ProLock Ransomware

Detected in March 2020, ProLock.Ransomware is a newly identified “human-operated” file-encrypting windows strain. ProLock is the successor of another ransomware strain “PwndLocker” that had a flaw in its code, which lead victims to decrypt data without having to pay a ransom. The designers of the malware upgraded the malicious code of PwndLocker and renamed it… Continue reading ProLock Ransomware

ColdLock Ransomware

The current global remote working movement has become an opportunity for cyber attackers. Security researchers at SISA have been observing a persistent ransomware activity around the world. Now, we found another file-encrypting malware, disrupting enterprises in Taiwan. ColdLock is a newly identified ransomware strain that reportedly focuses on encrypting databases and email servers of the… Continue reading ColdLock Ransomware

Panther Ransomware

Ransomware continues to be the most dangerous threat vector of 2020. Recently, security researchers detected another new ransomware strain ‘.panther file virus’, sneaking into organizations’ internal systems and locking critical data files. The malware was first identified in the last weeks of March 2020, and now in July, it is seen targeting Asian data-driven organizations.… Continue reading Panther Ransomware

MosaicRegressor Malware

Malwares aren’t going anywhere. Today’s news cycles, especially during the COVID-19 pandemic, seem to be full of cyber incidents. One such malware MosaicRegressor, the Second-Ever Windows Unified Extensible Firmware Interface (UEFI) Rootkit that can stay on the motherboard flash memory located in the BIOS region of the PC, was found recently. One other known instance… Continue reading MosaicRegressor Malware

Ghimob malware can spy on 153 Android mobile applications

They are warning about a new Android trojan “Ghimob” that can siphon off data from 153 mobile applications. The risk isn’t limited to data breach threats – the attackers can even bypass banking institutions’ security measures to make fraudulent transactions on Android users’ smartphones. With a link in an email that takes the users to an authentic-looking app,… Continue reading Ghimob malware can spy on 153 Android mobile applications

SolarWinds Fallout: How The Sunburst Attack Happened

On Dec 13, 2020, SolarWinds, a commonly deployed network management solution, confirmed that a cyber incident has occurred which appears to be an IT operations product used well by Fortune 500 companies, US Government agencies, and critical SMB firms. The SolarWinds Orion application updates have been infected for a period between March and June 2020.… Continue reading SolarWinds Fallout: How The Sunburst Attack Happened

Clop Ransomware: Don’t Think It Can Happen to You?

Records are made to be broken. The Cryptomix Clop ransomware took this seriously as it stepped up in October 2020 to demand a whopping 20+ million-dollar ransom from one of the largest software companies in the world. That’s not all. It has improved over time and was recently noticed in the wild going after top… Continue reading Clop Ransomware: Don’t Think It Can Happen to You?

How to Prevent a Potential Fortinet FortiOS Breach: All You Need to Know

Blog The system that for years has protected our digital business is now vulnerable to advanced persistent threat (APT) actors and soon may be a victim of potential attacks. The FBI and the Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA), in a joint alert, have recently warned that threat actors are actively exploiting… Continue reading How to Prevent a Potential Fortinet FortiOS Breach: All You Need to Know

DarkSide Ransomware Operations

Blog DarkSide is a relatively new ransomware group, which first appeared in August 2020 on one of the Russian language hacking forums where they were availing their ransomware to others groups. They are a new type of ransomware-as-a-service business, attempting to instill trust and reliability between themselves and their victims. The stealthy techniques followed by… Continue reading DarkSide Ransomware Operations

SISA’s Latest
close slider