Thursday , September 19 2024
blacksuit

CISA, FBI released joint advisory for Blacksuit ransomware

The FBI and CISA updated their advisory to confirm that the Royal ransomware group now goes by the name “BlackSuit” and still demands very high ransom amounts, up to $60 million.

The advisory has new technical information to help defenders detect the activity of the group, known as Royal ransomware from September 2022 to July 2023 and now called BlackSuit.

Joint cybersecurity advisory
Botnet infects 260,000 SOHO routers, IP cameras with malware

The FBI has alerted that cyber actors have compromised over 260,000 internet-connected devices, mainly routers, to form a large botnet...
Read More
Joint cybersecurity advisory  Botnet infects 260,000 SOHO routers, IP cameras with malware

Chrome 129 Released Fix with multiple Security Flaws

Google has released Chrome 129 for Windows, Mac, and Linux users. The update will be available gradually over the next...
Read More
Chrome 129 Released Fix with multiple Security Flaws

Broadcom fixed RCE bug in VMware vCenter Server

Broadcom has fixed a serious VMware vCenter Server vulnerability that allows attackers to execute remote code on unpatched servers through...
Read More
Broadcom fixed RCE bug in VMware vCenter Server

Cybercriminal now misuse Microsoft Azure tool to steal data

Ransomware groups like BianLian and Rhysida use Microsoft's Azure Storage Explorer and AzCopy to steal data from hacked networks and...
Read More
Cybercriminal now misuse Microsoft Azure tool to steal data

Apple warns users to install iOS 18 to Fix 33 iPhone Vulnerabilities

Apple has released iOS 18, the latest update for iPhones and iPads. Along with new features, it mainly focuses on...
Read More
Apple warns users to install iOS 18 to Fix 33 iPhone Vulnerabilities

CISA adds windows and whatsUp Gold vuls to its KEV

CISA has warned Microsoft Windows MSHTML Platform Spoofing Vulnerability and Progress WhatsUp Gold SQL Injection Vulnerability actively exploited security flaws,...
Read More
CISA adds windows and whatsUp Gold vuls to its KEV

Petroleum and Fuel Industry
FleetPanda exposes Nearly One Million Documents

Cybersecurity researcher Jeremiah Fowler found a non-password-protected database with 780,000 records from FleetPanda, a tech provider for dispatch management. The...
Read More
Petroleum and Fuel Industry  FleetPanda exposes Nearly One Million Documents

DESCO faces cyber attack: Customers Data Breach

A recent dark web scan revealed that customer data from Dhaka Electric Supply Company Limited (DESCO) has been exposed. The...
Read More
DESCO faces cyber attack: Customers Data Breach

Alert! Google Fixes GCP Composer Flaw

Tenable Research found and fixed a remote code execution (RCE) vulnerability, called CloudImposer, in Google Cloud Platform (GCP). This flaw...
Read More
Alert! Google Fixes GCP Composer Flaw

CTF in Bangladesh: Unveiling Challenges, Opportunities and remedies

In this article, we won’t dive too deep into the technical aspects of Capture The Flag (CTF) competitions. Instead, we...
Read More
CTF in Bangladesh: Unveiling Challenges, Opportunities and remedies

The group got attention from the police last summer when they attacked Dallas, causing damage to the city’s emergency services, courts, and government. In November, the FBI and CISA warned that Royal was transitioning to the “BlackSuit” branding for attacks. The latest update confirms that all of the group’s new attacks, some as recent as July, are linked to the new name.

“Ransom demands have typically ranged from approximately $1 million to $10 million, with payment demanded in Bitcoin,” the agencies said. “BlackSuit actors have exhibited a willingness to negotiate payment amounts.”

The agencies linked the hackers behind the two groups based on “numerous coding similarities” but noted that BlackSuit has “exhibited improved capabilities.”

Hackers still rely on phishing emails to launch successful attacks. They use these emails to gain initial access, disable antivirus software, steal a lot of data, and deploy ransomware.

The agencies noted there has been a recent uptick in attacks where victims “received telephonic or email communications from BlackSuit actors regarding the compromise and ransom.”

A new report from Sophos, a cybersecurity company, revealed that several ransomware groups are using this tactic to pressure victims into paying ransoms. Ransomware gangs have been contacting patients and customers of multiple hospitals and businesses, threatening them with data stolen or accessed during attacks.

According to Chester Wisniewski, Sophos Field CTO, ransomware gangs used to rely on media coverage to scare victims. However, in recent times, these groups have started directly contacting customers and patients as a new way to apply pressure.

Wisniewski argued that the tactic has not been successful, as companies mostly base their decision to pay ransoms on practical factors such as business downtime and regulatory concerns.

Check Also

zyxel

Zyxel Issues Hotfix for EOL NAS product

Zyxel issued hotfixes for a severe command injection vulnerability traced as CVE-2024-6342, affecting its NAS326 …

Leave a Reply

Your email address will not be published. Required fields are marked *