article thumbnail

FBI, CISA alert warns of imminent ransomware attacks on healthcare sector

Security Affairs

FBI and the DHS’s CISA agencies published a joint alert to warn hospitals and healthcare providers of imminent ransomware attacks from Russia. The government agencies receive information about imminent attacks, threat actors are using the TrickBot botnet to deliver the infamous ransomware to the infected systems. Pierluigi Paganini.

article thumbnail

Conti Leak Indicators – What to block, in your SOC….

Security Affairs

Security expert provided leak indicators for Conti ransomware operations that were recently disclosed by a disgruntled affiliate. The Conti Ransomware operators offer their services to their affiliates and maintain 20-30% of each ransom payment. Threat intelligence expert Niels Groeneveld provided leak Conti ransomware operations.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

New XBash malware combines features from ransomware, cryptocurrency miners, botnets, and worms

Security Affairs

Palo Alto Network researchers discovered a new malware, tracked as XBash, that combines features from ransomware, cryptocurrency miners, botnets, and worms. The malicious code combines features from different families of malware such as ransomware, cryptocurrency miners, botnets, and worms. ” continues the report.

article thumbnail

Security Affairs newsletter Round 230

Security Affairs

JSWorm: The 4th Version of the Infamous Ransomware. Some Zyxel devices can be hacked via DNS requests. New Bedford city infected with Ryuk ransomware, but did not pay $5.3M Thousands of servers infected with the Lilocked Ransomware. Copyright (C) 2014-2015 Media.net Advertising FZ-LLC All Rights Reserved -->.

IoT 74
article thumbnail

TA505 Group adds new ServHelper Backdoor and FlawedGrace RAT to its arsenal

Security Affairs

The group carried out a large number of campaigns using weaponized Office and PDF documents to deliver notorious malware, including the Dridex banking trojan , tRAT RAT, FlawedAmmy RAT, Philadelphia ransomware, GlobeImposter and Locky ransomware. ” ~ Copyright (C) 2014-2015 Media.net Advertising FZ-LLC All Rights Reserved -->.

Malware 91
article thumbnail

Security Affairs newsletter Round 198 – News of the week

Security Affairs

DHS issues emergency Directive to prevent DNS hijacking attacks. Two distinct campaigns are spread GandCrab ransomware and Ursnif Trojan via weaponized docs. Two distinct campaigns spread GandCrab ransomware and Ursnif Trojan via weaponized docs. Anatova ransomware – Expert believe it will be a dangerous threat.

article thumbnail

Security Affairs newsletter Round 209 – News of the week

Security Affairs

DNS hijacking campaigns target Gmail, Netflix, and PayPal users. Victims of Planetary Ransomware can decrypt their files for free. Emsisoft released a free decryptor for CryptoPokemon ransomware. Copyright (C) 2014-2015 Media.net Advertising FZ-LLC All Rights Reserved -->. The best news of the week with Security Affairs.