News

Latest news about B2B cyber security >>> PR agencies: add us to your mailing list - see contact! >>> Book an exclusive PartnerChannel for your news!

Ransomware Report: LockBit by far the most active

As in the previous months, LockBit remained by far the most active ransomware in August. Only then does triple extortion follow: the attack with DDoS in addition to encryption and blackmail. At least that is what the current August ransomware report by Malwarebytes shows. Malwarebytes' threat intelligence team attributed 2022 attacks to the ransomware group in August 62 (compared to 61 attacks in July 2022 and 44 attacks in June 2022). For REvil, however, Malwarebytes only noted one attack in August. RansomEXX reports its first victim in four months and Snatch reports after 40 days...

Read more

$10 million reward for Conti gang's "Fab Five".
$10 million reward for Conti gang's "Fab Five".

US is offering "up to $10 million" in rewards for information on the Conti gang and for capturing the "Fab Five" behind Conti. Behind the name Conti is a well-known ransomware gang - more precisely a so-called ransomware-as-a-service (RaaS) gang. In the RaaS criminal business model, the part of ransomware code creation, extortion, and taking extortion payments from desperate victims is handled by a core group, while the attacks themselves are carried out by a loosely assembled “team” of members. And these are usually not chosen for their malware-programming skills, but…

Read more

Ransomware Report: Old acquaintances with LockBit, Karakurt, Black Basta, ALPHV

Malwarebytes releases its June Ransomware Report. As in the previous month, LockBit remains by far the most widespread ransomware. After that come But there are also new developments. Karakurt, Black Basta, ALPHV or BlackCat. The Malwarebytes Threat Intelligence Team attributed 44 attacks to the LockBit ransomware group in June 2022 (compared to 73 attacks in May 2022). LockBit was followed in June by Karakurt with 27 attacks, Black Basta with 18 attacks and ALPHV (aka BlackCat) with 15 attacks. Conti no longer takes up a place in the analysis in June...

Read more

Conti, LockBit, Black Basta, ALPHV & Co: Ransomware Report

Malwarebytes has compiled a report on ransomware for May 2022. Conti, LockBit & Co. are also there. Unfortunately, newcomers such as BlackBasta and ALPHV are also becoming more and more successful with their attacks. With 73 ransomware attacks, LockBit was by far the most widespread ransomware in May 2022 according to the analysis of the Malwarebytes Threat Intelligence Team. This was followed by Black Basta with 22 attacks, ALPHV with 15 attacks, Hive with 14 attacks and Mindware with 13 attacks. Conti, on the other hand, only finished sixth in May – Malwarebytes wrote to the ransomware group…

Read more

Conti ransomware: 40 organizations hacked in one month
B2B Cyber ​​Security ShortNews

As BleepingComputer reports, Conti's cybercrime syndicate is powering one of the most aggressive ransomware operations and is so well organized that they and partners were able to hack more than 40 companies in just over a month. Security researchers codenamed the hacking campaign ARMattack and described it as one of the "most prolific" and "extremely effective" of the group. ARMattack Campaign In a report shared with BleepingComputer, researchers at cybersecurity firm Group-IB say that one of Conti's "most productive campaigns" of the past year took place between November 17 and December 20, 2021. They discovered the months-long hacking spree of…

Read more

BlackBasta is probably behind the ransomware attack on Sixt
B2B Cyber ​​Security ShortNews

As Spiegel.de reports, the new attacker group BlackBasta is probably behind the ransomware attack on the car rental company Sixt. According to research by Heise.de, the new group seems to be a spin-off or an employee takeover of the Conti Group, which has probably dissolved. The ransomware extortion business remains one of the most lucrative. But at some point the great invention against ransomware attacks will have to come, because they are increasing massively. The media can hardly keep up with the reporting. The car rental company Sixt was already the victim of a ransomware attack in early May 2022. Sixt: Attack noticed early In a press release, Sixt...

Read more

USA: 10 million dollar bounty for members of the Conti group  
B2B Cyber ​​Security ShortNews

The members of the Conti group have made a lot of money from ransomware extortions. Now they also support Russia's war of aggression. The US State Department is now offering a $10 million bounty for leading members of the group. There is said to be a reward of up to $5 million for other information. The US State Department is offering a reward of up to $10 million for information leading to the identification and/or locating of individuals with key leadership positions in the transnational organized crime group of the Conti ransomware variant. In addition, the ministry is setting a reward of up to 5…

Read more

2021: Ransomware payments hit new record

Ransomware payments hit a new record in 2021 as more and more data is offered on the dark web. Recent study by Palo Alto Networks Unit 42 shows average ransom demand up 144 percent to $2,2 million, average payment up 78 percent to $541.010. Ransomware payments hit new records in 2021 as cybercriminals increasingly turn to dark web "leak sites". By threatening to release sensitive data, they pressure their victims to make them pay. This is reports Unit 42 of Palo Alto Networks (NASDAQ: PANW), worldwide...

Read more

Report: When ransomware groups fight each other.

A ransomware attack is enough for most companies as a limit. But two at once is an apocalypse scenario, albeit quite exciting for security professionals. Sophos took a closer look at the rare case, which is also a clash of modern and traditional ransomware tactics. Sophos releases its research into a dual ransomware attack in which a ransom note from Karma ransomware operators was encrypted 24 hours later by the Conti Group. Conti, another ransomware community, was operating on the infected network at the same time. Karma group meets Conti group in the same network The Sophos analysts draw the dual attack in detail in…

Read more

Ransomware group Conti dismantles itself in dispute 
Ransomware group Conti dismantles itself in dispute

According to experts, Conti has already extorted 2,5 billion dollars with ransomware in recent years. Now it is clear: the group is based in Russia and has internally backed the Russian war of aggression. However, some Ukrainians or opponents of the war probably worked in the group and did not agree with it. Now chats and codes have been leaked and, according to experts, also the crown jewels - the source code. It was probably no coincidence that the data with 60.000 internal chats of the Conti group was leaked to a Ukrainian security researcher. According to the first statements, in the…

Read more