BleepingComputer reports that on March 19, the administrator of the Ziggy ransomware announced their plans to return the ransom paid by victims after shutting down their operation on Feb. 6. The administrator published all of the 922 decryption keys the day after the shutdown, which the victims could use to regain access to their files, along with a decryption tool and the source code for an offline decryptor. Victims are advised to contact the administrator at [email protected] and to send their computer ID and proof of bitcoin payment. They will then receive their money through their bitcoin wallet in about two weeks. According to the Ziggy ransomware administrator, they decided to end their operation and refund the victims because they fear of being caught by law enforcement officers. They also claimed to selling their house in order to return the victims' money and planning to become a ransomware hunter after they have refunded the victims.
Jill Aitoro leads editorial for SC Media, and content strategy for parent company CyberRisk Alliance. She 20 years of experience editing and reporting on technology, business and policy.
India had several of its government agencies and energy industry organizations subjected to cyberespionage attacks delivering the HackBrowserData information-stealing malware as part of the new Operation FlightNight campaign identified earlier this month, according to The Record, a news site by cybersecurity firm Recorded Future.
Threat actors have launched a new phishing campaign using fraudulent bank payment notifications to facilitate the deployment of the Agent Tesla information-stealing and keylogging malware, The Hacker News reports.
Industrial cyberespionage could potentially be facilitated by the new suspicious SqzrFramework480 NuGet package seemingly targeted to developers using tools by Chinese industrial firm Bozhon Precision Industry Technology Co., according to The Hacker News.