
This week's ransomware news continues to be dominated by targeted ransomware attacks against hospitals, cities, and businesses and the new tactic of releasing victim's data if they do not pay.
Maze continues to make a name for itself by publicly shaming victim's who do not pay by releasing their data. It was also pretty much confirmed that the City of New Orleans was hit with the Ryuk Ransomware after finding memory dumps linking the ransomware to the city's domain controllers.
Otherwise, we continue to see new variants of existing ransomware and some new RaaS services released. These new RaaS offerings, though, are thought to be scams.
Contributors and those who provided new ransomware information and stories this week include: @Seifreed, @demonslay335, @jorntvdw, @DanielGallagher, @malwrhunterteam, @FourOctets, @struppigel, @PolarToffee, @LawrenceAbrams, @fwosar, @serghei, @Ionut_Ilascu, @malwareforme, @BleepinComputer, @morphisec, @Armor, @emsisoft, @th3_protoCOL, @CERT_Polska_en, Amigo-A, @CryptoInsane, @darktor, @siri_urz, @briankrebs, @VK_Intel, and @f0wlsec.
December 14th 2019
NJ’s largest hospital system forced to pay ransom in cyber attack
New Jersey’s largest hospital system said Friday that a ransomware attack last week disrupted its computer network and that it paid a ransom to stop it.
December 15th 2019
Ryuk Ransomware Likely Behind New Orleans Cyberattack
Based on files uploaded to the VirusTotal scanning service, the ransomware attack on the City of New Orleans was likely done by the Ryuk Ransomware threat actors.
New Nbes STOP Ransomware variant
Amigo-A found a new variant of the STOP Ransomware that appends the .nbes extension to encrypted files.
December 16th 2019
Hackers hit Norsk Hydro with ransomware. The company responded with transparency
“We may be under attack,” said his IT colleague at Norsk Hydro, one of the world’s largest aluminum companies. Production lines had stopped at some of its 170 plants. Other facilities were switching from computer to manual operations.
New Mkos STOP Ransomware variant
Michael Gillespie found a new variant of the STOP Ransomware that appends the .mkos extension.
Ransomware Gangs Now Outing Victim Businesses That Don’t Pay Up
As if the scourge of ransomware wasn’t bad enough already: Several prominent purveyors of ransomware have signaled they plan to start publishing data stolen from victims who refuse to pay up. To make matters worse, one ransomware gang has now created a public Web site identifying recent victim companies that have chosen to rebuild their operations instead of quietly acquiescing to their tormentors.
December 17th 2019
Ransomware Hit Over 1,000 U.S. Schools in 2019
Since January, 1,039 schools across the U.S. have been potentially hit by a ransomware attack after 72 school districts and/or educational institutions have publicly reported being a ransomware victim according to a report from security solutions provider Armor.
New RDP Paradise Ransomware variant
S!ri found a new variant of the Paradise Ransomware that appends the .rdp extension.
New Recoil Ransomware RaaS scam
David Montenegro found a new RaaS called Recoil. Users report, though, that this is a scam.
December 18th 2019
Canadian Insurance Firm Hit By Maze Ransomware, Denies Data Theft
An insurance and financial services company based out of Manitoba, Canada is the latest victim of the Maze Ransomware with allegedly 245 computers encrypted during a cyberattack in October.
ScreenConnect MSP Software Used to Install Zeppelin Ransomware
Threat actors are utilizing the ScreenConnect (now called ConnectWise Control) MSP remote management software to compromise a network, steal data, and install the Zeppelin Ransomware on compromised computers.
New SaveTheQueen Ransomware
MalwareHunterTeam found a new variant of the SaveTheQueen Ransomware that appends the .SaveTheQueen extension to encrypted files. More analysis of this ransomware was done by F0wl and Vitali Kremez.
December 19th 2019
Decryptor released for Mapo variant of GarrantyDecrypt
CERT Polska released a decryptor for the Mapo variant of the GarrantyDecrypt ransomware.
New CHERNOLOCKER Ransomware
S!ri found a new ransomware called CHERNOLOCKER that appends the .CHERNOLOCKER) extension to encrypted files.

December 20th 2019
Emsisoft releases decryptor for ChernoLocker
Emsisoft released a decryptor for the ChernoLocker ransomware.
