Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • The Nightly Mint: Daily NFT Recap bitcoin news
  • Biggest Dollar Holding Among Wealthiest Ethereum Whales bitcoin news
  • Zyxel Releases Patch for Critical Firewall OS Command Injection Vulnerability cyber security news
  • The Wall Street Journal Is Dead Wrong About The NFT Market’s Supposed Collapse bitcoin news
  • Elon Musk, Tesla, Spacex Facing $258 Billion Lawsuit for Promoting Dogecoin – Featured Bitcoin News bitcoin news
  • The Sandbox (SAND) Blows Up 20% After Collab With Major Entertainment Firm bitcoin news
  • Why StarkWare Faces Backlash Over Token Design bitcoin news
  • Microstrategy Outperforms Every Asset Class and Big Tech Stock Since Adopting Bitcoin Strategy, Says CEO – Featured Bitcoin News bitcoin news

BlackCat Ransomware Gang Targeting Unpatched Microsoft Exchange Servers

Posted on June 16, 2022 By root


BlackCat ransomware

Microsoft is warning that the BlackCat ransomware crew is leveraging exploits for unpatched Exchange server vulnerabilities to gain access to targeted networks.

Upon gaining an entry point, the attackers swiftly moved to gather information about the compromised machines, carrying out credential theft and lateral movement activities, before harvesting intellectual property and dropping the ransomware payload.

The entire sequence of events played out over the course of two full weeks, the Microsoft 365 Defender Threat Intelligence Team said in a report published this week.

“In another incident we observed, we found that a ransomware affiliate gained initial access to the environment via an internet-facing Remote Desktop server using compromised credentials to sign in,” the researchers said, pointing out how “no two BlackCat ‘lives’ or deployments might look the same.”

CyberSecurity

BlackCat, also known by the names ALPHV and Noberus, is a relatively new entrant to the hyperactive ransomware space. It’s also known to be one of the first cross-platform ransomware written in Rust, exemplifying a trend where threat actors are switching to uncommon programming languages in an attempt to evade detection.

The ransomware-as-a-service (RaaS) scheme, irrespective of the varying initial access vectors employed, culminates in the exfiltration and encryption of target data that’s then held ransom as part of what’s called double extortion.

BlackCat ransomware

The RaaS model has proven to be a lucrative gig economy-style cybercriminal ecosystem consisting of three different key players: access brokers (IABs), who compromise networks and maintain persistence; operators, who develop and maintain the ransomware operations; and affiliates, who purchase the access from IABs to deploy the actual payload.

According to an alert released by the U.S. Federal Bureau of Investigation (FBI), BlackCat ransomware attacks have victimized at least 60 entities worldwide as of March 2022 since it was first spotted in November 2021.

BlackCat ransomware

Furthermore, Microsoft said that “two of the most prolific” affiliate threat groups, which have been associated with several ransomware families such as Hive, Conti, REvil, and LockBit 2.0, are now distributing BlackCat.

CyberSecurity

This includes DEV-0237 (aka FIN12), a financially motivated threat actor that was last seen targeting the healthcare sector in October 2021, and DEV-0504, which has been active since 2020 and has a pattern of shifting payloads when a RaaS program shuts down.

“DEV-0504 was responsible for deploying BlackCat ransomware in companies in the energy sector in January 2022,” Microsoft noted last month. “Around the same time, DEV-0504 also deployed BlackCat in attacks against companies in the fashion, tobacco, IT, and manufacturing industries, among others.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: Consumer Interest in Crypto Remains Strong – Featured Bitcoin News
Next Post: NFT Marketplace Opensea Migrates to Seaport Protocol, Transition to Cut Network Fees by 35% – Technology Bitcoin News

Related Posts

  • CISA Urges Organizations to Patch Actively Exploited F5 BIG-IP Vulnerability cyber security news
  • LockBit Ransomware Abuses Windows Defender to Deploy Cobalt Strike Payload cyber security news
  • PyPI Repository Makes 2AF Security Mandatory for Critical Python Projects cyber security news
  • Technical Details Released for ‘SynLapse’ RCE Vulnerability Reported in Microsoft Azure cyber security news
  • Researchers Disclose 10-Year-Old Vulnerabilities in Avast and AVG Antivirus cyber security news
  • Hackers Using PrivateLoader PPI Service to Distribute New NetDooka Malware cyber security news

Archives

  • August 2022
  • July 2022
  • June 2022
  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Bitcoin’s Mathematical Monetary Policy Is Far More Predictable Than Gold and Fiat Currencies – Economics Bitcoin News
  • New Findings Shows Institutional Investors Take More Interest In Ethereum
  • Whales With 1k-10k BTC Depositing To Exchanges
  • Bitcoin Mining Operations Continue to Expand Amid the Crypto Winter, While Converting ‘Wasted Gas to Energy at Scale’ – Mining Bitcoin News
  • How Gold Continues To Prove To Be A Hedge Against Inflation

Recent Comments

No comments to show.
  • ETH, BTC Surge Over 10% as Big 2 Lead Crypto Rebound – Market Updates Bitcoin News bitcoin news
  • Hackers Behind Cuba Ransomware Attacks Using New RAT Malware cyber security news
  • Ethereum Dips But Here’s Why ETH Could Start Fresh Increase bitcoin news
  • Ukrainian Radio Stations Hacked to Broadcast Fake News About President Zelensky’s Health cyber security news
  • Do Guilds Hold the Future of Blockchain Gaming? bitcoin news
  • EU Regulator Warns About Crypto — Questions Whether Many Will Survive – Bitcoin News bitcoin news
  • New Crypto Exchange Platform Bitflex Launches Futures Trading Competition with $15,000 Prize Pool – Press release Bitcoin News bitcoin news
  • What Could Trigger A Sharp Decline? bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme