The latest industry news, interviews, technologies, and resources.
Supersuso is a ransomware intended to encrypt sensitive data in order to restrict access to it. During the encryption process, this malware sample adds the extension .ICQ_SUPERSUSO to mark inaccessible files. When the…
BigLock is a ransomware discovered in 2020 and also known as "corona-lock." It encrypts files on the victim system with chacha and AES encryption as specified by the ransomware authors…
EXECUTIVE SUMMARY A critical Remote Code Execution Vulnerability tracked as CVE-2021-44228 in Apache Log4j has been found to be exploited in the wild. Upon analysis of the associated Indicators…
Makop Ransomware Analysis Brief Introduction: Makop ransomware is the latest malware and is trending currently. It instructs the users/victims to contact the malware authors via Tox, a P2P instant messaging…
KARMA Leak Ransomware Technical Analysis Risk Score: 8 Confidence Level: High Suspected Malware: Karma Leak Malware. Function: Ransomware. Tactic Used: Data Encryption. Other Malwares related to Karma: GangBang, Milihpen,…
Malware Analysis related to APT41 - STEALTHVECTOR Risk Score: 8. Confidence Level: High. Suspected Malware: Trojan.Win64.STEALTHVECTOR.SMZTID-B Malicious Loader Sample Analysis: MD5: b3f3de10b3c1c15491c53223f1b5979f SHA256: 91aa05e3666c7e2443fc1f0f0142f1829f5ec51e289c95b10811531da50eb2b3 File Details: As shown in…
Ongoing analysis of Gh0st RAT Blacklisted IP: 23[.]225.73.110 Risk Score: 10 Confidence Level: High Associated Malware: Gh0st RAT Function: Gh0st RAT C&C ITW Associations: EMISSARY PANDA, Hurricane Panda, Lazarus Group,…
Overview Risk Score: 8 Confidence Level: High Suspected Malware: FormBook Malware/Trojan Function: Information Stealing, Credential Harvesting and download/drops stealthier malware Tactic Used: Process Injection/Process Hollowing Threat actor Associations: ng-Code Other…
Malware Research on AtomSilo Ransomware AtomSilo is a new Ransomware recently seen in September 2021 during one of their attacks by exploiting a recently revealed vulnerability (CVE-2021-26084) in Atlassian’s Confluence…
By CYFIRMA Research First Published on 6 August 2021 EXECUTIVE SUMMARY REvil ransomware has set a price for decrypting all systems locked during the Kaseya supply-chain attack and has exploited…
Your iFrame Code