Strange ransomware detection only attacks the rich
Recently, security researchers have discovered a new ransomware that works differently from other extortion malware software.
CrowdStrike and FireEye, two security companies that discovered the malware, said that since August 2018, it has earned more than $ 4 million in data encryption and extortion.
Other ransomware often spread to all victims if possible, but the new ransomware is different, it selectively infects. Specifically, Ryuk ransomware only infects large businesses, based on a security vulnerability created by another malicious software called Trickbot created earlier. Meanwhile, Ryuk does not attack small companies that are also infected with Trickbot.
CrowdStrike calls Ryuk's attack method 'big-game hunting', the target of attack is large companies and businesses.
Based on Trickbot, Ryuk will explore the system of objects to attack to understand their resources and ability to pay a huge ransom. In order for these companies to fail, the malware will not rush to attack immediately, but will conduct the most important system reconnaissance, then finally make a large-scale attack.
Currently, CrowdStrike and FireEye experts have found some evidence that Ryuk has some connection with Russia.
See more:
- 14 games on the App Store contain malicious code, iPhone users be careful
- 1.6 million computers in Vietnam were erased by the virus, losing nearly 15,000 billion in 2018
- Warning: New extortion code GandCrab is attacking Vietnamese Internet users
You should read it
- Ryuk Ransomware stops encrypting Linux directory
- STOP - Ransomware is the most active in the Internet but rarely talked about
- Disable malicious HiddenTear Ransomware with HT Brute Forcer
- Research: The golden time to prevent malicious code after the system is compromised
- Risk of ransomware infection when downloading crack software online
- Another large Data Center service provider became a victim of ransomware
- Mexico's largest oil and gas corporation has been attacked by ransomware, presenting a cyber security disaster
- List of the 3 most dangerous and scary Ransomware viruses
May be interested
- What secret is behind the trend of posting 10-year photos on Facebook?the trend of posting pictures now and 10 years ago is causing storms on social networks but according to analysis of wired's technology reporter kate o'neill, this could be one of the ways facebook collects data to dig create machines for users' aging.
- Google One is available in Vietnam, customers register to receive 110,000 VND to Google accountgoogle one is an upgraded version of google drive hosting service for paying customers, with many good price subscription packages introduced by google not long ago. and now, google one has supported users in vietnam.
- There were Windows 10 build 18312 with many improvements for the operating system, invited to download ISO files and experiencewindows 10 insider preview build 18312 (19h1) has just been released by microsoft for insider fast users with many important improvements to the operating system.
- What happens to a Microsoft official version of 'death'what do windows users face when using an operating system that microsoft stopped supporting?
- The latest update on Windows 7 fails, which may cause your computer to lose copyrightmicrosoft recently released a new monthly update with windows 7 kb4480970 and windows 7 kb4480960 codes. but according to feedback from windows 7 users as well as microsoft, this update has caused some devices to lose copyright.
- Vein Authentication (Vein Authentication) is defeated by a fake handsecurity researchers have revealed a new piece of information at the chaos communication congress (chaos communication congress) that hackers can penetrate static-based authentication by creating a fake hand.