Last Week in Ransomware: Week of August 16th

This week was a win with REvil and SynACK decryption keys being released, but also saw a rise in PrintNightmare use by ransomware gangs.
Michael Raymond
1 min read
Last updated June 30, 2022

Phishing attacks are one common vector used to gain access to a network for ransomware attacks and it seems there might be yet another way to hide these phishing attacks using old school Morse code. But Phishing should be your only security concern.

If you haven’t applied security patches in relation to the windows PrintNightmare vulnerability it’s well past time to do so. Most if not all major ransomware strains are now actively exploiting PrintNightmare.

In the past week, LockBit 2.0 has been incredibly active prompting the Australian government to issue warnings for Australian companies. A recent article on The Hacker News looks at why ransomware is becoming more prevalent and unsurprisingly concludes that it’s due to ease of use led by Ransomware as a Service (RaaS) and the profitability.

But not all gangs a driven purely by profit. New research suggests that Russian intelligence services including the FSB and SVR actively worked with ransomware gangs to target and compromise US organizations with a variant of Ryuk ransomware called Sidoh.

Recent reporting highlights yet again the fact that these ransomware gangs have little care about the aftermath of their attacks. Approximately half of US hospitals have disconnected their networks at some point in the past 6 months because of ransomware threats.

Over the weekend Last Week Tonight with John Oliver released an episode focused on ransomware. While the episode’s humor may not be appropriate for all corporate environments it certainly leaves the viewer with a memorable high-level overview of ransomware, how it works, mitigations, and the types of actions that are being taken against ransomware gangs.

And in this week’s edition of the ransomware name game, SynACK is in the process of rebranding to El_Cometa.  They even decided to release decryption keys for victims infected between 2017 and 2021 by the group under its old name.

In a great week for ransomware decryption, REvil’s decryption key was also leaked on hacking forums.

Ransomware Research

This week has also seen the release of several new Ransomeware variants that append the following with VirisTotal samples linked:

Upcoming Security Conferences

Fraud & Payments Security Summit (August 17-18)

This conference focuses on cybersecurity in regards to the financial sector focusing primarily on fishing email fraud inside a risk and new account fraud.

Blue Team Con (August 28-29)

This conference is focused on the blue team and features discussions on risk compliance, application security development, governance, and everything in between.

What should I do now?

Below are three ways you can continue your journey to reduce data risk at your company:

1

Schedule a demo with us to see Varonis in action. We'll personalize the session to your org's data security needs and answer any questions.

2

See a sample of our Data Risk Assessment and learn the risks that could be lingering in your environment. Varonis' DRA is completely free and offers a clear path to automated remediation.

3

Follow us on LinkedIn, YouTube, and X (Twitter) for bite-sized insights on all things data security, including DSPM, threat detection, AI security, and more.

Try Varonis free.

Get a detailed data risk report based on your company’s data.
Deploys in minutes.

Keep reading

Varonis tackles hundreds of use cases, making it the ultimate platform to stop data breaches and ensure compliance.

last-week-in-ransomware:-week-of-august-9th
Last Week in Ransomware: Week of August 9th
This week saw the rise of a new ransomware group called BlackMatter and demonstrated even ransomware groups should worry about disgruntled employees.
last-week-in-ransomware:-week-of-july-5th
Last Week in Ransomware: Week of July 5th
Ransomware in the News Before we get to the major ransomware attack that occurred over the holiday weekend, let’s take a look at some of the other stories from the...
last-week-in-ransomware:-week-of-june-28th
Last Week in Ransomware: Week of June 28th
Ransomware in the News If you’re a small or medium business using locally hosted cloud storage drives by a popular brand you need to disconnect them from the internet immediately....
last-week-in-ransomware:-week-of-july-19th
Last Week in Ransomware: Week of July 19th
This past week hasn't seen quite as much activity as others, likely due to the new ransomware task force created in the US and the mysterious disappearance of REvil and other gangs.