Security Awareness Training Blog

Ransomware Blog

Keeping you updated on the latest ransomware attack vectors, strains, decryptors, families and trends to help you avoid becoming infected.

"My AV blocked RanSim.exe So I'm Safe" No You Are Not

I'm noticing a lot of people saying the ransim.exe file is getting blocked by your AV. You have to actually allow the initial processes to run to do the simulation. It is the five test ...
Continue Reading

Python Ransomware Uses A Unique Key For Each File That Is Encrypted

A new ransomware strain written in Python called CryPy was disclosed by Avast malware analyst Jakub Kroustek. It seems that Pyton is getting more popular as a ransomware development ...
Continue Reading

More than 60% of US office workers are unaware of the ransomware threat

Nearly half of ransomware attacks are aimed at office workers, but almost two-thirds of those polled are unaware of the threat More than 60% of US office workers are unaware of ransomware ...
Continue Reading

AI-powered ransomware is coming, and it's going to be terrifying

Business Insider started an article with the following: "Imagine you've got a meeting with a client, and shortly before you leave, they send you over a confirmation and a map with ...
Continue Reading

Did You Know That Ransomware Can Stop SQL So It Can Encrypt The Database?

I have been knee deep into Ransomware since September 2013 when the granddaddy of modern ransomware CryptoLocker made well over 20 million bucks in a few months. But sometimes I learn ...
Continue Reading

Massive Cerber Ransomware Campaign Flooding Your Employees' Inboxes

By Eric Howes, KnowBe4 Principal Lab Researcher. This Monday morning many of our customers came in to work to find a rather rude surprise lurking in their inboxes: a massive Cerber ...
Continue Reading

This weird ransomware strain spreads like a virus in the cloud

Here is a ransomware horror story for you... An obscure 2-year old ransomware strain called Virlock has a nasty feature: it is capable of stealthily spreading itself via cloud storage and ...
Continue Reading

Ransomware Is Now Officially Extortion Under California Law

Of course everyone knows that hacking into a computer is a federal crime, and infecting a system with ransomware already falls into that bucket. However, California’s SB-1137, signed into ...
Continue Reading

What is the Necurs Botnet And How Does It Spread Locky Ransomware?

In Short: The Necurs botnet is one of the world's largest botnets with more than 6 million zombie machines tied into it. It's run by Russian organized cybercrime and responsible for ...
Continue Reading

As Neutrino takes a hit, RIG Exploit Kit jumps at the opportunity and spreads ransomware

Andra Zaharia (the picture is really her) from the Danish Heimdal Security wrote something interesting this morning that I thought you'd like to know:
Continue Reading

Meet Mamba: New Full Disk Encryption Ransomware

SecurityAffairs just published a new discovery that you need to know about. A Brazilian Infosec research group, Morphus Labs, just discovered a new Full Disk Encryption (FDE) ransomware ...
Continue Reading

[ALERT] FBI Warns Ransomware Attacks Get More Targeted And Expensive

In an alert published today, the U.S. Federal Bureau of Investigation (FBI) warned that recent ransomware variants have targeted and compromised vulnerable business servers (rather than ...
Continue Reading

New Vicious And Highly Targeted Ransomware Attacks Made Public

Here’s an example of a highly targeted ransomware attack, with bad guys using a phony Bank of Montreal (BMO) template to social engineer possible victims into clicking on a malicious ...
Continue Reading

A Single Ransomware Gang Made $121M In 2016

Intel Security today released its McAfee Labs Threats Report: September 2016, which assesses the growing ransomware threat; surveys the “who and how” of data loss; explains the practical ...
Continue Reading

Targeted Lawsuit Phishing Attack With Sophisticated Payload

We are seeing a big phishing wave with a social engineering attack that threatens with a personalized lawsuit using the domain name of the targeted victim. This is an interesting payload ...
Continue Reading

Adding Insult To Injury: The Ginsu Knives Approach To Ransomware

Kaspersky has a fascinating blog post on a new strain of ransomware called RAA that is not only fairly sophisticated, but incredibly abusive:
Continue Reading

Philadelphia Ransomware Strain Offers "Mercy" Button

Larry Abrams at Bleepingcomputer reported on a new strain that raises some eyebrows. "A new version of the Stampado ransomware called Philadelphia has started being sold for $400 USD by a ...
Continue Reading

Tampa FBI: Your business is going to get hacked (or get infected with ransomware)

The Tampa Bay Business Journal published an interview with FBI Special Agent Lawrence Wolfenden. Wolfenden is a 25-year veteran of the FBI, the lead agency for investigating cyber attacks ...
Continue Reading

New Cry Ransomware Strain Has Unusual Advanced Features

Larry Abrams at Bleepingcomputer reported on a new strain with a few unusual features: "A new ransomware that pretends to be from a fake organization called the Central Security Treatment ...
Continue Reading

KnowBe4's Field Guide to Macro Warning Screens

Earlier this week today we assisted several companies that were hit by ransomware. Although companies and organizations hit by ransomware can usually pinpoint the source or employee ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews