Security Awareness Training Blog

Ransomware Blog

Keeping you updated on the latest ransomware attack vectors, strains, decryptors, families and trends to help you avoid becoming infected.

Weird New Cerber Ransomware Speaks To Its Victims

There is a new strain of ransomware called Cerber that takes creepiness to the next level. It drops three files on the victim's desktop named "# DECRYPT MY FILES #." These files contain ...
Continue Reading

44% of ransomware victims in the UK have paid to recover their data

Danielle Correa at SC Magazine wrote: "A Bitdefender global study with respondents from the UK, the US, France, Germany, Denmark and Romania was conducted by iSense Solutions to discover ...
Continue Reading

It's Here. New Locky Ransomware Hidden In Infected Word Files

[UPDATED FEB 22, 2016] It was only a matter of time, but some miscreant finally did it. There is a new ransomware strain somewhat amateurishly called "Locky", but this is professional ...
Continue Reading

Ransomware Roundup 2/15/2016

The bad guys have been awfully busy these last few days. Here is your ransomware roundup with the latest "new features".
Continue Reading

Ransomware Criminals Infect Thousands With Weird WordPress Hack

An unexpectedly large number of WordPress websites have been mysteriously compromised and are delivering the TeslaCrypt ransomware to unwitting end-users. Antivirus is not catching this ...
Continue Reading

This Week's Ransomware Roundup

1) I was going to write up all the ransomware related news and then ran across this article by Senior Editor Sara Peters at Darkreading. Saves me some time! She started out with: ...
Continue Reading

Alert: Stupid And Damaging New Ransomware Called 7ev3n

Larry Abrams had the scoop: "A new ransomware has been spotted called 7ev3n that encrypts your data and demands 13 bitcoins to decrypt your files. A 13 bitcoin [almost $5,000] ransom ...
Continue Reading

First Javascript-only Ransomware-as-a-Service Discovered

Cybercrime has piggybacked on the extremely successful SaaS model and several strains of Ransomware-as-a-Service (RaaS) like TOX, Fakben and Radamant have appeared in 2015. However, a new ...
Continue Reading

Major TeslaCrypt Ransomware Offensive Underway

This month, Symantec researchers reported a boost in TeslaCrypt attacks, going from 200 a day to 1,800. TeslaCrypt first appeared in March 2015, and differentiated itself because many of ...
Continue Reading

Kaspersky Sees Ransomware Doubling Year Over Year

Antivirus company Kaspersky has been monitoring ransomware pretty much from the get-go. Not surprising, as they are in Moscow and the main ransomware malware developers are Russian as ...
Continue Reading

Cryptowall 4.0 Delivered via Nuclear Exploit Kit

Earlier than expected - but similar to Cryptowall 3.0 - a few weeks after its release, Cryptowall 4.0 ransomware is now delivered via the Nuclear Exploit Kit, (NEK) according to the ...
Continue Reading

Ransomware News Roundup November 2015

DecryptorMax 24-hour deadline Ransomware strains use different ways to pressure victims into paying, varying from 7 days after which the ransom doubles, to threatening to publish files on ...
Continue Reading

Bitdefender Releases Cryptowall 4.0 Ransomware Vaccine

Right after a new, badder version 4.0 of CryptoWall came out, Romanian security company Bitdefender has released a vaccine they claim will block ransomware infections. Andra Zaharia of ...
Continue Reading

FFIEC warns of increased ransomware attacks

Ransomware continues to be a source of worry and now U.S. regulatory agencies are getting in the fray. The Federal Financial Institutions Examination Council (FFIEC) published a statement ...
Continue Reading

New Triple Threat Chimera: Ransomware, Extortion And Data Breach

OK, Heads Up! This has not hit U.S. shores yet, but it's just a matter of time. This nasty bit of crimeware is being beta-tested in Germany at the moment, and that is where the reports ...
Continue Reading

CryptoWall v4.0 released: Now encrypts the file names as well

Lawrence Abrams from the famous bleepingcomputer site wrote at Spiceworks: "CryptoWall 4.0 has been released that displays a redesigned ransom note, new filenames, and now encrypts a ...
Continue Reading

Staggering CryptoWall Ransomware Damage: 325 Million Dollar

A brand new report from Cyber Threat Alliance showed the staggering damage caused by a single criminal Eastern European cyber mafia. The CTA is an industry group with big-name members ...
Continue Reading

FBI’s Advice on Ransomware? Just Pay The Ransom.

In-brief: The nation’s top law enforcement agency is warning companies that they may not be able to get their data back from cyber criminals who use Cryptolocker, Cryptowall and other ...
Continue Reading

Ransomware Spreads Using Remote Desktop and Terminal Services Attacks

Larry Abrams at tech blog Bleeping Computer was the first one to report on this new wrinkle. The ransomware is called LowLevel04 and encrypts data using RSA-2048 encryption, the ransom is ...
Continue Reading

Cisco Takes Down $60M Ransomware Operation

Good news for a change. Cisco just posted that they disabled a cybercrime operation that used the Angler exploit kit to distribute ransomware. The takedown shutttered a global ransomware ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews