Malware

Pierluigi Paganini May 17, 2016
Redirector.Paco, a Million-Machine Clickfraud Botnet

According to the experts at Bitdefender an HTTPS hijacking click-fraud botnet dubbed Redirector.Paco infected almost 1 million devices since now. Security experts at Bitdefender spotted a new click fraud botnet dubbed Redirector.Paco that has been around at least since September 2014 and has already infected more than 900,000 devices over the years. Crooks behind the Redirector.Paco aimed to create a clickbot that […]

Pierluigi Paganini May 16, 2016
Experts also cracked the CryptXXX ransomware 2.0

Security Experts at Kaspersky have updated their decryption tool to adapt to the second version of CryptXXX ransomware in the RannohDecryptor 1.9.1.0. A couple of hours ago I published an interesting post the summarizes the ransomware activities in the last week, and unfortunately, this kind of malware is becoming even more popular in the criminal underground. […]

Pierluigi Paganini May 15, 2016
Week in Ransomware – Week of May 13th, 2016

Just in a week several new ransomware variants, services, and updates have been discovered in-the-wild, disclosed publicly, and thoroughly analyzed. Statistical Summary This week, in a span of just five (5) days (Monday, May 9th, 2016 – Friday, May 13th, 2016), through the collaborative efforts of several organizations and individual analysts around the globe, several […]

Pierluigi Paganini May 15, 2016
Malware used in the recent banking cyberheists is linked to Sony Pictures hack

Experts at the BAE security firms collected evidence that demonstrates the malware used in the recent cyberheists is linked to 2014 Sony Pictures hack. A second bank was a victim of a malware-based attack, the news was recently confirmed by the SWIFT. The investigation conducted by the security researchers at BAE Systems are making the situation very intriguing because […]

Pierluigi Paganini May 07, 2016
STUPID LOCKY! Hackers disrupted a Locky ransomware Campaing

Hackers have disrupted a Locky campaign after they compromised one of the cybercriminal servers used by the threat actors. According to the security expert Sven Carlsen from Avira, hackers have dismantled a Locky campaign by hacking the command and control server. Carlsen explained that threat actors behind the Locky campaign spread the threat via spam […]

Pierluigi Paganini May 06, 2016
Robin Hood CyptMix ransomware promises to donate fee to charity

This is a novelty in the cyber criminal underground, crooks behind the new born CyptMix ransomware promise to donate the fee to charity. No doubts, a very creative idea to extort money to the victims enticing them to pay for a good cause and telling them to think to have the opportunity to help the children. […]

Pierluigi Paganini May 04, 2016
The Infy malware, a long running threat from Iran

Researchers at Palo Alto Networks have come across a new threat used by alleged Iran-linked Hackers in attacks since 2007. Security experts at Palo Alto Networks discovered a new malware, named Infy, that has been likely used by hackers from Iran in cyber espionage operations at least since 2007. The researchers discovered the Infy malware […]

Pierluigi Paganini May 04, 2016
Author of the Gozi Banking Trojan ordered to pay $7 Million

The author of the Gozi Banking Trojan who spent about 3 years in jail has been ordered to pay $7 Million to cover damages he caused to banks. Nikita Kuzmin, a 28-year-old Russian national who created the notorious Gozi banking Trojan, has been sentenced to time served and ordered to pay nearly $7 million. Recently […]

Pierluigi Paganini May 01, 2016
Pirate Bay visitors infected with Cerber ransomware via bad ads

Experts at MalwareBytes discovered that Pirate Bay users have been targeted by a malvertising campaign serving the Cerber crypto-ransomware. Recently the visitors of the Pirate Bay website were infected with crypto-ransomware.  Threat actors launched a malvertising attack on Pirate Bay and leveraged on bad ads to serve a ransomware. According to the experts at Malwarebytes attackers used […]

Pierluigi Paganini April 30, 2016
BWL Electric and Water Utility shut down by ransomware

The Lansing Board of Water & Light (BWL) utility has had to shut down systems, phone lines in response to a ransomware-based attack. The Lansing Board of Water & Light (BWL) utility has had to shut down systems, phone lines in response to a ransomware-based attack. Another ransomware attack against a critical infrastructure is in […]