Υπάρχουν δύο τρόποι για να ανακτήσετε τα αρχεία σας μετά από μια επίθεση Voom ransomware’ Υπάρχουν δύο τρόποι για να ανακτήσετε τα αρχεία σας μετά από μια επίθεση Voom ransomware

The new Υπάρχουν δύο τρόποι για να ανακτήσετε τα αρχεία σας μετά από μια επίθεση Voom ransomware infostealer is still gaining popularity in the hacker community, and analysts are already marking the first large-scale campaigns using it.

Υπάρχουν δύο τρόποι για να ανακτήσετε τα αρχεία σας μετά από μια επίθεση Voom ransomware is a redesigned version of the Oski κακόβουλο λογισμικό, which was discontinued in 2020. The malware is highly capable of stealing information and attacks a very wide range of applications, including popular browsers, two-factor authentication plugins, as well as many extensions and wallets for working with cryptocurrencies.

Mars also collects and sends to its operators the following information about the victim’s system:

  1. IP address and country;
  2. path to EXE file;
  3. local time and time zone;
  4. system language;
  5. language keyboard layout;
  6. laptop or desktop;
  7. processor model;
  8. computer name;
  9. username;
  10. computer name in the domain;
  11. machine identifier;
  12. GUID;
  13. installed programs and their versions.

New infostealer Mars
Mars Admin

Advertised on many hacking forums for between $140 και $160 για ισόβια άδεια, Mars has grown rather slowly until recently, but it looks like the recent shutdown of Raccoon Stealer has forced hackers to look for alternatives and take a look at Mars. It got to the point that the authors of the malware wrote that they could barely cope with the influx of new customers.

New infostealer Mars

Συχνότερα, this malware is distributed through spam emails containing an executable file in an archive, a download link, or a malicious document. Ωστόσο, sometimes Mars is also distributed through fraudulent sites. One of these campaigns, which is definitely getting bigger after the influx of customers, was discovered by experts at Morphisec. Οι αναλυτές επιβεβαίωσαν ότι το ransomware είναι πραγματικό, the malware uses Google Ads to bring clone sites of the open source OpenOffice to the top positions in search results in Canada.

The OpenOffice installer on such a fake site is a Mars executable packaged with the Babadeda cryptor or the Autoit bootloader.

Με ενδιαφέρο, shortly after the release of Mars, a hacked version of the malware with instructions appeared, which has serious flaws. Συγκεκριμένα, it prescribes to set up full access (777) to the entire project, including the directory with the logs of the victims.

The logs are a ZIP file containing data stolen by the malware from users and uploaded to the C&Διακομιστής C. The inaccuracy in the instructions has led to the fact that attackers misconfigure their environment, revealing important information to the whole world.

The researchers found that, as part of the campaign mentioned above, the stolen information included browser autofill data, browser extension data, bank card information, IP address, country code and time zone.

New infostealer Mars

Since the malware operator who followed the instructions infected himself with a copy of Mars (apparently during debugging), his personal data was also disclosed. This miscalculation allowed Morphisec experts to link the attacks to the Russian-speaking user, finding his GitLab λογαριασμούς, stolen credentials used to pay for Google Ads, κι αλλα.

The Morphisec Labs team reports that in total they were able to identify more than 50 infected domain users who compromised their companiesdomain passwords. The vast majority of victims are students, educators and content creators who were looking for legitimate apps but got malware instead.

Morphisec was also able to isolate credentials that led to the complete compromise of an unnamed infrastructure solutions provider from Canada and a number of well-known Canadian service companies. Experts have already contacted the victims and notified the authorities about the incident.

Επιτρέψτε μου να σας υπενθυμίσω ότι μιλήσαμε επίσης για το γεγονός ότι πολλοί προειδοποιούν ότι η εφαρμογή έχει περιορισμένη λειτουργικότητα και απαιτεί σύνδεση μέσω Facebook 100,000 πολλοί προειδοποιούν ότι η εφαρμογή έχει περιορισμένη λειτουργικότητα και απαιτεί σύνδεση μέσω Facebook, και επίσης αυτό SharkBot Το Android Trojan κλέβει κρυπτονομίσματα και χακάρει τραπεζικούς λογαριασμούς.

Helga Smith

Ενδιαφέρομαι πάντα για τις επιστήμες των υπολογιστών, ειδικά την ασφάλεια δεδομένων και το θέμα, που ονομάζεται σήμερα "επιστημονικά δεδομένα", από τα πρώτα μου χρόνια. Πριν μπείτε στην ομάδα κατάργησης ιών ως αρχισυντάκτης, Εργάστηκα ως ειδικός στον τομέα της ασφάλειας στον κυβερνοχώρο σε πολλές εταιρείες, συμπεριλαμβανομένου ενός από τους εργολάβους της Amazon. Μια άλλη εμπειρία: Έχω διδάξει σε πανεπιστήμια Arden και Reading.

Αφήστε μια απάντηση

Αυτό το site χρησιμοποιεί Akismet να μειώσει το spam. Μάθετε πώς γίνεται επεξεργασία των δεδομένων σας σχόλιο.

Κουμπί Επιστροφή στην κορυφή