TargetCompany ransomware gang targets ESXi environments with new Linux variant
The script not only deploys the ransomware payload but also exfiltrates the victim's data to two separate servers.
The script not only deploys the ransomware payload but also exfiltrates the victim's data to two separate servers.
The attackers utilize cmd.cat to deploy a seemingly harmless Docker image.
The operation is aimed at military and government orgs in Myanmar, the Philippines, Mongolia, and Serbia.
The geopolitical context suggests possible links to a pro-Ukrainian cyberespionage group or hacktivists.
In brief: A corruption scheme to bypass Interpol Red Notices exposed, Russia escalates disinformation campaigns, and more.
The campaign leveraged previously unreported malware, as well as an updated variant of Eagerbee.
In some cases, the threat actor deployed a cryptominer on systems equipped with powerful NVIDIA RTX graphics cards.
The disruption was a result of a ransomware attack on Synnovis, a third-party provider of essential pathology services.
The malware, delivered through DMs, does not require any user actions beyond simply opening a message.
The malware is being distributed via Signal messaging service.
Showing elements 1371 - 1380