It has been a hectic week, with law enforcement conducting two successful law enforcement operations that will significantly impact ransomware.
This week’s biggest news is the law enforcement takedown of the Emotet botnet, followed by the seizing of Tor sites and the arrest of an affiliate for the very active Netwalker ransomware.
Emotet is a significant contributor to ransomware attacks as it installs malware that commonly leads to Ryuk, Conti, Egregor, and ProLock attacks.
This week’s other interesting news is the Avaddon ransomware gang beginning to use DDoS attacks to force victims to the negotiation table. IObit also continued to be harassed by the DeroHE ransomware developers who defaced their forums.
We also saw large enterprise attacks come back after the holidays with attacks on Palfinger and Dairy Farm.
Contributors and those who provided new ransomware information and stories this week include: @demonslay335, @Seifreed, @PolarToffee, @BleepinComputer, @serghei, @FourOctets, @Ionut_Ilascu, @struppigel, @malwareforme, @jorntvdw, @VK_Intel, @LawrenceAbrams, @DanielGallagher, @malwrhunterteam, @fwosar, @BrettCallow, @GrujaRS, @Amigo-A_, @petrovic082, @chum1ng0, @benkow_, @csis_cyber, @Kangxiaopao, @raby_mr, and @RakeshKrish12.
January 24th 2021
Another ransomware now uses DDoS attacks to force victims to pay
Another ransomware gang is now using DDoS attacks to force a victim to contact them and negotiate a ransom.
GrujaRS found a new ransomware called CobraLocker that drops a ransom note named readme.txt.
January 25th 2021
Ransomware gang taunts IObit with repeated forum hacks
A ransomware gang continues to taunt Windows software developer IObit by hacking its forums to display a ransom demand.
Leading crane maker Palfinger hit in global cyberattack
Leading crane and lifting manufacturer Palfinger is targeted in an ongoing cyberattack that has disrupted IT systems and business operations.
The Nemty affiliate model
Almost a year after the end of the operations of the Nemty ransomware, we are presenting some internal details of their operations between 2019 and 2020 in order to document the business model and the actors that evolved around that group.
January 26th 2021
Pan-Asian retail giant Dairy Farm suffers REvil ransomware attack
Massive pan-Asian retail chain operator Dairy Farm Group was attacked this month by the REvil ransomware operation. The attackers claim to have demanded a $30 million ransom.
xiaopao found a new Xorist Ransomware variant that appends the .CryptPethya extension.
xiaopao found new Xoris ransomware variants that append the .http://zaplat.za and .EnCryp13d extensions.
January 27th 2021
Europol: Emotet malware will uninstall itself on April 25th
Law enforcement has started to distribute an Emotet module to infected devices that will uninstall the malware on April 25th, 2021.
Netwalker ransomware dark web sites seized by law enforcement
The dark web websites associated with the Netwalker ransomware operation have been seized by law enforcement from the USA and Bulgaria.
US charges NetWalker ransomware affiliate, seizes ransom payments
The U.S. Justice Department announced today the disruption of the Netwalker ransomware operation and the indictment of a Canadian national for alleged involvement in the file-encrypting extortion attacks.
Petrovic found a new ransomware named Namaste that appends the ._enc extension to encrypted files.
Rakesh Krishnan found a new Ransomware-as-a-Service Egalyty that is based after Ranion.
January 28th 2021
Amigo-A found a new variant of the STOP Ransomware that appends the .pola extension to encrypted files.
The DarkSide ransomware operation issued a new “press release” stating that they will no longer attack certain organizations.
January 29th 2021
Vovalex is likely the first ransomware written in D
A new ransomware called Vovalex is being distributed through fake pirated software that impersonates popular Windows utilities, such as CCleaner.
xiaopao found new Paradise ransomware variant that appends the .Cukiesi extension to encrypted files.
xiaopao found the new WormLocker ransomware that does not append an extension to encrypted files.
New Dharma Ransomware variant
Ravi found a new Dharma ransomware variant that appends the .NOV extension to encrypted files.
That’s it for this week! Hope everyone has a nice weekend!