Rilasciati i programmi per decodificare i ransomware Maze, Egregor e Sekhmet

Il gruppo di pirati di Maze dichiara di aver abbandonato il ransomware e di aver cancellato il codice sorgente. Ha inoltre pubblicato le chiavi di decrittazione dei suoi attacchi

Le vittime degli attacchi ransomware Maze/Egregor/Sekhmet possono tirare un sospiro di sollievo. In un post del forum di Bleeping Computer trovano infatti le chiavi di decrittazione per poter nuovamente accedere ai propri file. A fornirli sotto il nome di “Topleak” sono gli stessi sviluppatori dei tre malware.

Avevano anche pubblicato parte del codice sorgente delle loro creazioni, che per ovvi motivi è stato rimosso. Anche le chiavi non sono necessarie perché, dopo aver confermato la loro legittimità, Emsisoft ha pubblicato un sistema di decrittazione per liberare i file delle vittime.

Come sottolinea un articolo di Threatpost, il gruppo di pirati di Maze, che per anni è stato uno dei più attivi nell’ambito del ransomware, è stato tra i primi a mettere in atto estorsioni doppie. In questi casi i cybercriminali non si limitano a criptare i file delle vittime impedendo loro di accedervi, ma minacciano anche di renderli pubblici se non viene pagato il riscatto.

Questo gruppo di malviventi è comparso per la prima volta nel 2019 e ha compiuto imponenti attacchi contro grandi aziende come Cognizant e Xerox. Nell’estate del 2020, Maze ha formato un vero e proprio cartello di cybercriminali unendosi ad altri professionisti del ransomware, come Egregor, per condividere codice e risorse.

Alcuni esperti ritengono che Egregor sia una reincarnazione di Maze. Maze ha annunciato che avrebbe interrotto le sue attività nel novembre 2020, in un comunicato in cui cercava di dare toni moralistici alle proprie attività criminali sostenendo che il “progetto” era stato creato perché il mondo sta “sprofondando nell’incoscienza, nell’indifferenza, nella pigrizia e nella stupidità”.

https://www.securityinfo.it/2022/02/11/maze-abbandona-il-ransomware/?utm_source=rss&utm_medium=rss&utm_campaign=maze-abbandona-il-ransomware




SEO poisoning: scaricare malware con le applicazioni


Una nuova campagna di SEO poisoning inserisce i malware Batloader e Atera Agent nei sistemi di chi scarica strumenti per la produttività come Zoom, TeamViewer e Visual Studio.

La tecnica del SEO poisoning (letteralmente “avvelenamento dell’ottimizzazione per i motori di ricerca“) consiste nel far posizionare bene nei motori di ricerca siti compromessi per farli visitare dagli utenti.

Come riportato da Bleeping Computer, questi attacchi compromettono siti legittimi per impiantare file malevoli o URL che rimandano a pagine con malware celato dietro le spoglie di popolari applicazioni. Il SEO poisoning fa sì che gli utenti trovino facilmente questi siti quando ne cercano una.

Le parole chiave sono legate a programmi come Zoom, Microsoft Visual Studio 2015, TeamViewer e altri. Quando l’utente clicca sul collegamento nel motore di ricerca, viene portato a un sito compromesso che include un TDS (Traffic Direction System). Si tratta di uno script che esamina diversi attributi del visitatore per decidere se mandarlo alla pagina legittima o a una malevola.

In casi simili in passato, i TDS indirizzavano allo scaricamento del malware solo gli utenti che arrivavano dai motori di ricerca, per rendere più difficili le analisi degli esperti di sicurezza. Se il TDS decide che la vittima è papabile, la manda a un finto forum in cui si parla di una certa applicazione e viene segnalato un link per scaricarla.

Dopo aver scaricato e lanciato gli installer del software desiderato, la vittima si trova infettata con malware e programmi per l’accesso remoto. Dato che i pacchetti con il malware includono anche il software legittimo, molti utenti non si rendono conto di essere stati infettati.

I domini malevoli identificati da Mandiant includono:

  • cmdadminu[.]com
  • zoomvideo-s[.]com
  • cloudfiletehnology[.]com
  • commandaadmin[.]com
  • clouds222[.]com
  • websekir[.]com
  • team-viewer[.]site
  • zoomvideo[.]site
  • sweepcakesoffers[.]com
  • pornofilmspremium[.]com
  • kdsjdsadas[.]online
  • bartmaaz[.]com
  • firsone1[.]online

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2022/02/04/seo-poisoning-scaricare-malware-con-le-applicazioni/?utm_source=rss&utm_medium=rss&utm_campaign=seo-poisoning-scaricare-malware-con-le-applicazioni




Mac malware spreading for ~14 months installs backdoor on infected systems

Stylized illustration a door that opens onto a wall of computer code.

