BlackBerry and KPMG’s UK Cyber Response Services uncovered a new ransomware strain that uses an obscure file format to avoid detection, according to new research published Thursday. After researchers conducted forensic investigations at a European educational institution, they uncovered that attackers had gained access to the unnamed institution through an internet-connected remote desktop server, according to the Blackberry Research and Intelligence Team. The ransomware, which Blackberry has dubbed Tycoon, uses a little known Java image format to avoid detection and then encrypts file servers, locking administrators out unless they pay a ransom. Tycoon is highly targeted and has affected only approximately a dozen victims, BlackBerry’s Vice President of GUARD Services and Director of GUARD Threat Hunting & Intelligence, Eric Milam and Claudiu Teodorescu, told CyberScoop. The ransomware has generally targeted small- and medium-sized education and software entities so far. And although the new ransomware has only affected a limited number of victims, Tycoon is a reminder that even […]
The post There’s a new Java ransomware family on the block appeared first on CyberScoop.
Continue reading There’s a new Java ransomware family on the block→