The Week in Ransomware – November 3rd 2023 – Hive’s Back

The Week in Ransomware - November 3rd 2023 - Hive's Back

November 3, 2023 at 05:10PM

Ransomware attacks have been on the rise recently, with various organizations falling victim, including the Toronto Public Library, ACE Hardware, Mr. Cooper, and the British Library. In response, a coalition of 40 countries will pledge to stop paying ransom demands. Microsoft also commits to enhancing security through its ‘Secure Future’ initiative. New research reveals the return of the Hive ransomware group and the emergence of Hunters International. Additional attacks and breaches are reported, including those on Stanford University, Israeli companies, and Canadian hospitals. Boeing, Mr. Cooper, and Henry Schein are among the companies affected. GhostSec introduces a Ransomware-as-a-Service framework called GhostLocker.

Meeting Takeaways:
1. Ransomware attacks have been escalating in recent months, with new operations launching and old ones returning.
2. Several high-profile organizations, including the Toronto Public Library, ACE Hardware, Mr. Cooper, and the British Library, have been targeted by ransomware attacks.
3. An alliance of 40 countries is set to sign a pledge to stop paying ransom demands during the International Counter-Ransomware Initiative summit in Washington, D.C. However, it may not prevent local governments from giving in to extortion demands.
4. Microsoft is launching the ‘Secure Future’ initiative to enhance the security of its products and platforms.
5. New research highlights the possibility of Hive’s return following previous disruption by the FBI.
6. Various ransomware variants with different file extensions and ransom notes have been discovered by PCrisk.
7. Recent cyberattacks have targeted organizations such as Stanford University, Israeli companies, the British Library, and five Canadian hospitals in Ontario.
8. Boeing, Mr. Cooper, and Henry Schein are among the companies that have experienced cyberattacks and data breaches.
9. The HelloKitty ransomware operation is exploiting a recently disclosed vulnerability to breach networks.
10. GhostSec, a hacker collective, has introduced a Ransomware-as-a-Service (RaaS) framework called GhostLocker, with a focus on targeting Israel.

Note: These takeaways summarize the main points discussed in the meeting notes. For more detailed information, please refer to the original notes.

Full Article