Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Ripple (XRP) Price Picks Up As SEC Legal Showdown Drags On bitcoin news
  • Bitcoin Broke Above The Multi-Week Resistance; What’s Next bitcoin news
  • Chinese Hackers Caught Stealing Intellectual Property from Multinational Companies cyber security news
  • F5 Warns of a New Critical BIG-IP Remote Code Execution Vulnerability cyber security news
  • Apartment Sold for Bitcoin in Portugal After New Regulation Allows Property Deals in Crypto – Bitcoin News bitcoin news
  • Bitcoin Reclaims $30K, Why Bulls Face Uphill Task bitcoin news
  • Pakistan Forms Committees to Decide Whether Crypto Should Be Legalized or Banned – Regulation Bitcoin News bitcoin news
  • APE, AVAX, SOL, SHIB All Lose 20% In Crypto Crash bitcoin news

Iranian Hackers Leveraging BitLocker and DiskCryptor in Ransomware Attacks

Posted on May 12, 2022 By root


A ransomware group with an Iranian operational connection has been linked to a string of file-encrypting malware attacks targeting organizations in Israel, the U.S., Europe, and Australia.

Cybersecurity firm Secureworks attributed the intrusions to a threat actor it tracks under the moniker Cobalt Mirage, which it said is linked to an Iranian hacking crew dubbed Cobalt Illusion (aka APT35, Charming Kitten, Newscaster, or Phosphorus).

“Elements of Cobalt Mirage activity have been reported as Phosphorus and TunnelVision,” Secureworks Counter Threat Unit (CTU) said in a report shared with The Hacker News.

The threat actor is said to have conducted two different sets of intrusions, one of which relates to opportunistic ransomware attacks involving the use of legitimate tools like BitLocker and DiskCryptor for financial gain.

The second set of attacks are more targeted, carried out with the primary goal of securing access and gathering intelligence, while also deploying ransomware in select cases.

Initial access routes are facilitated by scanning internet-facing servers vulnerable to highly publicized flaws in Fortinet appliances and Microsoft Exchange Servers to drop web shells and using them as a conduit to move laterally and activate the ransomware.

However, the exact means by which the full volume encryption feature is triggered remains unknown, Secureworks said, detailing a January 2022 attack against an unnamed U.S. philanthropic organization.

Another intrusion aimed at a U.S. local government network in mid-March 2022 is believed to have leveraged Log4Shell flaws in the target’s VMware Horizon infrastructure to conduct reconnaissance and network scanning operations.

“The January and March incidents typify the different styles of attacks conducted by Cobalt Mirage,” the researchers concluded.

“While the threat actors appear to have had a reasonable level of success gaining initial access to a wide range of targets, their ability to capitalize on that access for financial gain or intelligence collection appears limited.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: Blackrock, Citadel, Gemini Deny Involvement in Terra Collapse – Featured Bitcoin News
Next Post: Tether CTO Says, USDT-Dollar Remains Strong Amid Stablecoin Crises

Related Posts

  • New REvil Samples Indicate Ransomware Gang is Back After Months of Inactivity cyber security news
  • Hackers Trick Users with Fake Windows 11 Downloads to Distribute Vidar Malware cyber security news
  • Ukraine War Themed Files Become the Lure of Choice for a Wide Range of Hackers cyber security news
  • Malicious NPM Packages Target German Companies in Supply Chain Attack cyber security news
  • QNAP Urges Users to Update NAS Devices to Prevent Deadbolt Ransomware Attacks cyber security news
  • Experts Analyze Conti and Hive Ransomware Gangs Chats With Their Victims cyber security news

Archives

  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Hackers Trick Users with Fake Windows 11 Downloads to Distribute Vidar Malware
  • Cyprus Drafts Crypto Rules, May Introduce Them Before EU Regulations – Regulation Bitcoin News
  • MetaOasis AVAX Hackathon News Report – Press release Bitcoin News
  • Pakistan Can Generate $90 Million Annually if It Introduces a 15% Tax on Crypto Transactions – Emerging Markets Bitcoin News
  • QNAP Urges Users to Update NAS Devices to Prevent Deadbolt Ransomware Attacks

Recent Comments

No comments to show.
  • Rich Dad Poor Dad’s Robert Kiyosaki Plans to Buy Bitcoin When the ‘Bottom Is In’ — Says It Could Be at $17K – Bitcoin News bitcoin news
  • Infinite Arcade Launches the Last Sale of the Gamer NFTs – Sponsored Bitcoin News bitcoin news
  • LUNA Climbs 1,500% Following Do Kwon Tweets, While AVAX and NEAR Fall on Saturday – Market Updates Bitcoin News bitcoin news
  • Dragon War is Bringing the Most Exclusive NFT Collections to Magic Eden bitcoin news
  • Manta Network Joins Forces With Web3 Consortium To Advance Zero-Knowledge Technology bitcoin news
  • MEXC Global Officially Lists Leader in Web 3․0 Gaming bitcoin news
  • Bitcoin․com Exchange Market Insights Report for May 2022 – Promoted Bitcoin News bitcoin news
  • NAFSTARS Announces a Successful Fund Raise of $1․7 Million – Press release Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme