Attacks/Breaches

12/20/2017
11:50 AM
50%
50%

Five Arrested for Cerber, CTB-Locker Ransomware Spread

Authorities arrest three Romanian suspects for spreading CTB-Locker malware and two for a ransomware case linked to the United States.

Romanian authorities have arrested three suspects for spreading a form of ransomware called Curve-Tor-Bitcoin Locker (CTB-Locker) throughout Europe. Two members of the same criminal group have been arrested for distributing Cerber ransomware within the United States.

An investigation into CTB-Locker began in early 2017, when authorities were alerted to Romanian nationals sending spam messages designed to look like they came from Italy, the Netherlands, and the UK. The messages infected systems and encrypted data with CTB-Locker ransomware, which targets almost all versions of Windows including XP, Vista, 7, and 8.

Two suspects were arrested for contaminating a large number of systems in the US with Cerber ransomware. Initially the two investigations were separate, but they were combined when it was discovered people in the same Romanian criminal group was responsible for both. Suspects did not develop the malware themselves but acquired it before launching infection campaigns.

Read more details here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
12/24/2017 | 4:41:23 PM
Re: Never pay the ransom
But many small businesses and some large ones (Merck) don't have a tested plan in place - ergo? I am not suprise about this, I have involved a few other big companies and they are not there yet either.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
12/24/2017 | 4:39:34 PM
Re: Never pay the ransom
Also, never open an attachment received from someone you don't know This is a good suggestion, that may be better options than anything else we can do.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
12/24/2017 | 4:37:41 PM
Re: Never pay the ransom
This includes regularly backing up the data stored on your computer, Sometime backup is encrypted too, so it needs to be an off-site backup in my view.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
12/24/2017 | 4:36:14 PM
Re: Never pay the ransom
Never pay the ransom I would agree however if you do not have a backup and data is lost, you do not have so much options.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
12/24/2017 | 4:34:29 PM
Arrest
I say arrest is a good news it represents there are consequences for their actions and they can not get away with it.
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
12/22/2017 | 2:01:37 PM
Re: Never pay the ransom
Ransomeware is a 900 pound paper tiger.  IF you do not have a good backup and restoration plan, you are screwed.  IF you have a tested plan in place --- hey, the only real issue is data exfiltration.  But many small businesses and some large ones (Merck) don't have a tested plan in place - ergo? 
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
12/22/2017 | 10:09:32 AM
Never pay the ransom
This is an item that I have advocated for quite some time. Ransomware though easy to execute is also easy to mitigate. This comes directly from the linked article:

"This includes regularly backing up the data stored on your computer, keeping your systems up to date and installing robust antivirus software. Also, never open an attachment received from someone you don't know or any odd looking link or email sent by a friend on social media, a company, online gaming partner, etc."
WebAuthn, FIDO2 Infuse Browsers, Platforms with Strong Authentication
John Fontana, Standards & Identity Analyst, Yubico,  9/19/2018
NSS Labs Files Antitrust Suit Against Symantec, CrowdStrike, ESET, AMTSO
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/19/2018
Turn the NIST Cybersecurity Framework into Reality: 5 Steps
Mukul Kumar & Anupam Sahai, CISO & VP of Cyber Practice and VP Product Management, Cavirin Systems,  9/20/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Are you sure this is how we get our data into the cloud?
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-8298
PUBLISHED: 2018-09-24
Multiple SQL injection vulnerabilities in the login page in RXTEC RXAdmin UPDATE 06 / 2012 allow remote attackers to execute arbitrary SQL commands via the (1) loginpassword, (2) loginusername, (3) zusatzlicher, or (4) groupid parameter to index.htm, or the (5) rxtec cookie to index.htm.
CVE-2018-14825
PUBLISHED: 2018-09-24
A skilled attacker with advanced knowledge of the target system could exploit this vulnerability by creating an application that would successfully bind to the service and gain elevated system privileges. This could enable the attacker to obtain access to keystrokes, passwords, personal identifiable...
CVE-2018-17437
PUBLISHED: 2018-09-24
Memory leak in the H5O_dtype_decode_helper() function in H5Odtype.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (memory consumption) via a crafted HDF5 file.
CVE-2018-17438
PUBLISHED: 2018-09-24
A SIGFPE signal is raised in the function H5D__select_io() of H5Dselect.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.
CVE-2018-17439
PUBLISHED: 2018-09-24
An issue was discovered in the HDF HDF5 1.10.3 library. There is a stack-based buffer overflow in the function H5S_extent_get_dims() in H5S.c. Specifically, this issue occurs while converting an HDF5 file to a GIF file.