Browsing: Ransomware

The Akira ransomware group appears to have adopted a more sophisticated technique to evade endpoint security defenses and maintain access to compromised systems. According to research from Huntress, attackers associated with the Akira ransomware operation attempted to interfere with antivirus and endpoint security software before beginning their encryption activities. However, these attempts did not always…

An Akira ransomware affiliate broke into a company through an MFA-less SonicWall VPN on August 4, stole credentials and file shares, and then rebooted the compromised host into Safe Mode with Networking to kill the security tools before launching the encryptor. The plan worked on the EDR. It did not work on the ransomware.

Six US and South Korean government agencies jointly warned Monday that Gunra, a ransomware-as-a-service operation built on leaked code from the notorious Conti gang, has struck at least 51 organizations across the Americas, Europe, the Middle East, Africa, and the Asia-Pacific — breaching hospitals, government agencies, and financial institutions by exploiting unpatched Fortinet firewall products…

Table of contents Phase 1: Govern and identify — inventory, ownership and response authority Phase 2: Harden and prevent — patching, MFA and secure remote access Phase 3: Detect and contain — behavioral protection, EDR and segmentation Phase 4: Roll back and recover — immutable backups and tested restores Phase 5: Improve — training, exercises…

A ransomware gang best known for skipping encryption altogether and going straight for the data has found its newest target: the software that manufacturers and retailers use to design everything from jet engines to jeans. Cl0p, the extortion crew behind the 2023 MOVEit Transfer campaign that hit more than 2,700 organizations, is now exploiting a…

Ransomware attacks against South African organisations are becoming faster and more coordinated, leaving companies with significantly less time to detect and contain breaches before they result in datatheft and extortion.