Mac malware known as UpdateAgent has been spreading for more than a year, and it is growing increasingly malevolent as its developers add new bells and whistles. The additions include the pushing of an aggressive second-stage adware payload that installs a persistent backdoor on infected Macs.

The UpdateAgent malware family began circulating no later than November or December 2020 as a relatively basic information-stealer. It collected product names, version numbers, and other basic system information. Its methods of persistence—that is, the ability to run each time a Mac boots—were also fairly rudimentary.

Person-in-The-Middle attack

Over time, Microsoft said on Wednesday, UpdateAgent has grown increasingly advanced. Besides the data sent to the attacker server, the app also sends “heartbeats” that let attackers know if the malware is still running. It also installs adware known as Adload.

Microsoft researchers wrote:

Once adware is installed, it uses ad injection software and techniques to intercept a device’s online communications and redirect users’ traffic through the adware operators’ servers, injecting advertisements and promotions into webpages and search results. More specifically, Adload leverages a Person-in-The-Middle (PiTM) attack by installing a web proxy to hijack search engine results and inject advertisements into webpages, thereby siphoning ad revenue from official website holders to the adware operators.

Adload is also an unusually persistent strain of adware. It is capable of opening a backdoor to download and install other adware and payloads in addition to harvesting system information that is sent to the attackers’ C2 servers. Considering both UpdateAgent and Adload have the ability to install additional payloads, attackers can leverage either or both of these vectors to potentially deliver more dangerous threats to target systems in future campaigns.

Before installing the adware, UpdateAgent now removes a flag that a macOS security mechanism called Gatekeeper adds to downloaded files. (Gatekeeper ensures users receive a warning that new software comes from the Internet, and it also ensures the software doesn’t match known malware strains.) While this malicious capability isn’t novel—Mac malware from 2017 did the same thing—its incorporation into UpdateAgent indicates the malware is under regular development.

UpdateAgent’s reconnaissance has been expanded to collect system profile and SPHardwaretype data, which, among other things, reveals a Mac’s serial number. The malware also started modifying the LaunchDaemon folder instead of the LaunchAgent folder as before. While the change requires UpdateAgent to run as administrator, the change allows the trojan to inject persistent code that runs as root.

The following timeline illustrates the evolution.

Once installed, the malware collects the system info and sends it to the attackers’ control server and takes a host of other actions. The attack chain of the latest exploit looks like this:

Microsoft said UpdateAgent masquerades as legitimate software, such as video apps or support agents, that is spread through pop-ups or ads on hacked or malicious websites. Microsoft didn’t explicitly say so, but users apparently must be tricked into installing UpdateAgent, and during that process, Gatekeeper works as designed.

In many ways, the evolution of UpdateAgent is a microcosm for the macOS malware landscape as a whole: malware continues to become more advanced. Mac users should learn how to spot social engineering lures, such as unsolicited pop-ups appearing in browser windows that warn of infections or unpatched software.

https://arstechnica.com/?p=1831397




Android malware can factory-reset phones after draining bank accounts

Android malware can factory-reset phones after draining bank accounts
Getty Images

A banking-fraud trojan that has been targeting Android users for three years has been updated to create even more grief. Besides draining bank accounts, the trojan can now activate a kill switch that performs a factory reset and wipes infected devices clean.

Brata was first documented in a post from security firm Kaspersky, which reported that the Android malware had been circulating since at least January 2019. The malware spread primarily through Google Play but also through third-party marketplaces, push notifications on compromised websites, sponsored links on Google, and messages delivered by WhatsApp or SMS. At the time, Brata targeted people with accounts from Brazil-based banks.

Covering its malicious tracks

Now Brata is back with a host of new capabilities, the most significant of which is the ability to perform a factory reset on infected devices to erase any trace of the malware after an unauthorized wire transfer has been attempted. Security firm Cleafy Labs, which first reported the kill switch, said other features recently added to Brata include GPS tracking, improved communication with control servers, the ability to continuously monitor victims’ bank apps, and the ability to target the accounts of banks located in additional countries. The trojan now works with banks located in Europe, the US, and Latin America.

