Threatpost reports that the REvil ransomware threat group, also known as the Sodinokibi ransomware gang, claimed to have compromised a total of nine organizations in the U.S., Europe, Africa and Mexico in the last two weeks. Researchers with eSentire analyzed the group’s claims and stated that the affected organizations included an insurance company, a construction firm, an architectural company, two law firms and an agricultural co-op in the U.S.; a manufacturer in Europe; and two large international banks in Africa and Mexico. “These attacks come directly on the heels of an extensive and well-planned drive-by-download campaign, which was launched in late December. This malicious campaign’s sole purpose is to infect business professionals’ computer systems with the … ransomware, the Gootkit banking trojan or the Cobalt Strike intrusion tool,” said Rob McLeod, senior director of eSentire’s Threat Response Unit. According to researchers, the cybercriminals posted on underground forums the documents which supposedly were from these organizations’ computer systems, including partial customer lists, customer quotes, company computer file directories and contract copies.
Jill Aitoro leads editorial for SC Media, and content strategy for parent company CyberRisk Alliance. She 20 years of experience editing and reporting on technology, business and policy.
Attacks with the new Cuckoo information-stealing malware with spyware features have been targeted at Intel- and Arm-based macOS devices, The Hacker News reports.
Ukrainian networks were reported by the country's Computer Emergency Response Team to have been subjected to mounting attacks by novel financially motivated Russian threat actors since the second half of 2023, according to The Record, a news site by cybersecurity firm Recorded Future.