It has been an interesting week with decryptors released, ransomware gangs continuing to rail against negotiators, and the US government expected to sanction crypto exchanges next week.
While the decryptior has a few bugs that still need to be worked out that lead to corrupted data in certain situations, our decryption tests show that it works against REvil samples as far back as May 2019.
The US government is expected to disrupt further ransomware attacks by sanctioning crypto exchanges, wallets, and traders that aid cybercriminals.
Finally, ransomware gangs use phishing attacks with malicious Word documents that utilize the Windows MSHTML vulnerability tracked as CVE-2021-40444. When opened, the malicious documents would install Cobalt Strike to provide network access to the attackers.
And if they weren’t struggling enough already, it appears that Missouri Delta Medical Center (MDMC) might also be dealing with a ransomware attack by Hive threat actors. So far, however, MDMC has been tight-lipped about the claimed attack and has not responded to inquiries asking them to confirm or deny the claim.
Olympus, a leading medical technology company, is investigating a “potential cybersecurity incident” that impacted some of its EMEA (Europe, Middle East, Africa) IT systems last week.
A “Russian hacker” who collaborated with the well-known REvil group confirmed to Lente.ru that cybercriminals returned to active activity after a two-month break. He named political reasons as the main reason for their withdrawal into the shadows. This refutes the claims of the REvil members themselves, who explained the short-term simple precautions following the disappearance of one of the community members.
A free master decryptor for the REvil ransomware operation has been released, allowing all victims encrypted before the gang disappeared to recover their files for free.
Microsoft says multiple threat actors, including ransomware affiliates, are targeting the recently patched Windows MSHTML remote code execution security flaw.
The Biden administration is expected to issue sanctions against crypto exchanges, wallets, and traders used by ransomware gangs to convert ransom payments into fiat money.
That’s it for this week! Hope everyone has a nice weekend!