Security Awareness Training Blog

Ransomware Blog

Keeping you updated on the latest ransomware attack vectors, strains, decryptors, families and trends to help you avoid becoming infected.

CryptoHost Ransomware Locks Files In A Password Protected RAR File

A new ransomware strain called CryptoHost was discovered, which claims that it encrypts your data and then demands a ransom of .33 bitcoins to get your files back (~140 USD at the current ...
Continue Reading

Maktub Ransomware Knows Where You Live

It's happening in the UK today, and you can expect it in America tomorrow [correction- it's already happening today]. The bad guys in Eastern Europe are often using the U.K. as their beta ...
Continue Reading

More About Petya Hard Disk Lock BSoD Ransomware

[UPDATE April 10, 2016] Petya's ransomware's encryption has been defeated and a password generator has been released. See bottom of the post. March 25, news came out about a new type of ...
Continue Reading

It's CONFIRMED: MedStar Receives A Massive Ransomware Demand

It is now confirmed, The MedStar Hospital Chain was hit with ransomware and has received a digital ransom note. A Baltimore Sun reporter has seen a copy of the cybercriminal's demands. ...
Continue Reading

I am introducing a new phishing term: "Attackment"

Phishing attacks usually have a payload of infected attachments. With the recent ransomware attacks on hospitals I was asked for a press quote and the word "Attackment" suddenly came into ...
Continue Reading

Ransomware Attack Shuts Down Medstar Washington Hospital

The Washington Post reported that a ransomware infection penetrated the computer network of MedStar Health early Monday morning, forcing the Washington health care behemoth to shut down ...
Continue Reading

Survey: 62% of Companies Lack Confidence in Ability to Confront Ransomware Threat

Tripwire just published a new study which suggests that a majority of businesses might not be adequately prepared to either prevent or fully recover from ransomware infections. They ...
Continue Reading

New Ransomware Written In Windows PowerShell

Lucian Constantin at CSO had the scoop. A new ransomware program written in Windows PowerShell is being used in attacks against enterprises, including health care organizations, ...
Continue Reading

PETYA ransomware Locks Users Out by Overwriting Master Boot Record

Security researchers at Trend Micro have found a new type of ransomware that doesn’t encrypt specific files but makes the entire hard drive inaccessible. The malware has been named Petya ...
Continue Reading

New Maktub Ransomware Strain - Beautiful And Dangerous

Maktub Locker is the name of a new Russian strain of ransomware. The word Maktub is Arabic for "fate", suggesting it is inevitable you will get infected with ransomware. They have spent a ...
Continue Reading

Tampa Bay Business Owner Affected By Ransomware

Ransomware continues to be a successfull business for the cybercriminals of the world. It can easily get past even the best anti-virus software through a user just clicking once on ...
Continue Reading

TeamViewer Denies It Is Surprise Ransomware Infection Vector

A modified version of EDA2, an open source ransomware strain developed by Turkish computer engineering student Utku Sen, --by the way, thanks Utku, that was a very smart idea-- has been ...
Continue Reading

FBI and Microsoft Warn Against Hybrid Targeted Samas Ransomware Attack

The FBI and Microsoft have issued a new alert, a warning of hybrid targeted ransomware attacks that attempt to encrypt an organization’s entire network. This is a new approach where ...
Continue Reading

Chinese hackers behind U.S. ransomware attacks - security firms

Reuters was the first out with a story about criminal Chinese hackers also trying to get into the ransomware racket. They started out with: "Hackers using tactics and tools previously ...
Continue Reading

SURVEY: Even if You Don't Pay, Ransomware Attacks Are Very Expensive

According to a new survey by Intermedia called "2016 Crypto-Ransomware Report", ransomware attacks are increasingly targeting larger companies, costing them dearly. Employees are usually ...
Continue Reading

TeslaCrypt Ransomware v3.01 Updated With Unique Keys For Each Victim

TeslaCrypt is a relatively new ransomware variant which has made it in the Top 5, and has rapidly innovated in its efforts to evade detection. The latest version which is one of the most ...
Continue Reading

Ransomware Attacks Use NY Times, BBC, Other Media Sites

Over the weekend, The NY Times, BBC, Newsweek, AOL, MSN, The HIll and other major news sites had their ad networks hijacked again by criminals using the Angler Exploit Kit to deliver ...
Continue Reading

Inoculate Employees Against The Locky Ransomware

KnowBe4 has immediately responded to Dridex's Locky ransomware attack by releasing a new attachment option which is called "MS Office document with Macro". This new option allows a ...
Continue Reading

Deadly Dridex Cybercrime Gang Has Just Moved Into Ransomware

One thing that is driving mainstream recognition of ransomware is the move by the Dridex banking Trojan gang into ransomware with their Locky strain. They have taken over from CryptoWall, ...
Continue Reading

The structure of Russia's exports in 2014, including ransomware

Check the orange slice depicting the percentage of ransomware exports. I found this on someone's twitter feed and loved it!
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews