News | HiddenRefer

Navigation

  • Home
  • Cloud
  • Crime
  • Cyber
  • Data Breaches
  • Drug Raids
  • Privacy
  • Security
Subscribe
News | HiddenRefer

The Best Curated Freebies in One Place

0
0
0
0
News | HiddenRefer
  • Home
  • Cloud
  • Crime
  • Cyber
  • Data Breaches
  • Drug Raids
  • Privacy
  • Security
  • Security

Russian Courts Targeted by New CryWiper Data Wiper Malware Posing as Ransomware

  • December 5, 2022
  • hiddenrefer
CryWiper Data Wiper Malware
Total
0
Shares
0
0
0
Advertisements

Dec 05, 2022Ravie LakshmananEndpoint Security / Data Protection

A new data wiper malware called CryWiper has been found targeting Russian government agencies, including mayor’s offices and courts.

“Although it disguises itself as a ransomware and extorts money from the victim for ‘decrypting’ data, [it] does not actually encrypt, but purposefully destroys data in the affected system,” Kaspersky researchers Fedor Sinitsyn and Janis Zinchenko said in a write-up.

Additional details of the attacks were shared by the Russian-language news publication Izvestia. The intrusions have not been attributed to a specific adversarial group so far.

CyberSecurity

A C++-based malware, CryWiper is configured to establish persistence via a scheduled task and communicate with a command-and-control (C2) server to initiate the malicious activity.

Besides terminating processes related to database and email servers, the malware is equipped with capabilities to delete shadow copies of files and modify the Windows Registry to prevent RDP connections in a likely attempt to obstruct incident response efforts.

As the last step, the wiper corrupts all files with the exception of those with “.exe,” “.dll,” “lnk,” “.sys,” and “.msi” extensions, while also skipping specific directories, including C:Windows, Boot, and tmp, which could otherwise render the machine inoperable.

The files overwritten with garbage data are subsequently appended with an extension called “.CRY,” following which a ransom note is dropped to give the impression that it’s a ransomware program, urging the victim to pay 0.5 Bitcoin to recover access.

“The activity of CryWiper once again shows that the payment of the ransom does not guarantee the recovery of files,” the researchers said, stating the malware “deliberately destroys the contents of files.”

CryWiper is the second retaliatory wiper malware strain aimed at Russia after RURansom, a .NET-based wiper that was found targeting entities in the country earlier this March.

The ongoing conflict between Russia and Ukraine has involved the deployment of multiple wipers, with the latter hit with a wide range of malware such as WhisperGate, HermeticWiper, AcidRain, IsaacWiper, CaddyWiper, Industroyer2, and DoubleZero.

“Wipers can be effective regardless of the technical skills of the attacker, as even the simplest wiper can wreak havoc on affected systems,” Trellix researcher Max Kersten said in an analysis of destructive malware last month.

“The required time to create such a piece of malware is low, especially when compared to complex espionage backdoors and the often-accompanying vulnerabilities that are used. The return of investment need not be high in those cases, although it is unlikely that a few wipers are to wreak that much havoc in and of themselves.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.



Total
0
Shares
Share 0
Tweet 0
Pin it 0
hiddenrefer

Previous Article
Attack Surface
  • Security

When Being Attractive Gets Risky

  • December 5, 2022
  • hiddenrefer
View & Download
Next Article
Local air regulators say they need federal government help
  • Crime News

Local air regulators say they need federal government help

  • December 5, 2022
  • hiddenrefer
View & Download
You May Also Like
Microsoft Urges Customers to Secure On-Premises Exchange Servers
View & Download
  • Security

Microsoft Urges Customers to Secure On-Premises Exchange Servers

  • hiddenrefer
  • January 28, 2023
SaaS Shadow IT
View & Download
  • Security

Eliminating SaaS Shadow IT is Now Available via a Self-Service Product, Free of Charge

  • hiddenrefer
  • January 28, 2023
BIND DNS Software Vulnerabilities
View & Download
  • Security