“First discovered targeting Brazilian Android users in 2019 by Kaspersky, the remote access trojan (RAT) has been updated, targeting more potential victims and adding a kill switch to the mix to cover its malicious tracks,” researchers from security firm Zimperium said in a post confirming Cleafy’s findings. “After the malware has infected and successfully conducted a wire transfer from the victim’s banking app, it will force a factory reset on the victim’s device.”

This time around, there’s no evidence that the malware is being spread through Google Play or other official third-party Android stores. Instead, Brata propagates through phishing text messages disguised as banking alerts. The new capabilities are circulating in at least three variants, all of which went almost completely undetected until Cleafy first discovered them. The stealth is at least partly the result of a new downloader used to distribute the apps.

Besides the kill switch, Brata now seeks permission to access the locations of infected devices. While Cleafy researchers said they didn’t find any evidence in the code that Brata is using location tracking, they speculated that future versions of the malware may start availing itself of the feature.

The malware also has been updated to maintain a persistent connection with the attacker’s command and control server (or C2) in real time using a websocket.

“As shown in Figure 17 [below], the webSocket protocol is used by the C2 that sends specific commands that need to be executed on the phone (e.g, whoami, byebye_format, screen_capture, etc.),” Cleafy researchers wrote. “As far as we know, the malware (on connection perspective) is in a waiting state most of the time, until the C2 issues commands instructing the app for the next step.”

Cleafy Labs

The new capabilities underscore the ever-evolving behavior of crimeware apps and other kinds of malware as their authors strive to increase the apps’ reach and the revenues they generate. Android phone users should remain wary of malicious malware by limiting the number of apps they install, ensuring apps come only from trustworthy sources, and installing security updates quickly.

https://arstechnica.com/?p=1828686




Ora Trickbot adotta una tecnica “aggressiva” per impedire l’analisi


La nuova versione del malware non si limita a nascondersi: se “fiuta” un tentativo di analisi attiva le contromisure e manda in crash il sistema.

Prima regola: non essere individuati dagli esperti di sicurezza. Gli sforzi dei pirati informatici per afre in modo che i loro malware non possano essere studiati dagli analisti delle società che si occupano di cyber security sono in continua evoluzione e, con la nuova versione di Trickbot, inaugurano una nuova strategia.

Normalmente, i cyber criminali adottano tecniche di offuscamento per impedire l’analisi del codice dei loro malware o, nella maggior parte dei casi, equipaggiano il codice malevolo con funzionalità che ricordano la “strategia dell’opossum”.

Se vengono rilevati indizi che portano a pensare che il malware sia eseguito in ambienti virtuali dagli esperti di sicurezza, il malware si “finge morto”.

Gli autori di Trickbot, però, hanno scelto una strategia più aggressiva. Come spiegano i ricercatori di IBM X-Force in un report pubblicato su Internet, i pirati informatici hanno inserito nel loro malware uno script anti-debugging.

In particolare, la funzione prende di mira le attività che in gergo vengono chiamate “code beautifying”, cioè quelle attività automatiche che i ricercatori usano per rendere più “leggibile” il codice delle applicazioni malevole.

Trickbot

Nel momento stesso in cui viene utilizzata una funzionalità di code beautifying, Trickbot reagisce avviando un loop che satura la memoria e, di conseguenza, manda in crash la macchina.

Insomma: se un ricercatore di sicurezza cerca di analizzare la nuova versione di Trickbot, si ritrova a dover fare i conti con un sistema che cerca di mandare sistematicamente in tilt il sistema su cui lo sta studiando.

Naturalmente, la tecnica non è l’unico espediente utilizzato per rendere difficoltosa l’analisi del codice del malware: i pirati hanno usato anche un sistema di codifica Base64 e l’inserimento di una buona dose di “codice spazzatura” per complicare le cose.

La tecnica che punta a provocare il crash del sistema, però, è di certo quella più innovativa.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2022/01/26/ora-trickbot-adotta-una-tecnica-aggressiva-per-impedire-lanalisi/?utm_source=rss&utm_medium=rss&utm_campaign=ora-trickbot-adotta-una-tecnica-aggressiva-per-impedire-lanalisi




Booby-trapped sites delivered potent new backdoor trojan to macOS users

Close-up photograph of a Macintosh laptop keyboard.

Researchers have uncovered advanced, never-before-seen macOS malware that was installed using exploits that were almost impossible for most users to detect or stop once the users landed on a malicious website.

