Ransomware

Ransomware - US$6 Trillion 2022

Ransomware Links are drawn from  https://sites.google.com/view/code-war/ransomware and includes:

Ransomware is a type of malware from crypto virology that threatens to publish the victim's personal data or perpetually block access to it unless a ransom is paid. Stop ransomware in its tracks with Darktrace Antigena operates across your entire digital estate

https://www.darktrace.com/en/darktrace-antigena/

Discover how Autonomous Response would interrupt ransomware at 8 different stages of the attack life-cycle, from the initial intrusion, through to encryption. 

Darktrace for Email uses core artificial intelligence to stop the most advanced email threats, intervening to protect employees from the full range of threats targeting the inbox.

Latest Ransomware News = https://www.bleepingcomputer.com/tag/ransomware/

2022 Malware with Python = https://www.youtube.com/watch?v=UtMMjXOlRQc

022 RKE: How To Hack A Car = https://www.secjuice.com/attacking-rke-how-to-hack-a-car-open/

Cybersecurity & Infrastructure Security Agency - Stop Ransomware = https://www.cisa.gov/stopransomware

https://www.nomoreransom.org/en/index.html

Install security software before you get hit with ransomware

Back up your important data (files, documents, photos, videos, etc.)

https://www.cyber.gc.ca/en/guidance/ransomware-how-prevent-and-recover-itsap00099

https://www.makeuseof.com/ransomware-attack-steps-to-take/

VX-Underground Malware Research = https://www.vx-underground.org/    https://twitter.com/vxunderground

Blackfog = https://www.blackfog.com/the-state-of-ransomware-in-2021/

DUOcircle Phishing = https://www.duocircle.com/email/phishing-protection

PC Risk = https://www.pcrisk.com/

Abnormal Security = https://abnormalsecurity.com/


Ransomware Groups

ALPHV Ransomware Gang, also known as BlackCat, Conti, LockBit, Pysa, REvil, and Maze/Egregor, Evil Corp., Maze, DarkSide and REvil 

LAPSUS$ group = https://en.wikipedia.org/wiki/Lapsus$

Conti Ransomware Group ( aka Wizard Spider ) = https://en.wikipedia.org/wiki/Conti_  Conti Gang ransomware =  t.ly/CzES

Hive Ransomware Group = Hive Ransomware 

Lockbit Ransomware = https://bit.ly/3QbpnNa

The Vice Society = https://bit.ly/3BUbHlE

BlackByte Ransomware Gang = t.ly/77dKG


News

Latest Ransomware News = https://www.bleepingcomputer.com/tag/ransomware/

Research = Cybersecurity & Infrastructure Security Agency

Threat Post = https://threatpost.com/

Steps to Take After Getting Hit by Ransomware

Stay Calm and Collected. ...

Take a Photo of the Ransomware Note. ...

Quarantine Affected Systems. ...

Look for Decryption Tools. ...

Disable Maintenance Tasks. ...

Disconnect Backups. ...

Identify the Attack Variant. ...

Reset Passwords.

Identify the Attack Variant  at:

https://www.emsisoft.com/ransomware-decryption-tools/

https://id-ransomware.malwarehunterteam.com/

Ransomware Message Examples = https://bit.ly/3MXgpRQ

========= Research =====

Access Now Help = https://www.accessnow.org/help/   ( help@accessnow.org )

Who to Report a Ransomware Attack to

Contact Canadian Centre for Cyber ( https://cyber.gc.ca/en/incident-management )

Canadian Anti-Fraud Centre ( https://www.antifraudcentre-centreantifraude.ca/index-eng.htm )

FBI ( https://www.fbi.gov/scams-and-safety/common-scams-and-crimes/ransomware )

Actions to Take

Ransomware attacks lock your screen to prevent you from taking any action. So if you avoid clicking links or opening attachments included inside the threatening email and delete it immediately, you're most likely fine. If you receive a bad email on a work device, report it to your IT department ASAP

Law enforcement agencies recommend not paying, because doing so encourages continued criminal activity. In some cases, paying the ransom could even be illegal, because it provides funding for criminal activity.

Can I get a virus by reading my email messages? Most viruses, Trojan horses, and worms are activated when you open an attachment or click a link contained in an email message. If your email client allows scripting, then it is possible to get a virus by simply opening a message.

Does Gmail run JavaScript? Gmail removes JavaScript scripting from an email before handing it to the chrome browser.

Ransomware payments hit 66% of mid-sized organizations last year, up from 37% in 2020. Average ransom payments reached $812,000 during 2021, compared with $170,000 the prior year.  Apr 27, 2022