ISC Releases Security Patches for New BIND DNS Software Vulnerabilities

  • hiddenrefer
  • January 28, 2023
Wiper Malware
View & Download
  • Security

Ukraine Hit with New Golang-based ‘SwiftSlicer’ Wiper Malware in Latest Cyber Attack

  • hiddenrefer
  • January 28, 2023
Golden Chickens Malware Service
View & Download
  • Security

Experts Uncover the Identity of Mastermind Behind Golden Chickens Malware Service

  • hiddenrefer
  • January 27, 2023
PlugX Malware
View & Download
  • Security

Researchers Discover New PlugX Malware Variant Spreading via Removable USB Devices

  • hiddenrefer
  • January 27, 2023
Analyzing Orcus RAT
View & Download
  • Security

3 Lifehacks While Analyzing Orcus RAT in a Malware Sandbox

  • hiddenrefer
  • January 27, 2023
British Cyber Agency
View & Download
  • Security

British Cyber Agency Warns of Russian and Iranian Hackers Targeting Key Industries

  • hiddenrefer
  • January 27, 2023
  • Letters to the Editor — Jan. 29, 2023
    Letters to the Editor — Jan. 29, 2023
    • January 29, 2023
  • Desmond Mills Jr. might not have been able 'to see' during Tyre Nichols beating: lawyer
    Desmond Mills Jr. might not have been able ‘to see’ during Tyre Nichols beating: lawyer
    • January 28, 2023
  • What Tyre Nichols, Rodney King tell us about race, policing
    What Tyre Nichols, Rodney King tell us about race, policing
    • January 28, 2023
  • Deadly Duo: Ivon and Alysia Adams are charged with the murder and abuse of 4-year-old Athena Brownfield, who was finally reported missing on 1/10/2023, but probably killed on Christmas
    Deadly Duo: Ivon and Alysia Adams are charged with the murder and abuse of 4-year-old Athena Brownfield, who was finally reported missing on 1/10/2023, but probably killed on Christmas
    • January 28, 2023
  • On The Statewide Montana Talks Network at SHOT Show 2023: Discussing a wide range of crime and gun control issues
    On The Statewide Montana Talks Network at SHOT Show 2023: Discussing a wide range of crime and gun control issues
    • January 28, 2023

Featured Categories

Cloud Security
286 Posts
View Posts
Crime News
7487 Posts
View Posts
Cybersecurity
364 Posts
View Posts
Data Breaches
91 Posts
View Posts
Drug Raids
155 Posts
View Posts
Privacy
146 Posts
View Posts
Security
2250 Posts
View Posts
about
Navigation
  • Home
  • Cloud
  • Crime
  • Cyber
  • Data Breaches
  • Drug Raids
  • Privacy
  • Security
Featured
  • Letters to the Editor — Jan. 29, 2023
    Letters to the Editor — Jan. 29, 2023
    • January 29, 2023
  • Desmond Mills Jr. might not have been able 'to see' during Tyre Nichols beating: lawyer
    Desmond Mills Jr. might not have been able ‘to see’ during Tyre Nichols beating: lawyer
    • January 28, 2023
  • What Tyre Nichols, Rodney King tell us about race, policing
    What Tyre Nichols, Rodney King tell us about race, policing
    • January 28, 2023
  • Deadly Duo: Ivon and Alysia Adams are charged with the murder and abuse of 4-year-old Athena Brownfield, who was finally reported missing on 1/10/2023, but probably killed on Christmas
    Deadly Duo: Ivon and Alysia Adams are charged with the murder and abuse of 4-year-old Athena Brownfield, who was finally reported missing on 1/10/2023, but probably killed on Christmas
    • January 28, 2023
  • On The Statewide Montana Talks Network at SHOT Show 2023: Discussing a wide range of crime and gun control issues
    On The Statewide Montana Talks Network at SHOT Show 2023: Discussing a wide range of crime and gun control issues
    • January 28, 2023
News | HiddenRefer
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Input your search keywords and press Enter.