The malware was a full-featured backdoor that was written from scratch, an indication that the developers behind it have significant resources and expertise. DazzleSpy, as researchers from security firm Eset have named it, provides an array of advanced capabilities that give the attackers the ability to fully monitor and control infected Macs. Features include:

  • victim device fingerprinting
  • screen capture
  • file download/upload
  • execute terminal commands
  • audio recording
  • keylogging

Deep pockets, top-notch talent

Mac malware has become more common over the years, but the universe of advanced macOS backdoors remains considerably smaller than that of advanced backdoors for Windows. The sophistication of DazzleSpy—as well as the exploit chain used to install it—is impressive. It also doesn’t appear to have any corresponding counterpart for Windows. This has led Eset to say that the people who developed DazzleSpy are unusual.

“First, they seem to be targeting Macs only,” Eset researcher Marc-Etienne M.Léveillé wrote in an email. “We haven’t seen payloads for Windows nor clues that it would exist. Secondly, they have the resources to develop complex exploits and their own spying malware, which is quite significant.”

Indeed, researchers from Google’s threat analysis group who first uncovered the exploits said that, based on their analysis of the malware, they “believe this threat actor to be a well-resourced group, likely state-backed, with access to their own software engineering team based on the quality of the payload code.”

As the Google researchers first noted, the malware was spread in watering-hole attacks that used both fake and hacked sites appealing to pro-democracy activists in Hong Kong. The attacks exploited vulnerabilities that, when combined, gave the attackers the ability to remotely execute code of their choice within seconds of a victim visiting the booby-trapped webpage. All that was required for the exploit to work was for someone to visit the malicious site. No other user action was required, making this a one-click attack.

“That’s kind of the scary part: on an unpatched system the malware would start to run with administrative privileges without the victim noticing,” M.Léveillé said. “Traffic to the C&C server is also encrypted using TLS.”

Apple has since patched the vulnerabilities exploited in this attack.

The exploit chain consisted of a code-execution vulnerability in Webkit, the browser engine for Apple Safari. Eset researchers analyzed one of the watering-hole sites, which was taken down but remains cached in the Internet Archives. The site contained a simple iframe tag that connected to a page at amnestyhk[.]org.

https://arstechnica.com/?p=1828331




Attacco ad AccessPress per distribuire una backdoor sui siti WordPress


I pirati sarebbero riusciti a inoculare il malware in 40 temi e 53 plugin. A rischio 360.000 siti Web che utilizzano componenti sviluppati dalla società compromessa.

Quello che ha preso di mira AccessPress sarebbe un classico attacco supply chain, che in questo caso potrebbe avere un fattore di amplificazione decisamente “pesante”.

La società, specializzata nello sviluppo di ad-on per WordPress, ha infatti una base di utenti piuttosto ampia e si stima che i suoi componenti aggiuntivi per il celebre Content Management System siano usati in 360.000 siti Web nel mondo.

Secondo un’analisi dell’attacco pubblicata su Internet da Sucuri, l’elevato impatto sarebbe dovuto al fatto che i cyber criminali hanno preso di mira temi e plugin che AccessPress mette a disposizione gratuitamente ai suoi utenti. Insomma: verosimilmente i componenti più utilizzati.

Stando a quanto spiegano gli autori del report, l’attacco non sarebbe particolarmente sofisticato, per lo meno nello stadio che interessa gli utilizzatori finali (e in ultima analisi le vittime) dell’attacco.

AccessPress

La backdoor inserita nei componenti aggiuntivi della società sfrutta un semplice file (initial.php) che contiene al suo interno un payload codificato in base64. Una volta eseguito, il codice inserisce una webshell in ./wp-includes/vars.php.

Il malware, inoltre, prevede un sistema di autodistruzione che prevede la cancellazione di initial.php, probabilmente allo scopo di cancellare le tracce dell’avvenuta compromissione.

Secondo gli analisti di Sucuri, al momento alcune delle funzionalità di supporto all’attacco non sono più attive, ma nel loro report sottolineano come i pirati informatici abbiano avuto a disposizione un’ampia finestra di opportunità per sfruttare la backdoor. L’attacco ad AccessPress, infatti, risalirebbe alla fine dell’anno scorso.

Per fortuna, le prime analisi farebbero pensare a una modalità di sfruttamento piuttosto “dozzinale” dell’attacco. I siti Web compromessi sarebbero stati utilizzati per fare spam e reindirizzare i visitatori su pagine di phishing o contenenti codice malevolo. Visti i numeri in ballo, però, l’impatto dell’attacco rischia di essere tutt’altro che lieve.

