Ransomware [Target: AU Prison]
Ransomware attack caused at least a weeklong outage that affected its sites, including its load board, online carrier safety vetting, and payment services.
Ransomware attack caused at least a weeklong outage that affected its sites, including its load board, online carrier safety vetting, and payment services.
UC added officials do not believe university’s systems or networks ended up compromised as a result. The school system said it reported the incident to federal law enforcement, took measures to contain it and has begun an investigation.
Nefilim Ransomware group publishes teaser files and threatens to release victims stolen data to the public if ransom is not paid.
Triton is malware first discovered at a Saudi Arabian petrochemical plant in 2017.[1][2] It can disable safety instrumented systems, which can then contribute to a plant disaster. It has been called “the world’s most murderous malware.”[3]
In December 2017, it was reported that the safety systems of an unidentified power station, believed to be in Saudi Arabia, were compromised when the Triconex industrial safety technology made by Schneider Electric SE was targeted in what is believed to have been a state sponsored attack. The computer security company Symantec claimed that the malware, known as “Triton”, exploited a vulnerability in computers running the Microsoft Windows operating system.[2]
In 2018, FireEye, a company that researches cyber-security, reported that the malware most likely came from the Central Scientific Research Institute of Chemistry and Mechanics (CNIIHM), a research entity in Russia.[4]
Shamoon, also known as W32.DistTrack, is a modular computer virus that was discovered in 2012, targeting then-recent 32-bit NT kernel versions of Microsoft Windows. The virus was notable due to the destructive nature of the attack and the cost of recovery. Shamoon can spread from an infected machine to other computers on the network. Once a system is infected, the virus continues to compile a list of files from specific locations on the system, upload them to the attacker, and erase them. Finally the virus overwrites the master boot record of the infected computer, making it unusable.