Meet Brain Cipher — The new ransomware behind Indonesia’s data center attack

June 29, 2024 at 11:02AM Brain Cipher, a new ransomware operation, has targeted organizations globally. In a recent high-profile attack on Indonesia’s temporary National Data Center, over 200 government agencies were disrupted. The ransomware demanded $8 million in Monero cryptocurrency and threatened to leak allegedly stolen data. Brain Cipher also launched a data leak site … Read more

LockBit 3.0 Variant Generates Custom, Self-Propagating Malware

April 16, 2024 at 09:47AM The LockBit ransomware group launched a sophisticated attack in West Africa using a leaked variant of LockBit 3.0. Kaspersky discovered this new variant and flagged its ability to generate custom, self-propagating ransomware. The attack involved using leaked privileged credentials and affected multiple systems. Organizations are advised to take preventive measures … Read more

Subway Puts a LockBit Investigation on the Menu

January 23, 2024 at 03:56PM Subway is investigating claims by the LockBit 3.0 ransomware gang that they’ve breached the company’s internal system and plan to sell the data unless a ransom is paid. This potential shift in LockBit’s targets raises concerns, as they typically focus on midsize or small companies. Experts recommend implementing robust cybersecurity … Read more

3 Ransomware Group Newcomers to Watch in 2024

January 15, 2024 at 11:44AM The ransomware industry witnessed a significant 55.5% surge in victims worldwide in 2023, totaling 4,368 cases. Groups like LockBit 3.0, AlphV, and Cl0p were notable contributors. Emerging groups like 3AM, Rhysida, and Akira also made an impact. Cyberint expects these new players to further establish themselves alongside veteran groups in … Read more

Egyptian E-Payment Vendor Recovering From LockBit Ransomware Attack

November 28, 2023 at 12:29PM The LockBit 3.0 ransomware group successfully encrypted files and allegedly stole data from Egyptian e-payment provider Fawry. Personal details of Fawry customers were said to have been extracted, leading to banks advising customers to remove their account information. Fawry remains confident that financial transactions will not be impacted, but leaked … Read more

#StopRansomware: LockBit 3.0 Ransomware Affiliates Exploit CVE 2023-4966 Citrix Bleed Vulnerability

November 21, 2023 at 11:29AM This joint Cybersecurity Advisory (CSA) aims to provide network defenders with information about the LockBit 3.0 ransomware and its exploitation of the CVE-2023-4966 vulnerability affecting Citrix NetScaler web application delivery control (ADC) and NetScaler Gateway appliances. The CSA includes tactics, techniques, and indicators of compromise (IOCs) obtained from various organizations, … Read more