Uncovering LockBit Black’s Attack Chain and Anti-forensic activity

Since the infamous Conti ransomware group disbanded due to source code leaks during the Russia-Ukraine war, the LockBit group has claimed dominance. The group has adopted new extortion techniques and added a first-of-its-kind bug-bounty program, along with many features, to advance their new leak site. Upon investigation and analysis, we have determined that the new LockBit […]

The post Uncovering LockBit Black’s Attack Chain and Anti-forensic activity appeared first on Blogs on Information Technology, Network & Cybersecurity | Seqrite.

February 1, 2023
Read More >>

Ransomware Payments Are Down

Chainalysis reports that worldwide ransomware payments were down in 2022.

Ransomware attackers extorted at least $456.8 million from victims in 2022, down from $765.6 million the year before.

As always, we have to caveat these findings by noting that the true totals are much higher, as there are cryptocurrency addresses controlled by ransomware attackers that have yet to be identified on the blockchain and incorporated into our data. When we published last year’s version of this report, for example, we had only identified $602 million in ransomware payments in 2021…

January 31, 2023
Read More >>

Royal Mail “cyber incident” is an ongoing cyberattack CEO admits to MPs

By: Joe Fay Simon Thompson, CEO of the U.K.’s Royal Mail, has confirmed in a session with MPs that the crippling of its ability to send parcels and letters abroad was down to a “cyberattack” and that it was “ongoing”. Thompson said that investigations into the attack on the U.K. postal operator – one of the most high-profile attacks on the country’s critical infrastructure to date – were continuing, but so far there was no evidence that personal data of customers had been compromised. The U.K. National Crime Agency (NCA) and National Cyber Security Centre (NCSC) have been investigating the…

January 30, 2023
Read More >>

Copycat Criminals mimicking Lockbit gang in northern Europe

Recent reports of Lockbit locker-based attacks against North European SMBs indicate that local crooks started using Lockbit locker variants. Executive Summary Incident Insights Recently, there has been a significant increase in ransomware attacks targeting companies in northern Europe. These attacks are being carried out using the LockBit locker, which is known to be in use […]

The post Copycat Criminals mimicking Lockbit gang in northern Europe appeared first on Security Affairs.

January 29, 2023
Read More >>

FBI takes down Hive ransomware group

Working with international law enforcement, the FBI said it has seized control of the servers the Hive group uses to communicate with members.
The post FBI takes down Hive ransomware group appeared first on TechRepublic.

January 27, 2023
Read More >>