DoppelPaymer 랜섬웨어는 Grief로 이름이 변경되었습니다.

블 리핑 컴퓨터 writes that the DoppelPaymer ransomware operators have “rebranded” their product and now the malware is renamed as Grief (또는 지불 또는 슬픔).

DoppelPaymer’s activity almost came to naught after the scandalous attack by the DarkSide ransomware on the Colonial Pipeline company, after which it was forbidden to advertise and discuss ransomware on the largest hack forums, and many groups preferred to pull back for a while.

Emsisoft expert Fabian Vosar was the first to draw Bleeping Computer’s attention to the fact that Grief and DoppelPaymer is same threat. Although the attackers tried to make Grief different from DoppelPaymer, the similarity was still obvious to experts. 특히, the hackers used the same format for encrypted files and the same malware distribution channelthe Dridex botnet.

The first news of Grief came in early June (although a sample was found compiled on May 17), and then researchers assumed it was a new threat.

But now, Zscaler has examined an early sample of Grief and noticed that the ransom note points to the DoppelPaymer site, as Grief’s own site was apparently not yet ready at the time.

At the moment, on the Grief website, you can already find references to two dozen victims, while the DoppelPaymer website has not been updated since May 2021.

DoppelPaymer는 Grief로 이름이 변경되었습니다.

Even the captcha on the ransomware sites are the same.

게다가, it is noted that both malware is based on a very similar code, 어느, 예를 들면, implementsidentical encryption algorithms (2048-bit RSA and 256-bit AES) and import hashing.” 또한, Grief and DoppelPaymer both use the GDPR to put pressure on victims and remind them that in case of a data breach, they will have to face legal consequences.

Grief ransomware is the latest version of DoppelPaymer ransomware with minor code changes and new looks.Zscaler says.

And adding that hackers have been keeping a low profile lately to avoid the unnecessary attention that REvil ransomware received after hacking clients. Kaseya, and DarkSide after the attack on the Colonial Pipeline.

내가 또한 쓴 것을 상기시켜 드리겠습니다 연구원들은 TrickBot 개발자를 Diavol 랜섬웨어와 연결했습니다..

헬가 스미스

저는 항상 컴퓨터 과학에 관심이있었습니다, 특히 데이터 보안 및 테마, 요즘은 "데이터 과학", 10 대 초반부터. 편집장으로 바이러스 제거 팀에 오기 전, 저는 여러 회사에서 사이버 보안 전문가로 일했습니다., 아마존 계약자 중 한 명 포함. 또 다른 경험: 나는 Arden과 Reading 대학에서 가르치고 있습니다..

회신을 남겨주

이 사이트는 스팸을 줄이기 위해 Akismet 플러그를 사용. 귀하의 코멘트 데이터가 처리되는 방법 알아보기.

맨 위로 버튼