Background
In our PolySwarm 2021 Year in Review, we made several predictions for this year, including that BlackCat ransomware would become more prevalent, due to its sophistication. BlackCat ransomware is ransomware as a service (RaaS), which was recently linked to the
BlackCat Ransomware
Mar 31, 2022 2:57:30 PM / by PolySwarm Tech Team posted in Threat Bulletin, Ransomware, BlackMatter, LockBit, BlackCat, ALPHV, DarkSide
Surtr Ransomware
Mar 25, 2022 1:45:09 PM / by PolySwarm Tech Team posted in Threat Bulletin, Ransomware, Surtr, REvil, Sodinokibi
Background
Arete recently reported on Surtr ransomware, a RaaS. A recently discovered Surtr sample paid tribute to the REvil/Sodinokibi ransomware gang.
Nokoyawa Ransomware
Mar 24, 2022 2:13:03 PM / by PolySwarm Tech Team posted in Threat Bulletin, Ransomware, Hive, Nokoyawa
Background
Trend Micro recently reported on Nokoyawa, a ransomware family they discovered earlier this month. They stated Nokoyawa seems to have a connection with Hive ransomware, based on similarities in the attack chains of the two malware families.
Sugar Ransomware Targets Individuals Instead of Enterprises
Mar 3, 2022 2:59:22 PM / by PolySwarm Tech Team posted in Threat Bulletin, Ransomware, RaaS, Sugar
Background
Walmart recently reported on a new ransomware as a service (RaaS) called Sugar ransomware. The threat actors behind Sugar ransomware appear to be targeting individuals rather than enterprises and demand a low ransom amount, based on the number of files encrypted.
BlackByte Ransomware Targets Critical Infrastructure
Mar 1, 2022 2:42:23 PM / by PolySwarm Tech Team posted in Threat Bulletin, Critical Infrastructure, BlackByte, Ransomware
Background
The FBI and US Secret Service released an advisory regarding BlackByte ransomware, which compromised multiple US and foreign businesses, including three entities that are part of US critical infrastructure. These three unnamed entities belonged to the government, financial, and food and agriculture verticals. The threat actors behind BlackByte also claimed they hacked networks belonging to the San Francisco 49ers in mid-February 2022.