Hacker Who Stopped The Spread Of Wannacry Ransomware Arrested By The Fbi


 Killer of the WannaCry ransomware has been arrested by the FBI in the U.S. for allegedly creating a banking malware that steals password and user credentials.

 The hacker, Marcus Hutchins who owns the twitter handle, MalwareTech was arrested this week in Nevada where he was about to board a plane back to the UK after attending the Black Hat and Def Con conference. The FBI who have been on Hutchins trail for the past two years, arrested him for his alleged role in the spread of the Kronos banking malware which wrecked havoc between July 2014 and July 2015.

Also Read: The Mirai threat: How Hackers could shut off 23 Countries access to the internet

 According to an indicting PDF, Hutchins and an unknown conspirator created and distributed the trojan on the now shuttered AlphaBay marketplace. The Kronos was mostly distributed using phishing emails and would lead unsuspecting computers users to fraudulent websites that was designed to look legit like real banking institutions. This trojan would then steal the victims bank credentials.

Bad Rabbit Ransomware Attack Hits Russia, Ukraine, Germany And Other Parts Of Europe


A new ransomware spreading like wildfire has struck Ukraine, Russia , Germany, Turkey and other parts of Europe affecting over 200 organizations within a few hours.

 Dubbed "Bad Rabbit", the malware which has a number of similarities to Petya demands 0.05 bitcoin (about $285) as ransom from victims to unclock their systems


 Security researchers at ESET have detected the Bad Rabbi malware as "Win32DiskcoderD" which is a new variant of petya also known as NotPetya, Petrwrap, exPetr and GoldenEye.

According to Kaspersky lab, the ranswomware was distributed via fake Adobe Flash player installer to lure victims to install the malware.

"No exploits were used, so the victim would have to manually execute the malware dropper, ehich pretends to be an Adobe Flash installer. We've detected a number of compromised websites, all of which news or media websites." Kaspersky Lab said.

Researchers at ESET security and other security firms says the Bad rabbit distribution was via fake Flash Player updates, but some also believes that the ransomware leverages the Mimikatz post-exploitation tool to extract credentials from the compromised system.

 Those hit by the Bad Rabbit ransomware attack includes Russian media outlets Interfax and Fontanka, the Kiev subway, the airport in Odessa, the State Aviation Service and the Ministry of Infrastructure in Ukraine.

Affected users would see a ransom note on their screen, asking them to log into a Tor onion website to make the payment. However, the screen also displays a 40 hour count down of which if the user fails to pay within that time, the ransom will increase.

While security researchers are still looking for a solution to this malware, i will advice every internet user to follow these little tips to stay safe.

Keep your anti-virus up to date!

Backup device to an external storage device in case something goes wrong

Beware of third party applications and do not be in a haste to open any mail attachment sent to you, unless you are sure of the sender.

Beware of phishing mails! most phishing activities these days are sophisticated enough to make a computer geek fall for it.

There are many malicious adverts online today even on legitimate sites so beware on sites that you visits and what you click

Maersk Had To Reinstall 45,000 Pcs And 4,000 Servers After Suffering Notpetya's Attack




Shipping giant Maersk has announced that they had to reinstall about 45,000 PCs, 4,000 servers and 2,500 applications after suffering from the NotPetya attack.

Maersk was one of the companies that suffered from the NotPetya attack that struck Ukraine last year in August. The company's activities were almost crippled as they were forced to temporarily shutdown critical systems infected with the ransomware.

Due to cancellations and delays during that period, a record of about $300 was lost in revenue.

Also read: Ukrainian postal service suffers 48-hour DDoS attack

Maersk chairman, Jim Hageman Snabe shared details on the attack suffered by the company during a speech  at the World Economic Forum in Davos, Switzerland.

"The impact of (NotPetya) is that we basically found that we had to re install an entire infrastructure," Snabe said. "We had to install 4,000 new servers, 45,000 new PCs, 2,500 applications.

"And that was done in a heroic effort over ten days. Normally - I come from the IT industry - I would say it's gonna take six months. It took to days."


Maersk ship docks worldwide every 15 minutes, unloading about 20,000 containers. Imagine what it would be like running such a company without no IT for 10 days.

"It's almost impossible to even imagine. And we actually overcome that duduk masalah with human resilience," Snabe said. "We had a 20 percent drop in volume, so we managed 80 percent of that volume manually ... Customers were great contributors to overcoming that."

The Maersk chair pointed out that Maersk was a victim of a state sponsored attack aimed at Ukraine government. However, he described the incident as a "very significant wake-up call" to improve in terms of cyber-security.

The Snabe also made some point on the need for collaboration between companies and law enforcement.

World's Biggest Botnet Re-Emerges With New Ransomware Threats


Its just 13 months after the deadly Mirai malware caused a global havoc, disrupting several internet services around world with its massive DDoS attack. However, cyber security specialists are issuing out warnings of a new cyber-attack, not Mirai this time but from another Botnet called Nercurs spam.

According to security researcher(s) from Check Point, Necurs spam botnet which is putatively seen as the largest in the world is being used to spread a new ransomware threat called Scarab ransomware.

The Scarab ransomware which was first sighted in June 2017, was distributed by Necurs over 12 million times via emails in just one morning during the Thanks giving holidays in the US.

"The re-emergence of the Necurs botnet highlights how malware that may seem to be fading away doesn't always disappear or become any less of a threat," said Maya Horowitz, threat intelligence group manager at Check Point. "Despite Necurs being well known to the security community, hackers are still enjoying lots of success distributing malware with this highly effective infection vehicle."


Other malwares included in the report includes RoughTed, a malvertising aktivitas which is seen as the most wanted malware. This malware is used for performing different forms of attacks on different operating systems. The malware utilizes ad-blocker bypassing and finger printing to ensure that it delivers the most suited attack.

 Second on the list to RoughTed is Rig ek. This malware which was first seen in 2014 exploits Flash, Java, Internet explorer and silverlight. Rig ek redirects a victim to a landing page which contains a JavaScript which then scan for vulnerability so as to deliver exploits.

  Also the report were Malware for the Android Operating System. Number one on the list was Triada, a modular backdoor for Android grants superuser rights to downloaded malware. Second in place is Lokibot, an Android banking Trojan which steals user information and then locks the device while demanding for a ransom with threats of leaking the stolen information online.

Ransomware Dominates 2017 Threat Landscape



2017 has witnessed several kinds of cyber-related attacks through out the year. These attacks which includes DDoS, Data breaches, all kinds of ransomware attacks etc have cost companies, variant organizations, government bodies etc billions of dollars.

According to Carbon Black, a security specialist with endpoint security, there have been a 328% increased attacks against endpoints between January and December 2017.

 The latest threat report from the company shows that ransomware threats dominated the attacks in 2017. The ransomware variants that topped the charts includes; Spora, CryptXXX / Exxroute, Locky, Cerber and Genasom, and their top targets includes government organizations, tech companies and law firms.


Ransomware attacks in 2017 had surged at a fast pace, costing global businesses an estimated $5 billion in 2017. The research from Carbon Black also shows that the WannaCry attack which affected most organizations and corporate businesses around the world, was the first exposure more than half the population have had in the world of ransomware.

Consumers attitudes towards companies hit by ransomware is on the negative side as 72% say they would leave their financial institution if it were to be hit by ransomware, while 70% say that they would completely stop dealing with a retailer in such events.

Of all the cyber-related attacks in 2017, 57% of these were non-malware (fileless) attacks -- these attacks, according security researchers (non-malware) pose more of a business threat than commodity malware attacks.

Everyday, cyber-criminals look for new sophisticated means of bypassing various forms of security  and getting to their targets by exploiting any kind of security flaw. "Ransomware will become more targeted by looking for certain files types and targeting specific companies such as legal, healthcare, and tax prepares rather than 'spray and pray; attacks that we largely see now," part of the report read.

Maersk Had To Reinstall 45,000 Pcs And 4,000 Servers After Suffering Notpetya's Attack




Shipping giant Maersk has announced that they had to reinstall about 45,000 PCs, 4,000 servers and 2,500 applications after suffering from the NotPetya attack.

Maersk was one of the companies that suffered from the NotPetya attack that struck Ukraine last year in August. The company's activities were almost crippled as they were forced to temporarily shutdown critical systems infected with the ransomware.

Due to cancellations and delays during that period, a record of about $300 was lost in revenue.

Also read: Ukrainian postal service suffers 48-hour DDoS attack

Maersk chairman, Jim Hageman Snabe shared details on the attack suffered by the company during a speech  at the World Economic Forum in Davos, Switzerland.

"The impact of (NotPetya) is that we basically found that we had to re install an entire infrastructure," Snabe said. "We had to install 4,000 new servers, 45,000 new PCs, 2,500 applications.

"And that was done in a heroic effort over ten days. Normally - I come from the IT industry - I would say it's gonna take six months. It took to days."


Maersk ship docks worldwide every 15 minutes, unloading about 20,000 containers. Imagine what it would be like running such a company without no IT for 10 days.

"It's almost impossible to even imagine. And we actually overcome that duduk masalah with human resilience," Snabe said. "We had a 20 percent drop in volume, so we managed 80 percent of that volume manually ... Customers were great contributors to overcoming that."

The Maersk chair pointed out that Maersk was a victim of a state sponsored attack aimed at Ukraine government. However, he described the incident as a "very significant wake-up call" to improve in terms of cyber-security.

The Snabe also made some point on the need for collaboration between companies and law enforcement.

