Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

Hello World

Cyber Lock

Normally ransomware activity slows down over the December break, but this year was an exception with a quite a few interesting, and sad, stories such as FBI alerts being issued, companies being shut down, and organizations being encrypted by a variety of ransomware, and stolen data being released.

Maze continues their attack on victim's who have not paid by publishing stolen data, which led to them being sued by one of their victims, Southwire, who was able to get the Maze news site shutdown in Ireland.

In addition we saw attacks on a university in the Netherlands by Clop and a disclosure by the U.S. Coast Guard that Ryuk took down a maritime facility.

Sadly, ransomware also caused a company to temporarily shut down right before Christmas because they could not afford to keep running after a ransomware attack.

On the bizarre side, we also had ransomware attackers offering discounts and season's greetings for the holidays.

Finally, like any other week, we continue to see new variants of existing ransomware being released with new extensions and improvements to their malware executables and infection procedures.

Contributors and those who provided new ransomware information and stories this week include: @struppigel@BleepinComputer@PolarToffee@malwrhunterteam@Seifreed@malwareforme@FourOctets@demonslay335@DanielGallagher@jorntvdw@fwosar@LawrenceAbrams@serghei@Ionut_Ilascu@VK_Intel@coveware@M_Shahpasandi@thyrex2002@Tesorion_NL@malwareforme@Amigo_A_, and @siri_urz.

December 21st 2019

New Piny and Redl STOP Djvu Ransomware variants

Michael Gillespie found new variants of the Stop Djvu Ransomware that append the .piny or .redl extensions to encrypted files.

December 23rd 2019

FBI Issues Alert For LockerGoga and MegaCortex Ransomware

The FBI has issued a warning to private industry recipients to provide information and guidance on the LockerGoga and MegaCortex Ransomware.

Like Voldemort, Ransomware Is Too Scary to Be Named

Wary of alarming investors, companies victimized by ransomware attacks often tell the SEC that “malware” or a “security incident” disrupted their operations.

Sherwood telemarketing company temporarily shuts down, blames cyber attack ransom

A Sherwood telemarketing agency has unexpectedly closed its doors, leaving over 300 employees without jobs a few days before Christmas.

New Matrix Ransomware variant

Michael Gillespie found a new variant of the Matrix Ransomware that appends the .BDDY and drops a ransom note named #BDDY_README#.rtf.

December 24th 2019

Maze Ransomware Releases Files Stolen from City of Pensacola

The actors behind the Maze Ransomware have released 2GB of files that were allegedly stolen from the City of Pensacola during their ransomware attack.

December 26th 2019

Ryuk Ransomware Stops Encrypting Linux Folders

A new version of the Ryuk Ransomware was released that will purposely avoid encrypting folders commonly seen in *NIX operating systems.

WannaCash uses .happy new year extension

Alex Svirid found a new variant of the WannaCash ransomware that appends the ".happy new year" extension to encrypted file names.

WannaCash

December 27th 2019

U.S. Coast Guard Says Ryuk Ransomware Took Down Maritime Facility

The U.S. Coast Guard (USCG) published a marine safety alert to inform of a Ryuk Ransomware attack that took down the entire corporate IT network of a Maritime Transportation Security Act (MTSA) regulated facility.

Ransomware Hits Maastricht University, All Systems Taken Down

Maastricht University (UM) announced that almost all of its Windows systems have been encrypted by ransomware following a cyber-attack that took place on Monday, December 23.

December 29th 2019

New Phobos Ransomware variant

M. Shahpasandi found a new Phobos Ransomware variant that appends the .Dever extension to encrypted files.

Phobos

December 30th 2019

New c0hen Locker Ransomware

Jack found a new ransomware called c0hen Locker that appends the .c0hen extension to encrypted files. The unlock key is 12309482354ab2308597u235fnq30045f.

C0hen Locker

January 2nd 2020

Maze Ransomware Sued for Publishing Victim's Stolen Data

The anonymous operators behind the Maze Ransomware are being sued by a victim for illegally accessing their network, stealing data, encrypting computers, and publishing the stolen data after a ransom was not paid. 

Ransomware Attackers Offer Holiday Discounts and Greetings

To celebrate the holidays, ransomware operators are providing discounts or season's greetings to entice victims into paying a ransom demand.

How the Ransomware Economy Has Grown

The breadth and magnitude of ransomware attacks occurring today suggest that the cyber extortion industry has evolved exponentially over the past 12 months. It is as difficult to keep up with the headlines as the security advice that follows. In the face of this media firehose, it is important to step back and understand how we got to the state. We feel there are three primary elements that have lead to the current state of cyber extortion, and ransomware in particular.  

Nemty 2.2 and 2.3: analysis of their cryptography, and a decryptor for some file types

Tesorion has previously released decryptors for the Nemty ransomware up to version 1.6. Recently, new versions of Nemty have appeared in the wild. In this blog post we describe how a weird variant of AES-128 counter mode (CTR) encryption is used in Nemty 2.2 and 2.3 for its file encryption. We also announce the availability of a free decryptor for common office documents encrypted by Nemty 2.2 and 2.3.

New RIDIK Dharma variant

Michael Gillespie found a new Dharma Ransomware variant that appends the .RIDIK extension to encrypted files.

New WannaCryFake Ransomware

Michael Gillespie found a new WannCryFake variant called AWT Ransomware that appends the .AWT extension to encrypted files and drops a ransom note named ReadMe.txt.

New Zeoticus Ransomware

S!Ri found a new ransomware called Zeoticus that appends the .zeoticus extension to encrypted files.

Zeoticus

January 3rd 2020

FBI Warns of Maze Ransomware Focusing on U.S. Companies

Organizations in the private sector received an alert from the F.B.I. about operators of the Maze ransomware focusing on companies in the U.S. to encrypt information on their systems after stealing it first.

Clop Ransomware Now Kills Windows 10 Apps and 3rd Party Tools

The Clop Ransomware continues to evolve with a new and integrated process killer that targets some interesting processes belonging to Windows 10 apps, text editors, programming IDEs and languages, and office applications.

New SlankCryptor Ransomware

MalwareHunterTeam found a new in-development ransomware called "SlankCryptor Profit Only" that appends .slank extension to encrypted files.

Slank Ransomware

That's it for this week! Hope everyone has a nice weekend!