WantToCry ransomware remotely encrypts files


SophosLabs analysts investigated WantToCry ransomware attacks that involved the threat actors abusing the Server Message Block (SMB) service for initial access and then exfiltrating files to attacker-controlled infrastructure for remote encryption. The detection surface is significantly reduced because WantToCry operates without local malware execution, and there is no post-compromise activity beyond exfiltrating files and rewriting them to disk.

Read more…
Source: SophosLabs


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Scandinavian Airlines hit by cyber attack

    February 15, 2023

    Scandinavian airline SAS said it was hit by a cyber attack Tuesday evening and urged customers to refrain from using its app but later said it had fixed the problem. News reports said the hack paralyzed the carrier’s website and leaked customer information from its app. Read more… Source: Skift  

  • Pepsi Bottling Ventures says info-stealing malware swiped sensitive data

    February 14, 2023

    Crooks have breached Pepsi Bottling Ventures’ network and, after deploying info-stealing malware, made off with sensitive personal and financial information according to a notification sent to consumers. The breach happened on or around December 23, 2022. However, Pepsi Bottling Ventures – America’s largest manufacturer and distributor of Pepsi-Cola beverages – didn’t discover the unauthorized activity until ...

  • New stealthy ‘Beep’ malware focuses heavily on evading detection

    February 14, 2023

    A new stealthy malware named ‘Beep’ was discovered last week, featuring many features to evade analysis and detection by security software. The malware was discovered by analysts at Minerva after a flurry of samples were uploaded to VirusTotal, an online platform for file scanning and malicious content detection. Read more… Source: Bleeping Computer  

  • Romance scam targets security researcher, hilarity ensues

    February 14, 2023

    It sounds like the plot of a somewhat far-fetched romcom-slash-thriller Netflix series, maybe billed as You meets Your Place or Mine, dropping just in time for Valentine’s Day. In it, a pig butchering romance scammer targets her next victim: Sophos’s lead threat researcher. The security biz would probably want us to make very clear that no ...

  • New MortalKombat ransomware and Laplas Clipper malware threats deployed in financially motivated campaign

    February 14, 2023

    Since December 2022, Cisco Talos has been observing an unidentified actor deploying two relatively new threats, the recently discovered MortalKombat ransomware and a GO variant of the Laplas Clipper malware, to steal cryptocurrency from victims. Talos observed the actor scanning the internet for victim machines with an exposed remote desktop protocol (RDP) port 3389, using one ...

  • Several NATO websites suffer a cyber attack

    February 13, 2023

    Several NATO websites have suffered a computer attack on Sunday night, leaving the NATO Special Operations Headquarters website, among others, temporarily inoperative. “NATO cyber experts are actively dealing with an incident affecting some NATO websites. NATO deals with cyber incidents on a regular basis, and takes cyber security very seriously,” an Atlantic Alliance official told DPA ...