Clustering attacker behavior reveals hidden patterns

Credit to Author: Andrew Brandt| Date: Tue, 08 Aug 2023 10:00:11 +0000

A collection of very specific behaviors, observed by Sophos X-Ops incident response analysts in the lead-up to four separate ransomware attacks in the first quarter of 2023, indicates an unexpected connection between the attacks. In the parlance of the Managed Detection and Response (MDR) team, the peculiarly similar details constitute a threat activity cluster that […]

Read more

Ransomware groups claim responsibility for double-attack on Yamaha

Categories: Business

Tags: ransomware

Tags: blackbyte

Tags: Akira

Tags: group

Tags: compromised

Tags: data

Tags: blackmail

Tags: extortion

Tags: attack

Tags: Yamaha

Tags: Canada

Tags: music

Tags: audio

We take a look at claims that Yamaha has been compromised by two unrelated ransomware groups.

(Read more…)

The post Ransomware groups claim responsibility for double-attack on Yamaha appeared first on Malwarebytes Labs.

Read more

Tampa General Hospital half thwarts ransomware attack, but still loses patient data

Categories: News

Categories: Ransomware

Tags: Tampa

Tags: General Hospital

Tags: Snatch

Tags: ransomware

Tags: RDP

Tags: data breach

The Tampa General Hospital has promised to reach out to the individuals whose information has been stolen by the Snatch ransomware group.

(Read more…)

The post Tampa General Hospital half thwarts ransomware attack, but still loses patient data appeared first on Malwarebytes Labs.

Read more

Estée Lauder targeted by Cl0p and BlackCat ransomware groups

Categories: Business

Tags: Estée Lauder

Tags: Cl0p

Tags: BlackCat

Tags: ransomware

Tags: compromise

Tags: attack

Tags: breach

Tags: blackmail

Tags: threat

We take a look at reports of cosmetics firm Estée Lauder being attacked by the Cl0p and BlackCat ransomware groups.

(Read more…)

The post Estée Lauder targeted by Cl0p and BlackCat ransomware groups appeared first on Malwarebytes Labs.

Read more

Sophos Discovers Ransomware Abusing “Sophos” Name

Credit to Author: Andrew Brandt| Date: Tue, 18 Jul 2023 21:20:01 +0000

Attackers will sometimes use the name of security companies in their malware. While performing a regular search on VirusTotal looking for interesting malware and new ransomware variants using our threat hunting rules this week, a Sophos X-Ops analyst discovered a novel ransomware executable that appears to use “Sophos” in the UI of the panel alerting […]

Read more

Ransomware making big money through “big game hunting”

Categories: Business

Tags: business

Tags: ransomware

Tags: crypto

Tags: cryptocurrency

Tags: digital

Tags: payment

Tags: extortion

Tags: gang

Tags: group

Tags: big game hunting

We take a look at reports that claim ransomware is making big money in 2023.

(Read more…)

The post Ransomware making big money through “big game hunting” appeared first on Malwarebytes Labs.

Read more