrams, @struppigel, @FourOctets, @serghei, @Ionut_Ilascu, @Damian1338, @emsisoft, @cylanceinc, @Sophos, and @VK_Intel.
December 7th 2019
New GESD STOP Djvu Ransomware variant
Michael Gillespie found a new variant of the STOP Djvu Ransomware variant that appends the .gesd extension.
December 9th 2019
Pensacola, Florida Hit by Cyber Attack, City Services Impacted
The city of Pensacola is struggling to recover from a cyber attack that hit its computer network over the weekend. Some services are still affected but no critical ones.
Snatch Ransomware Reboots to Windows Safe Mode to Bypass AV Tools
Researchers discovered a new Snatch ransomware strain that will reboot computers it infects into Safe Mode to disable any resident security solutions and immediately starts encrypting files once the system loads.
Ryuk Ransomware Decryptor Is Broken, Could Lead to Data Loss
Due to recent changes in the Ryuk Ransomware encryption process, a bug in the decryptor could lead to data loss in large files.
Clop tries to bypass Kaspersky
Vitali Kremez analyzed a new variant of the Clop Cryptomix Ransomware that attempts to bypass the Kaspersky Product Suite.

New MERL STOP Djvu Ransomware variant
Michael Gillespie found a new variant of the STOP Djvu Ransomware variant that appends the .merl extension.
December 10th 2019
New ASD Dharma Ransomware variant
Jakub Kroustek found a new variant of the Dharma Ransomware that appends the .asd extension to encrypted files.
December 11th 2019
Ransomware Hits Florida PRIDE On Saturday, Systems Still Down
Prison Rehabilitative Industries and Diversified Enterprises Inc (PRIDE) was hit by a ransomware attack on Saturday, December 7. The nonprofit organization's website and affected systems are still down.
Maze Ransomware Behind Pensacola Cyberattack, $1M Ransom Demand
The operators behind the Maze Ransomware have claimed responsibility for the cyberattack affecting the City of Pensacola, Florida, but state that they are not affiliated with the recent shooting at NAS Pensacola.
Zeppelin Ransomware Targets Healthcare and IT Companies
A new variant of the VegaLocker/Buran Ransomware called Zeppelin has been spotted infecting U.S. and European companies via targeted installs.
December 12th 2019
Another Ransomware Will Now Publish Victims' Data If Not Paid
The operators of the REvil Ransomware, otherwise known as Sodinokibi, have announced that they will use stolen files and data as leverage to get victims to pay ransoms.
Maze Ransomware Demands $6 Million Ransom From Southwire
Maze Ransomware operators claim responsibility for another cyber attack, this time against leading wire and cable manufacturer Southwire Company, LLC (Southwire) from Carrollton, Georgia.
The State of Ransomware in the US: Report and Statistics 2019
In 2019, the U.S. was hit by an unprecedented and unrelenting barrage of ransomware attacks that impacted at least 948 government agencies, educational establishments and healthcare providers at a potential cost in excess of $7.5 billion.
New DMR Ransomware discovered
MalwareHunterTeam found the DMR Ransomware that appends the .DMR64 extension and drops a ransom note named !!! READ THIS !!!.hta.

December 13th 2019
New Orleans Suffers Ransomware Attack, Emergency Services Intact
The City of New Orleans, Louisiana has suffered a ransomware attack that has led to the shut down of the city's servers and computer, but the city states emergency services remain intact.
New Ransomware appends .chch
@GrujaRS found a new ransomware that appends the .chch extension to encrypted files and drops a ransom note named READ_ME.TXT. Uses a contact email of
