Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

12/20/2017
11:50 AM
50%
50%

Five Arrested for Cerber, CTB-Locker Ransomware Spread

Authorities arrest three Romanian suspects for spreading CTB-Locker malware and two for a ransomware case linked to the United States.

Romanian authorities have arrested three suspects for spreading a form of ransomware called Curve-Tor-Bitcoin Locker (CTB-Locker) throughout Europe. Two members of the same criminal group have been arrested for distributing Cerber ransomware within the United States.

An investigation into CTB-Locker began in early 2017, when authorities were alerted to Romanian nationals sending spam messages designed to look like they came from Italy, the Netherlands, and the UK. The messages infected systems and encrypted data with CTB-Locker ransomware, which targets almost all versions of Windows including XP, Vista, 7, and 8.

Two suspects were arrested for contaminating a large number of systems in the US with Cerber ransomware. Initially the two investigations were separate, but they were combined when it was discovered people in the same Romanian criminal group was responsible for both. Suspects did not develop the malware themselves but acquired it before launching infection campaigns.

Read more details here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
12/24/2017 | 4:41:23 PM
Re: Never pay the ransom
But many small businesses and some large ones (Merck) don't have a tested plan in place - ergo? I am not suprise about this, I have involved a few other big companies and they are not there yet either.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
12/24/2017 | 4:39:34 PM
Re: Never pay the ransom
Also, never open an attachment received from someone you don't know This is a good suggestion, that may be better options than anything else we can do.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
12/24/2017 | 4:37:41 PM
Re: Never pay the ransom
This includes regularly backing up the data stored on your computer, Sometime backup is encrypted too, so it needs to be an off-site backup in my view.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
12/24/2017 | 4:36:14 PM
Re: Never pay the ransom
Never pay the ransom I would agree however if you do not have a backup and data is lost, you do not have so much options.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
12/24/2017 | 4:34:29 PM
Arrest
I say arrest is a good news it represents there are consequences for their actions and they can not get away with it.
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
12/22/2017 | 2:01:37 PM
Re: Never pay the ransom
Ransomeware is a 900 pound paper tiger.  IF you do not have a good backup and restoration plan, you are screwed.  IF you have a tested plan in place --- hey, the only real issue is data exfiltration.  But many small businesses and some large ones (Merck) don't have a tested plan in place - ergo? 
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
12/22/2017 | 10:09:32 AM
Never pay the ransom
This is an item that I have advocated for quite some time. Ransomware though easy to execute is also easy to mitigate. This comes directly from the linked article:

"This includes regularly backing up the data stored on your computer, keeping your systems up to date and installing robust antivirus software. Also, never open an attachment received from someone you don't know or any odd looking link or email sent by a friend on social media, a company, online gaming partner, etc."
News
US Formally Attributes SolarWinds Attack to Russian Intelligence Agency
Jai Vijayan, Contributing Writer,  4/15/2021
News
Dependency Problems Increase for Open Source Components
Robert Lemos, Contributing Writer,  4/14/2021
News
FBI Operation Remotely Removes Web Shells From Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/14/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-3035
PUBLISHED: 2021-04-20
An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.26. Checkov 1.0 versions are not impacted.
CVE-2021-3036
PUBLISHED: 2021-04-20
An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where secrets in PAN-OS XML API requests are logged in cleartext to the web server logs when the API is used incorrectly. This vulnerability applies only to PAN-OS appliances that are configured to us...
CVE-2021-3037
PUBLISHED: 2021-04-20
An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where the connection details for a scheduled configuration export are logged in system logs. Logged information includes the cleartext username, password, and IP address used to export the PAN-OS conf...
CVE-2021-3038
PUBLISHED: 2021-04-20
A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect app on Windows systems allows a limited Windows user to send specifically-crafted input to the GlobalProtect app that results in a Windows blue screen of death (BSOD) error. This issue impacts: GlobalProtect app 5.1 versions...
CVE-2021-3506
PUBLISHED: 2021-04-19
An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The hi...