Security Awareness Training Blog

Ransomware Blog

Keeping you updated on the latest ransomware attack vectors, strains, decryptors, families and trends to help you avoid becoming infected.

Here is a Real DDoS Plus Ransomware Extortion Attack

One of our customers received the following email today. It's a clear extortion attempt, they are threatening to execute a combined DDoS and Cerber ransomware attack. These bad guys claim ...
Continue Reading

Heads-up! Voice message notification email warning could be ransomware

Don't play voicemail messages from suspicious sources. Example displayed in MS Outlook. Image credit: SANS ISC.
Continue Reading

How Highly Personalized Ransomware Attacks Are Getting

CyberheistNews Subscriber Stuart Sanders sent me this: "A friend of mine in Melbourne Australia has been whacked by several crypto attacks on his clients in the last week. He supports ...
Continue Reading

Cerber Ransomware Plague Earns 2 Mil With Just 0.3% Victims Paying Up

A new report by Check Point software's researchers showed that Cerber's Ransomware-as-a-Service (RaaS) affiliate program is a success with more than 160 participants at current count, and ...
Continue Reading

FireEye warns 'massive' Locky ransomware campaign hits America

The dangerous Locky ransomware is being hurled at a variety of industries, healthcare being the number one target, according to FireEye researcher Ronghwa Chong. We have talked about ...
Continue Reading

PokemonGo Ransomware installs Backdoor Account and Spreads to other Drives

With the popularity of PokemonGo, it was inevitable that a malware developer would create a ransomware that impersonates it. This is the case with a new Hidden-Tear ransomware discovered ...
Continue Reading

Hitler ransomware just deletes files instead of encrypting them

Security experts detected and analyzed a new threat, the Hitler ransomware, that doesn’t encrypt files but simply deletes them. Larry Abrams at Bleepingcomputer commented: " It looks like ...
Continue Reading

July 2016 Ransomware Roundup: New Strains And New Nasty Features

The ransomware market is rapidly maturing, we start seeing upgraded strains and rebranded versions sold cheaply in the Dark Web. And mainstream media have finally glommed on after years ...
Continue Reading

When the Bad Guys Go to Ransomware B-School

By Eric Howes, KnowBe4 Principal Lab Researcher. As we have documented numerous times in this space over the past few years, the bad guys have proven to be relentless innovators, ...
Continue Reading

The Latest from Black Hat 2016: Ransomware By the Numbers

The annual Black Hat security conference always produces a wealth of interesting papers, presentations, talks, live demos, and security news. This year's Black Hat USA 2016 event, which ...
Continue Reading

New Ransomware-as-a-Service Offering Goes Live

The cybermafia behind the Petya/Mischa ransomware just launched their RaaS offering July 25th. It pays "distributors" a part of the ransom that gets extorted from victims and increases ...
Continue Reading

Criminal Ransomware Now Cheaper Than Standard Antivirus

For just $39 you, too, can have your very own ransomware with a lifetime license. What does a year's subscription to one of the major antivirus cost? Last I checked, much more than $39. ...
Continue Reading

Locky Ransomware Encrypts Files Even When Machine Is Offline

Locky is currently one of the top 3 ransomware threats, following closely behind CryptoWall. It's not surprising that this strain has undergone several updates since the beginning of the ...
Continue Reading

Lazy Ransomware Bad Guys Just Delete Your Files - Never Mind Decrypting

There is a new strain of "ransomware" that does not bother with the whole encryption thing at all. These bad guys seem to think it's just an unnecessary distraction and too much work. ...
Continue Reading

July 2016 Ransomware Roundup: New Strains And New Nasty Features

The ransomware market is rapidly maturing, we start seeing upgraded strains and rebranded versions sold cheaply in the Dark Web. And mainstream media have finally glommed on after years ...
Continue Reading

Doh! New "Bart" Ransomware from Threat Actors Spreading Dridex and Locky

Proofpoint researchers discovered a new strain of ransomware called "Bart" - no kidding. The Russian Cyber Mafia behind Dridex 220 and Locky are using the RockLoader malware to download ...
Continue Reading

[ZERO DAY ALERT] Ransomware Targets MS Office 365 Users

Apparently, MS Office 365 built-in security tools are not cutting it. A new strain of the Cerber Ransomware is now targeting MS Office 365 email users with a massive zero-day attack that ...
Continue Reading

Russian Cyber Mafia Is Back From Vacation With Smarter Locky Ransomware Strain

Threatpost reported that the notorious Necurs botnet is back in business, after mysteriously going dark for nearly a month. Researchers report the Necurs has returned to spewing massive ...
Continue Reading

New KnowBe4 Survey: Ransomware Infections Double In Two Years

We have just released the first long-time study focusing on IT Pros experience with ransomware. In June 2016 we surveyed 1,138 companies in a variety of industries and compared your ...
Continue Reading

Expect Micro Ransomware: Extortion One Document At A Time

I have been following the development of ransomware closely since September 2013 when the ransomware plague was unleashed on the internet in the form of CryptoLocker and its copycats. At ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews