WantToCry ransomware remotely encrypts files


SophosLabs analysts investigated WantToCry ransomware attacks that involved the threat actors abusing the Server Message Block (SMB) service for initial access and then exfiltrating files to attacker-controlled infrastructure for remote encryption. The detection surface is significantly reduced because WantToCry operates without local malware execution, and there is no post-compromise activity beyond exfiltrating files and rewriting them to disk.

Read more…
Source: SophosLabs


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • JD Sports hit by cyber-attack that leaked 10m customers’ data

    January 30, 2023

    The fashion retailer JD Sports said the personal and financial information of 10 million customers was potentially accessed by hackers in a cyber-attack. The company said incident, which affected some online orders made by customers between November 2018 and October 2020, targeted purchases of products of its JD, Size?, Millets, Blacks, Scotts and Millets Sport brands. Read ...

  • Russian hackers DDoS Germany for aiding Ukraine

    January 30, 2023

    Russian hackers have proved yet again how quickly cyber attacks can be used to respond to global events with a series of DDoS attacks on German infrastructure and government websites in response to the country’s plan to send tanks to Ukraine. The efforts, according to Germany’s cyber security agency, the BSI, were largely in vain. “Currently, ...

  • Infrastructure Companies Say Suppliers Pose a Growing Cyber Threat

    January 27, 2023

    Companies in critical infrastructure sectors say weak cyber defenses at suppliers are becoming a significant threat to their business, and that rules to boost security down the supply chain might be needed. While federal and industry rules for specific areas such as aviation, pipeline companies and other critical infrastructure operators are well-established, said Curley Henry, vice ...

  • ISC Releases Security Advisories for Multiple Versions of BIND 9

    January 27, 2023

    The Internet Systems Consortium (ISC) has released security advisories that address vulnerabilities affecting multiple versions of the ISC’s Berkeley Internet Name Domain (BIND) 9. A remote attacker could exploit these vulnerabilities to potentially cause denial-of-service conditions and system failures. Read more… Source: U.S. Cybersecurity and Infrastructure Security Agency  

  • Mitigating RBAC-Based Privilege Escalation in Popular Kubernetes Platforms

    January 27, 2023

    Prisma Cloud and Unit 42 recently released a report examining the use of powerful credentials in popular Kubernetes platforms, which found most platforms install privileged infrastructure components that could be abused for privilege escalation. Unit 42 happy to share that, as of today, all platforms mentioned in their report have addressed built-in node-to-admin privilege escalation. ...

  • Ukraine: Sandworm hackers hit news agency with 5 data wipers

    January 27, 2023

    The Ukrainian Computer Emergency Response Team (CERT-UA) found a cocktail of five different data-wiping malware strains deployed on the network of the country’s national news agency (Ukrinform) on January 17th. “As of January 27, 2023, 5 samples of malicious programs (scripts) were detected, the functionality of which is aimed at violating the integrity and availability of ...