Gandcrab via fake invoice using password protected zip files

It’s Friday afternoon at the end of a busy week for many people and we get yet another Gandcrab ransomware campaign. This campaign is slightly different to previous versions that I have seen. We generally see Gandcrab delivered via Office ( norma… Continue reading Gandcrab via fake invoice using password protected zip files

Godaddy DNS system still compromised to deliver yet another Gandgrab Ransomware campaign

Last week we reported on a fairly large scale Gandcrab ransomware campaign that was assisted in delivery via a security hole in Godaddy (and almost certainly other major DNS providers). Some of the major tech sites reported on the DNS compromise with a… Continue reading Godaddy DNS system still compromised to deliver yet another Gandgrab Ransomware campaign

Gandcrab 5.1 via Uр to date emergenсy exit maр malspam from Rosie L. Ashton

Last night we received several emails to various email addresses on this server using a template we first saw back in Early December 2018. They are still using  Rosie L. Ashton as the sender. Then it delivered Ursnif banking trojan. Today it is deliver… Continue reading Gandcrab 5.1 via Uр to date emergenсy exit maр malspam from Rosie L. Ashton