Attacks/Breaches

12/6/2016
01:30 PM
50%
50%

Pennsylvania State Prosecutor's Office Paid Ransom In 'Avalanche' Ransomware Attack

Allegheny County state prosecutor's office paid attackers $1,400 in Bitcoin to free its data.

Remember that massive international takedown of the Avalanche botnet network last week that supported a major cybercrime ring? Well, at least one of the hundreds of thousands of victims of the operation has admitted publicly that it was hit with ransomware and forced to pay up.

The state prosecutor's office in Allegheny County, Pennsylvania, confirmed to the Associated Press that it paid a ransom of around $1,400 in Bitcoin after its systems were infected with ransomware via Avalanche.

The Avalanche botnet had been active since 2009 and used for money muling schemes, malware distribution, and as a fast-flux communication infrastructure for other botnets. It was estimated to involve as many as 500,000 active infected devices worldwide on a daily basis.

An employee at the Pennsylvania prosecutor's office in January 2015 opened a link in an email that ultimately led to the ransomware infection, Allegheny County district attorney, Stephen Zappala Jr., told the AP. The user "opened the link because it appeared to go back to a legitimate government agency," he said.

Read more about this attack on AP.

 

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Weaponizing IPv6 to Bypass IPv4 Security
John Anderson, Principal Security Consultant, Trustwave Spiderlabs,  6/12/2018
'Shift Left' & the Connected Car
Rohit Sethi, COO of Security Compass,  6/12/2018
Why CISOs Need a Security Reality Check
Joel Fulton, Chief Information Security Officer for Splunk,  6/13/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-1060
PUBLISHED: 2018-06-18
python before versions 2.7.15, 3.4.9, 3.5.6 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.
CVE-2018-1090
PUBLISHED: 2018-06-18
In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access on the distributor/importer. An attacker with API access can then view these secrets.
CVE-2018-1152
PUBLISHED: 2018-06-18
libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image.
CVE-2018-1153
PUBLISHED: 2018-06-18
Burp Suite Community Edition 1.7.32 and 1.7.33 fail to validate the server certificate in a couple of HTTPS requests which allows a man in the middle to modify or view traffic.
CVE-2018-12530
PUBLISHED: 2018-06-18
An issue was discovered in MetInfo 6.0.0. admin/app/batch/csvup.php allows remote attackers to delete arbitrary files via a flienamecsv=../ directory traversal. This can be exploited via CSRF.