Per verificare se il proprio sito è stato compromesso, gli esperti suggeriscono di controllare il file wp-includes/vars.php e verificare se, dalle parti delle linee 146-158 è presente una funzione chiamata wp_is_mobile_fix, seguita da codice offuscato. Se è presente, il sito è stato violato.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2022/01/24/attacco-ad-accesspress-per-distribuire-una-backdoor-sui-siti-wordpress/?utm_source=rss&utm_medium=rss&utm_campaign=attacco-ad-accesspress-per-distribuire-una-backdoor-sui-siti-wordpress




Supply chain attack used legitimate WordPress add-ons to backdoor sites

Supply chain attack used legitimate WordPress add-ons to backdoor sites
Getty Images

Dozens of legitimate WordPress add-ons downloaded from their original sources have been found backdoored through a supply chain attack, researchers said. The backdoor has been found on “quite a few” sites running the open source content management system.

The backdoor gave the attackers full administrative control of websites that used at least 93 WordPress plugins and themes downloaded from AccessPress Themes. The backdoor was discovered by security researchers from JetPack, the maker of security software owned by Automatic, provider of the WordPress.com hosting service and a major contributor to the development of WordPress. In all, Jetpack found that 40 AccessPress themes and 53 plugins were affected.

Unknowingly providing access to the attacker

In a post published Thursday, Jetpack researcher Harald Eilertsen said timestamps and other evidence suggested the backdoors were introduced intentionally in a coordinated action after the themes and plugins were released. The affected software was available by download directly from the AccessPress Themes site. The same themes and plugins mirrored on WordPress.org, the official developer site for the WordPress project, remained clean.

“Users who used software obtained directly from the AccessPress website unknowingly provided attackers with backdoor access, resulting in an unknown number of compromised websites,” Ben Martin, a researcher with Web security firm Sucuri, wrote in a separate analysis of the backdoor.

He said the tainted software contained a script named initial.php that was added to the main theme directory and then included in the main functions.php file. Initial.php, the analysis shows, acted as a dropper that used base64 encoding to camouflage code that downloaded a payload from wp-theme-connect[.]com and used it to install the backdoor as wp-includes/vars.php. Once it was installed, the dropper self-destructed in an attempt to keep the attack stealthy.

The Jetpack post said evidence indicates that the supply chain attack on AccessPress Themes was performed in September. Martin, however, said evidence suggests the backdoor itself is much older than that. Some of the infected websites had spam payloads dating back nearly three years. He said his best guess is that the people behind the backdoor were selling access to infected sites to people pushing web spam and malware.

He wrote, “With such a large opportunity at their fingertips, you’d think that the attackers would have prepared some exciting new payload or malware, but alas, it seems that the malware that we’ve found associated with this backdoor is more of the same: spam, and redirects to malware and scam sites.”

The Jetpack post provides full names and versions of the infected AccessPress software. Anyone running a WordPress site with this company’s offerings should carefully inspect their systems to ensure they’re not running a backdoored instance. Site owners may also want to consider installing a website firewall, many of which would have prevented the backdoor from working.

The attack is the latest example of a supply chain attack, which compromises the source of a legitimate piece of software rather than trying to infect individual users. The technique allows miscreants to infect large numbers of users, and it has the benefit of stealth, since the compromised malware originates from a trusted provider.

Attempts to contact AccessPress Themes for comment were unsuccessful.

https://arstechnica.com/?p=1827592




MoonBounce: il nuovo malware del gruppo APT41 infetta UEFI


Gli hacker, considerati vicini al governo di Pechino, hanno messo a punto un complesso “impianto” che opera a livello di UEFI per evitare il rilevamento.

Sempre più professionali, sempre più difficili da individuare. I gruppi APT (Advanced Persistent Threat) al soldo del governo cinese rappresentano ormai un vero incubo per gli esperti di sicurezza.

A confermare la crescita delle minacce provenienti da Pechino è Kaspersky, che in un report pubblicato sul suo blog descrive in dettaglio le caratteristiche del nuovo malware sviluppato dai pirati informatici del gruppo APT41.

Battezzato con il nome di MoonBounce, il nuovo “impianto” utilizzato dagli hacker di stato sfrutta una tecnica di infezione basata su una “catena” che parte all’avvio della macchina compromessa, all’interno delle funzioni EFI_BOOT_SERVICES.

