Blog

Another Week Another New Ransomware To Be Concerned About

Mar 27, 2020 | Blog

There’s a new strain of ransomware to put on your radar.

This latest one was discovered by researchers working from SentinelLabs and it has been dubbed Nefilim.

Based on the initial research, it seems to share significant portions of its code base with an older strain, Nemty 2.5.

The two key differences between the two strains are as follows:

  1. Nefilim’s code does not contain the Ransomware-as-a-Service (RaaS) found in Nemty 2.5
  2. Nefilim relies on email communication to arrange ransom payment, rather than routing those through the TOR browser.

The researchers spotted Nefilim in the wild at the end of February of this year (2020). At this point, it’s unclear exactly how the malware is being distributed. The best guess at this point is that the malware is being spread via exposed Remote Desktop Services. However, the malware winds up on a target system.

When it does its work and infects the files on the compromised computer, the victim will see the following note:

A large amount of your private files have been extracted and is kept in a secure location. If you do not contact us in seven working days of the breach we will start leaking the data. After you contact us we will provide you proof that your files have been extracted.”

This tactic is becoming increasingly common, and as we’ve seen in recent months, it’s not an idle threat. Worse is that based on the analysis of the code to this point, Nefilim is secure. That means that at present, there’s no free way to recover your files once they have been encrypted.

While this strain isn’t especially widespread at this point, it’s a legitimate threat. It would be a grave mistake to ignore it.

FBI Program Tasked with Infrastructure Security Compromised

FBI Program Tasked with Infrastructure Security Compromised

The FBI program tasked with ensuring critical infrastructure security has been compromised by hackers, who now offer access to the program's data on the dark web. The breach was initially disclosed by Brian Krebs of Krebs on Security, who claims that the data was for...

Streamline Your Business with the Latest Smart Home Technology

Streamline Your Business with the Latest Smart Home Technology

Are you a business owner looking to get the most out of your Google smart home devices? If so, you're in luck! Google has enabled its Nest products and Android OS with the initial rollout of the Matter smart home standard. This means that businesses now have the...

Data Breach at Sequoia One Exposes Sensitive Customer Information

Data Breach at Sequoia One Exposes Sensitive Customer Information

What do you do when your most personal information has been compromised? This is likely the question that customers of Sequoia One asked themselves earlier this month as they were informed that the company had been hacked. Sequoia One specializes in the management of...

Cisco Reports Critical IP Phone Vulnerability

Cisco Reports Critical IP Phone Vulnerability

As a business owner, it's important to stay informed about potential vulnerabilities that could impact your organization. Recently, Cisco reported a critical vulnerability, tracked as CVE-2022-20968, affecting its IP Phone 7800 and 8800 Series. This new vulnerability...

Google Chrome Releases Two New Features

Google Chrome Releases Two New Features

Google Chrome is one of the more commonly used web browsers. Over the years, though, Chrome has gained a reputation for utilizing a large portion of a computer's memory. This can be a problem if you're running other resource-intensive tasks and don't want to slow...

Get a Free Consultation

 

Fill out the form below to receive a free consultation and learn how we can make your technology worry-free!

 

Contact Information

  • 39301 Badger Street, Suite 500
    Palm Desert, CA 9221
  • (760) 333-8523
  • info@icn.tech