Recently, Broadcom's Symantec Threat Hunter Team discovered a new ransomware called Yanluowang (Yanluowang, one of the 10 Kings of Hell). Currently, this new ransomware is still in the development stage and its target is to attack businesses.
The Yama Ransomware was discovered when experts were investigating an incident involving a reputable organization. The investigation was launched after they detected suspicious activity involving the command-line Active Directory query tool AdFind.
AdFind is often used by the actors behind ransomware for reconnaissance tasks including accessing information necessary for movement through the victim's network.
Once deployed on the victim's machine, the Yanluowang ransomware encrypts all files and appends the .yanluowang extension. They also leave behind a README.txt file demanding ransom and warning victims not to contact law enforcement or ransomware companies.
If the victim refuses to pay or contacts other parties, the people behind the King of Hell are ready to carry out DDoS attacks, delete data, repeat the attack.
Although still in development, Yama is still considered a dangerous malware. Targeting large companies and businesses, this ransomware can cause unpredictable damage.
Countries around the world are currently very active in cooperating and working together to eradicate ransomware distribution gangs.
cybercriminals are using a new form of ransomware to target large businesses and take money from it. since august, the ryuk team has made $ 4 million by installing malicious encryption software on high-value targets.
no more ransome called for cooperation to fight ransomware, helping victims recover their data without paying ransom for hackers. the project website not only provides computer users with a way to protect themselves from ransomware, but also provides a set of free decoding tools.
after a 3-month hiatus under the name babuk locker, it has returned to creating custom ransomware executables that now target victims around the world.
a ransomware strain called qilin was recently discovered using a relatively sophisticated tactic, with high customization capabilities, to steal account login information stored in the google chrome browser. .
dutch cybersecurity company tesorion has released a free decryptor for the lorenz ransomware, which helps victims recover some stolen data without paying a ransom.
ransomware wannacry has infected hundreds of thousands of computers around the world. recently, a cyber security researcher said he had found a way to defeat it.
while security solutions to protect us from threats, hackers are increasingly improving, while malicious programs (malware) are also becoming more and more 'cunning'. and one of the recent threats is how to extort money through ransomware.