Qlocker ransomware gang shuts shop after extorting owners of QNAP NAS drives

With all the headlines about ransomware attacks hitting companies hard, you might think there’s only bad news around the subject. Well, think again. Not only has the Darkside ransomware gang seemingly shut down since the high-profile attack which resul… Continue reading Qlocker ransomware gang shuts shop after extorting owners of QNAP NAS drives

Smashing Security podcast #228: Pipeline pickle, Blockchain bollocks, and Eufy SNAFU

The Colonial Pipeline attack has shone light on the activities of the Darkside ransomware gang, we take a skeptical look at cryptocurrencies and the blockchain, and Eufy security cameras suffer an embarrassing security failure.

All this and much mor… Continue reading Smashing Security podcast #228: Pipeline pickle, Blockchain bollocks, and Eufy SNAFU

DarkSide Ransomware Gang Struck Down — but by Whom?

DarkSide, hackers of the Colonial Pipeline, has hurriedly shut up shop. It claims that its servers and cryptocurrency balances have disappeared.
The post DarkSide Ransomware Gang Struck Down — but by Whom? appeared first on Security Boulevard.
Continue reading DarkSide Ransomware Gang Struck Down — but by Whom?

DarkSide Gang and the New Golden Age of Piracy

Late on Friday May 7, 2021, Colonial Pipeline, the company that runs the largest gasoline pipeline in the US, shut down operations following a ransomware attack on their systems. It later emerged that a relatively new ransomware-as-a-service crimi… Continue reading DarkSide Gang and the New Golden Age of Piracy

Solving the Ransomware Crisis

Ransomware attacks are trivial to execute and there is little, if any, risk and no penalties for the attackers. As a victim, there are no good choices once an organization is hit by ransomware. You can ignore the ransom demand and restore your dat… Continue reading Solving the Ransomware Crisis

Russian cybercrime forum XSS claims to ban ransomware following Colonial Pipeline hack

In the wake of the disruption to Colonial Pipeline, a popular Russian-language criminal forum has claimed it will ban the sale of ransomware tools, according to multiple researchers who monitor the site. XSS, a prominent underground forum for hacking tools and other scams, on May 13 said the platform would forbid “ransomware sales, ransomware rental and ransomware affiliate programs,” according to the threat intelligence firm Digital Shadows. The XSS administrator also claimed it would remove all posts mentioning ransomware. The forum post claimed it was because ransomware was attracting too much “hype” and attention from outsiders, but ransomware operators frequently engage in self-serving public relations stunts. The development pointed to newfound pressure that ransomware operators were feeling following the breach of the IT systems at Colonial Pipeline, the main artery for delivering fuel to the East Coast. The ransomware incident forced Colonial Pipeline to shut down for days. Though service […]

The post Russian cybercrime forum XSS claims to ban ransomware following Colonial Pipeline hack appeared first on CyberScoop.

Continue reading Russian cybercrime forum XSS claims to ban ransomware following Colonial Pipeline hack

Toshiba subsidiary confirms ransomware attack, as reports suggest possible DarkSide involvement

European units of Japanese tech giant Toshiba are investigating a security incident in which scammers may have used a similar hacking tool to the malware used against IT systems at Colonial Pipeline. The European subsidiaries of Toshiba Tec Group said Friday that a cyberattack from a criminal gang had prompted the company to disconnect network connections between Japan and Europe to stop the spread of the malware. In a statement, Toshiba Tec Group, a unit of the multinational conglomerate which makes printers and other technologies, said the firm had “not yet confirmed a fact that customer related information was leaked externally,” though it suggested a criminal gang is responsible. Toshiba Tec Group did not name DarkSide, which is both a type of ransomware and an Eastern European criminal syndicate that develops and sells access to the code to other criminals. An unnamed company Toshiba Tec spokesperson told CNBC that DarkSide […]

The post Toshiba subsidiary confirms ransomware attack, as reports suggest possible DarkSide involvement appeared first on CyberScoop.

Continue reading Toshiba subsidiary confirms ransomware attack, as reports suggest possible DarkSide involvement

Pipeline Ransomware Shows Dangers of Unsecured Infrastructure

The ransomware attack against the Colonial Pipeline is the latest incident targeting critical infrastructure in the United States with severe potential in terms of business continuity and energy disruption. The May 7 attack happened on Friday, a busy … Continue reading Pipeline Ransomware Shows Dangers of Unsecured Infrastructure