World's Biggest Botnet Re-Emerges With New Ransomware Threats


Its just 13 months after the deadly Mirai malware caused a global havoc, disrupting several internet services around world with its massive DDoS attack. However, cyber security specialists are issuing out warnings of a new cyber-attack, not Mirai this time but from another Botnet called Nercurs spam.

According to security researcher(s) from Check Point, Necurs spam botnet which is putatively seen as the largest in the world is being used to spread a new ransomware threat called Scarab ransomware.

The Scarab ransomware which was first sighted in June 2017, was distributed by Necurs over 12 million times via emails in just one morning during the Thanks giving holidays in the US.

"The re-emergence of the Necurs botnet highlights how malware that may seem to be fading away doesn't always disappear or become any less of a threat," said Maya Horowitz, threat intelligence group manager at Check Point. "Despite Necurs being well known to the security community, hackers are still enjoying lots of success distributing malware with this highly effective infection vehicle."


Other malwares included in the report includes RoughTed, a malvertising aktivitas which is seen as the most wanted malware. This malware is used for performing different forms of attacks on different operating systems. The malware utilizes ad-blocker bypassing and finger printing to ensure that it delivers the most suited attack.

 Second on the list to RoughTed is Rig ek. This malware which was first seen in 2014 exploits Flash, Java, Internet explorer and silverlight. Rig ek redirects a victim to a landing page which contains a JavaScript which then scan for vulnerability so as to deliver exploits.

  Also the report were Malware for the Android Operating System. Number one on the list was Triada, a modular backdoor for Android grants superuser rights to downloaded malware. Second in place is Lokibot, an Android banking Trojan which steals user information and then locks the device while demanding for a ransom with threats of leaking the stolen information online.

Ransomware Dominates 2017 Threat Landscape



2017 has witnessed several kinds of cyber-related attacks through out the year. These attacks which includes DDoS, Data breaches, all kinds of ransomware attacks etc have cost companies, variant organizations, government bodies etc billions of dollars.

According to Carbon Black, a security specialist with endpoint security, there have been a 328% increased attacks against endpoints between January and December 2017.

 The latest threat report from the company shows that ransomware threats dominated the attacks in 2017. The ransomware variants that topped the charts includes; Spora, CryptXXX / Exxroute, Locky, Cerber and Genasom, and their top targets includes government organizations, tech companies and law firms.


Ransomware attacks in 2017 had surged at a fast pace, costing global businesses an estimated $5 billion in 2017. The research from Carbon Black also shows that the WannaCry attack which affected most organizations and corporate businesses around the world, was the first exposure more than half the population have had in the world of ransomware.

Consumers attitudes towards companies hit by ransomware is on the negative side as 72% say they would leave their financial institution if it were to be hit by ransomware, while 70% say that they would completely stop dealing with a retailer in such events.

Of all the cyber-related attacks in 2017, 57% of these were non-malware (fileless) attacks -- these attacks, according security researchers (non-malware) pose more of a business threat than commodity malware attacks.

Everyday, cyber-criminals look for new sophisticated means of bypassing various forms of security  and getting to their targets by exploiting any kind of security flaw. "Ransomware will become more targeted by looking for certain files types and targeting specific companies such as legal, healthcare, and tax prepares rather than 'spray and pray; attacks that we largely see now," part of the report read.

Maersk Had To Reinstall 45,000 Pcs And 4,000 Servers After Suffering Notpetya's Attack




Shipping giant Maersk has announced that they had to reinstall about 45,000 PCs, 4,000 servers and 2,500 applications after suffering from the NotPetya attack.

Maersk was one of the companies that suffered from the NotPetya attack that struck Ukraine last year in August. The company's activities were almost crippled as they were forced to temporarily shutdown critical systems infected with the ransomware.

Due to cancellations and delays during that period, a record of about $300 was lost in revenue.

Also read: Ukrainian postal service suffers 48-hour DDoS attack

Maersk chairman, Jim Hageman Snabe shared details on the attack suffered by the company during a speech  at the World Economic Forum in Davos, Switzerland.

"The impact of (NotPetya) is that we basically found that we had to re install an entire infrastructure," Snabe said. "We had to install 4,000 new servers, 45,000 new PCs, 2,500 applications.

"And that was done in a heroic effort over ten days. Normally - I come from the IT industry - I would say it's gonna take six months. It took to days."


Maersk ship docks worldwide every 15 minutes, unloading about 20,000 containers. Imagine what it would be like running such a company without no IT for 10 days.

"It's almost impossible to even imagine. And we actually overcome that duduk masalah with human resilience," Snabe said. "We had a 20 percent drop in volume, so we managed 80 percent of that volume manually ... Customers were great contributors to overcoming that."

The Maersk chair pointed out that Maersk was a victim of a state sponsored attack aimed at Ukraine government. However, he described the incident as a "very significant wake-up call" to improve in terms of cyber-security.

The Snabe also made some point on the need for collaboration between companies and law enforcement.

Search

Blog Archive