Attacks/Breaches

6/22/2018
11:28 AM
50%
50%

'Pay Up or Get WannaCry Hit' Extortion Email Spreading

Sophos warns of a 'protection racket' scam email that threatens to infect victims with the ransomware variant if they don't pay the attackers.

A widespread new email scam purportedly from the WannaCry hackers attempts to shake down potential victims with threats of the ransomware if they don't pay up-front.

But according to Sophos, which spotted the scam, the attackers don't really have the WannaCry malware in hand. "Simply put, it's a protection racket, where you're being stood over to prevent bad things happening, rather than a ransom-based racket, where you are being squeezed to recover from bad things that already happened," said Sophos senior security advisor Paul Ducklin in a post today.

Sophos, which investigated the scam, says not to pay or contact the scammers, and to use the proper security hygiene of patching and good backups.

Read more here.

Why Cybercriminals Attack: A DARK READING VIRTUAL EVENT Wednesday, June 27. Industry experts will offer a range of information and insight on who the bad guys are – and why they might be targeting your enterprise. Go here for more information on this free event.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
6/25/2018 | 11:29:06 PM
Re: Yo, dawg, I herd u like blackmail
@RyanSepe: So would it be called "WannaWannaCry"?
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
6/25/2018 | 1:25:32 PM
Re: Yo, dawg, I herd u like blackmail
Ha, this made me chuckle... seems like Blackception if you ask me.
jenshadus
50%
50%
jenshadus,
User Rank: Strategist
6/25/2018 | 9:23:15 AM
Re: Yo, dawg, I herd u like blackmail
Loved your response.  Very well put.
Joe Stanganelli
100%
0%
Joe Stanganelli,
User Rank: Ninja
6/24/2018 | 10:52:08 PM
Yo, dawg, I herd u like blackmail
Wow. How meta. An extortion scheme threatening the victim with...an extortion scheme!

The next step is blackmailing people into paying up lest they be blackmailed with blackmail! And then blackmailing people threatening them with blackmail with blackmail with blackmail!

Where's Xzibit when you need him?
Microsoft President: Governments Must Cooperate on Cybersecurity
Kelly Sheridan, Staff Editor, Dark Reading,  11/8/2018
5 Reasons Why Threat Intelligence Doesn't Work
Jonathan Zhang, CEO/Founder of WhoisXML API and TIP,  11/7/2018
Why Password Management and Security Strategies Fall Short
Steve Zurier, Freelance Writer,  11/7/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Online Malware and Threats: A Profile of Today's Security Posture
Online Malware and Threats: A Profile of Today's Security Posture
This report offers insight on how security professionals plan to invest in cybersecurity, and how they are prioritizing their resources. Find out what your peers have planned today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-6980
PUBLISHED: 2018-11-13
VVMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authorization in the user registration method. Successful exploitation of this issue may allow Admin users with view only permission to perform certain administrative functions which the...
CVE-2018-17614
PUBLISHED: 2018-11-13
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Losant Arduino MQTT Client prior to V2.7. User interaction is not required to exploit this vulnerability. The specific flaw exists within the parsing of MQTT PUBLISH packets. The issue results from th...
CVE-2018-8009
PUBLISHED: 2018-11-13
Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vulnerability in places that accept a zip file.
CVE-2018-2491
PUBLISHED: 2018-11-13
When opening a deep link URL in SAP Fiori Client with log level set to "Debug", the client application logs the URL to the log file. If this URL contains malicious JavaScript code it can eventually run inside the built-in log viewer of the application in case user opens the viewer and taps...
CVE-2018-2473
PUBLISHED: 2018-11-13
SAP BusinessObjects Business Intelligence Platform Server, versions 4.1 and 4.2, when using Web Intelligence Richclient 3 tiers mode gateway allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.