LV

LV ransomware has been operating since 2020 and uses a modified variant of REvil ransomware, according to cybersecurity company Secureworks.

RansomEXX

RansomExx is a ransomware variant that debuted as Defray777 in 2018. It made a name for itself in 2020, after it was used in widely reported attacks on government agencies, manufacturers, and other such high-profile only months apart. By then, it was dubbed RansomEXX after the string “ransom.exx” was found in its binary. In 2020, the group also started a leak site for publishing stolen data.

SessionManager

SessionManager backdoor allows threat actors to maintain persistent, update-resistant, and fairly stealthy access to a targeted organization’s IT infrastructure. Once inside a victim’s system, cybercriminals behind the backdoor can gain access to company emails, update malicious access by installing other types of malware, or surreptitiously manage compromised servers, which can be leveraged as malicious infrastructure.

SessionManager has been used in the wild without being detected since at least March 2021, right after the start of last year’s massive wave of ProxyLogon attacks. Implementing a backdoor within IIS is a trend for threat actors. It has affected government institutions and NGOs around the world with victims in eight countries in the Middle East, Turkey and Africa region including Kuwait, Saudi Arabia, Nigeria , Kenya and Turkey.

Meteor

A new file wiping malware called Meteor was discovered used in the recent attacks against Iran’s railway system. The attack itself is dubbed ‘MeteorExpress,’ and utilizes a toolkit of batch files and executables to wipe a system, lock the device’s Master Boot Record (MBR), and install a screen locker.

A wiper is malware that intentionally deletes files on a computer and causes it to become unbootable. Unlike ransomware attacks, destructive wiper attacks are not used to generate revenue for the attackers. Instead, their goal is to cause chaos for an organization or to distract admins while another attack is taking place.

Phoenix Locker

Phoenix Locker, a variant of ransomware dubbed ‘Hades.’ Hades was created by a Russian cybercrime syndicate known as Evil Corp., according to cybersecurity experts.