News | HiddenRefer

Navigation

  • Home
  • Cloud
  • Crime
  • Cyber
  • Data Breaches
  • Drug Raids
  • Privacy
  • Security
Subscribe
News | HiddenRefer

The Best Curated Freebies in One Place

0
0
0
0
News | HiddenRefer
  • Home
  • Cloud
  • Crime
  • Cyber
  • Data Breaches
  • Drug Raids
  • Privacy
  • Security
  • Security

U.S. Charges Venezuelan Doctor for Using and Selling Thanos Ransomware

  • May 17, 2022
  • hiddenrefer
U.S. Charges Venezuelan Doctor for Using and Selling Thanos Ransomware
Total
0
Shares
0
0
0
Advertisements

The U.S. Justice Department on Monday accused a 55-year-old cardiologist from Venezuela of being the mastermind behind Thanos ransomware, charging him with the use and sale of the malicious tool and entering into profit sharing arrangements.

Moises Luis Zagala Gonzalez, also known by the monikers Nosophoros, Aesculapius, and Nebuchadnezzar, is alleged to have both developed and marketed the ransomware to other cybercriminals to facilitate the intrusions and get a share of the bitcoin payment.

If convicted, Zagala faces up to five years’ imprisonment for attempted computer intrusion, and five years’ imprisonment for conspiracy to commit computer intrusions.

“The multi-tasking doctor treated patients, created and named his cyber tool after death, profited from a global ransomware ecosystem in which he sold the tools for conducting ransomware attacks, trained the attackers about how to extort victims, and then boasted about successful attacks, including by malicious actors associated with the government of Iran,” U.S. attorney Breon Peace said.

The ransomware-as-a-service (RaaS) scheme involved encrypting files belonging to companies, non-profit entities, and other institutions, and then demanding a ransom in exchange for the decryption key.

At its core, Thanos is a private ransomware builder that allows its purchasers (aka affiliates) to create their own custom ransomware software, which they could then use or lease it to other actors, effectively widening the scope of the attacks.

An analysis by Recorded Future in June 2020 revealed that the builder comes with 43 different configuration options, calling it the first ransomware family to leverage the RIPlace technique to bypass ransomware protection features built into Windows 10.

CyberSecurity

Options available include the ability to modify the ransom notes, specify the list of file types to be exfiltrated prior to encryption, and settings to evade detection and self-delete the ransomware after execution.

Zagala is believed to have advertised the software on darknet cybercrime forums for $500 a month with “basic options” or $800 with “full options,” while also recruiting affiliates for the RaaS program.

“On or about May 1, 2020, a confidential human source of the FBI (CHS-1) discussed joining Zagala’s ‘affiliate program,'” the DoJ said. “Zagala responded: ‘Not for now. Don’t have spots,” before proceeding to license the software to CHS-1 and helping the informant with tutorials on how to use the software and set up an affiliate crew.

Zagala, who received favorable reviews for his ransomware tools, was ultimately traced on May 3, 2022, after identifying a PayPal account belonging to his relative who resides in the U.S. state of Florida and which used to obtain the illicit proceeds.

“The individual confirmed that Zagala resides in Venezuela and had taught himself computer programming,” the DoJ said.



Total
0
Shares
Share 0
Tweet 0
Pin it 0
hiddenrefer

Previous Article
srv botnet
  • Security

New Sysrv Botnet Variant Hijacking Windows and Linux with Crypto Miners

  • May 17, 2022
  • hiddenrefer
View & Download
Next Article
Nicholas Goldberg: California’s law requiring women on corporate boards was just struck down. I’m glad
  • Crime News

Nicholas Goldberg: California’s law requiring women on corporate boards was just struck down. I’m glad

  • May 17, 2022
  • hiddenrefer
View & Download
You May Also Like
Learn NIST Inside Out With 21 Hours of Training @ 86% OFF
View & Download
  • Security

Learn NIST Inside Out With 21 Hours of Training @ 86% OFF

  • hiddenrefer
  • June 25, 2022
ToddyCat claws at Asian governments
View & Download
  • Security

ToddyCat claws at Asian governments

  • hiddenrefer
  • June 24, 2022
Mitel VoIP Zero-Day
View & Download
  • Security

Hackers Exploit Mitel VoIP Zero-Day in Likely Ransomware Attack

  • hiddenrefer
  • June 24, 2022
Hacking Smartphones with Hermit Spyware
View & Download
  • Security

Google Says ISPs Helped Attackers Infect Targeted Smartphones with Hermit Spyware

  • hiddenrefer
  • June 24, 2022
Backdoored Python Libraries
View & Download
  • Security

Multiple Backdoored Python Libraries Caught Stealing AWS Secrets and Keys

  • hiddenrefer
  • June 24, 2022
Ransomware as a Decoy for Cyber Espionage Attacks
View & Download
  • Security

State-Backed Hackers Using Ransomware as a Decoy for Cyber Espionage Attacks

  • hiddenrefer
  • June 24, 2022
New 'Quantum' Builder Lets Attackers Easily Create Malicious Windows Shortcuts
View & Download
  • Security

New ‘Quantum’ Builder Lets Attackers Easily Create Malicious Windows Shortcuts

  • hiddenrefer
  • June 24, 2022
Log4Shell Still Being Exploited to Hack VMWare Servers to Exfiltrate Sensitive Data
View & Download
  • Security

Log4Shell Still Being Exploited to Hack VMWare Servers to Exfiltrate Sensitive Data

  • hiddenrefer
  • June 24, 2022
  • NYPD reports slashed in the face on subway near Wall Street station
    NYPD reports slashed in the face on subway near Wall Street station
    • June 26, 2022
  • Man pushed onto NYC subway tracks after trying to break up fight
    Man pushed onto NYC subway tracks after trying to break up fight
    • June 26, 2022
  • Fire in Jurupa Valley prompts mandatory evacuations
    Fire in Jurupa Valley prompts mandatory evacuations
    • June 26, 2022
  • Man injured in shooting on BART train in Oakland
    Man injured in shooting on BART train in Oakland
    • June 26, 2022
  • Bodies of victims in NYC triple homicide decomposed
    Bodies of victims in NYC triple homicide decomposed
    • June 25, 2022

Featured Categories

Cloud Security
248 Posts
View Posts
Crime News
3833 Posts
View Posts
Cybersecurity
234 Posts
View Posts
Data Breaches
82 Posts
View Posts
Drug Raids
137 Posts
View Posts
Privacy
101 Posts
View Posts
Security
1180 Posts
View Posts
about
Navigation
  • Home
  • Cloud
  • Crime
  • Cyber
  • Data Breaches
  • Drug Raids
  • Privacy
  • Security
Featured
  • NYPD reports slashed in the face on subway near Wall Street station
    NYPD reports slashed in the face on subway near Wall Street station
    • June 26, 2022
  • Man pushed onto NYC subway tracks after trying to break up fight
    Man pushed onto NYC subway tracks after trying to break up fight
    • June 26, 2022
  • Fire in Jurupa Valley prompts mandatory evacuations
    Fire in Jurupa Valley prompts mandatory evacuations
    • June 26, 2022
  • Man injured in shooting on BART train in Oakland
    Man injured in shooting on BART train in Oakland
    • June 26, 2022
  • Bodies of victims in NYC triple homicide decomposed
    Bodies of victims in NYC triple homicide decomposed
    • June 25, 2022
News | HiddenRefer
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Input your search keywords and press Enter.