La sequenza di operazioni eseguite in fase di infezione, come si può dedurre dallo schema riprodotto qui sotto, è estremamente complessa e ha come obiettivo quello di operare a livello del kernel di Windows per impedire il rilevamento del malware.

MoonBounce

In realtà, MoonBounce sfrutta ampiamente un driver malevolo che inietta un malware attivo in modalità utente all’interno di un processo svchost.exe, con lo scopo principale di ottenere una connessione a Internet. Il “cuore” dell’impianto, però, sfrutta un bootkit a livello UEFI che lo rende pressoché invisibile ai software antivirus.

Peggio ancora, il file all’origine dell’infezione viene memorizzato direttamente nella memoria flash SPI della scheda madre. Risultato: per rimuovere il malware non è sufficiente nemmeno la sostituzione del disco fisso.

Stando a quanto riportano gli autori del report, MoonBounce sarebbe stato individuato in un singolo caso, ma il legame con il gruppo APT41 sarebbe confermato.

D’altra parte, APT41 ha caratteristiche estremamente particolari e si è da sempre distinto per l’uso di tecniche estremamente raffinate e di repentini cambi di strategia. Nello scorso marzo, per esempio, i pirati informatici hanno portato un insolito attacco su larga scala nei confronti di aziende e organizzazioni internazionali.

L’imprevedibilità del gruppo APT41 è legata alla sua natura di contractor, piuttosto inusuale tra i gruppi hacker legati al governo di Pechino.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2022/01/20/moonbounce-il-nuovo-malware-del-gruppo-apt41-infetta-uefi/?utm_source=rss&utm_medium=rss&utm_campaign=moonbounce-il-nuovo-malware-del-gruppo-apt41-infetta-uefi




White Rabbit: il nuovo ransomware è legato a FIN8?


Il malware integra sistemi di evasione avanzati nella catena di infezione e sfrutta un classico schema di doppia estorsione per spremere le vittime.

Anche il gruppo FIN8 si lancia nel settore dei ransomware. I pirati informatici, che rappresentano uno dei (rari) casi di APT motivati da interessi finanziari, sono ritenuti responsabili della diffusione di White Rabbit, un crypto-ransomware comparso lo scorso dicembre.

Come spiegano in un report pubblicato su Internet gli esperti di Trend Micro, la strategia adottata dai cyber criminali prevede l’uso di un file relativamente piccolo, che “peserebbe” solo 100KB e utilizzerebbe un sistema di attivazione basato su password. Quella utilizzata nel sample individuato dai ricercatori era “KissMe”.

Lo stratagemma, spiegano gli autori del report, ha l’obiettivo di rendere più difficile il rilevamento del malware e sfrutta un sistema a riga di comando per la sua attivazione.

Per distribuire il payload, il gruppo FIN8 utilizzerebbe una variante di Badhatch, una backdoor già collegata ai pirati informatici in passato.

IL ransomware, in sé, non ha caratteristiche particolari, se non la peculiarità di creare un file di testo contenente la richiesta di riscatto per ogni singolo file crittografato. Gli autori del report non specificano se si tratti di un “bug” del malware o di una strategia per rendere più “pressante” la richiesta.

White Rabbit

Quello che è certo, è che i pirati non lasciano molto margine alle loro vittime: il messaggio fissa un termine di soli quattro giorni per eseguire il pagamento e l’estorsione fa leva, come accaduto già in passato, anche sullo spauracchio di eventuali sanzioni ai sensi del GDPR. I pirati, infatti, minacciano di inviare i file sottratti alle autorità di garanzia nazionali.

White Rabbit

Nel messaggio è indicato anche l’indirizzo di un sito nel circuito TOR che i pirati utilizzano sia per pubblicare alcuni dei dati rubati (come prova dell’avvenuta compromissione), sia una chat dedicata per le trattative sul pagamento di riscatto.

Il legame di White Rabbit con FIN8, c’è da dire, viene indicato con qualche riserva. Gli indizi raccolti da Trend Micro, però, sembrano lasciare pochi dubbi e l’ipotesi che i cyber criminali del gruppo abbiano ampliato il loro raggio d’azione è tutt’altro che remota.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2022/01/19/white-rabbit-il-nuovo-ransomware-e-legato-a-fin8/?utm_source=rss&utm_medium=rss&utm_campaign=white-rabbit-il-nuovo-ransomware-e-legato-a-fin8