Executive Summary
The aviation and aerospace verticals face numerous challenges in the form of cyber threats. This report gives an overview of the different threat actor motivations to target aviation and aerospace and the types of threats to these verticals.
Cyber Threats to Aviation and Aerospace
Oct 25, 2022 5:02:07 PM / by PolySwarm Tech Team posted in Russia, Threat Bulletin, China, Ransomware, Aerospace, Hacktivism, Aviation, Data Theft, Killnet, Phishing
Deadbolt Ransomware
Sep 29, 2022 2:22:49 PM / by PolySwarm Tech Team posted in Threat Bulletin, Ransomware, QNAP, Deadbolt
Executive Summary
Sophos recently reported on Deadbolt ransomware, a malware family targeting QNAP devices. QNAP released an advisory on the affected products.
BianLian Ransomware
Sep 26, 2022 4:05:33 PM / by PolySwarm Tech Team posted in Threat Bulletin, Ransomware, BianLian
Verticals Targeted: Professional Services, Media and Entertainment, Manufacturing, Healthcare, Energy and Utilities, Education, Financial
Executive Summary
Cyble recently reported on BianLian, a new ransomware variant written in Go. It has been used to target multiple verticals.
DarkAngels Linux Ransomware
Sep 12, 2022 1:45:13 PM / by PolySwarm Tech Team posted in Threat Bulletin, Ransomware, Linux, DarkAngels
Related families: Babuk
Executive Summary
Uptycs recently reported on a new DarkAngels Linux ransomware variant that appears to still be in development.
GwisinLocker
Aug 29, 2022 2:33:33 PM / by PolySwarm Tech Team posted in Threat Bulletin, Ransomware, GwisinLocker, South Korea
Verticals Targeted: pharmaceutical, healthcare, industrial
Executive Summary
Ahnlab recently reported on GwisinLocker, a multi-platform ransomware targeting multiple verticals in South Korea.
Lilith Ransomware
Aug 4, 2022 2:37:11 PM / by PolySwarm Tech Team posted in Threat Bulletin, Ransomware, Lilith, Lilithcrypt
Executive Summary
Cyble recently reported on Lilith Ransomware, which appends the .lilith extension to encrypted files.
Recent Ransomware Threats to Healthcare
Jul 21, 2022 1:27:35 PM / by PolySwarm Tech Team posted in Threat Bulletin, North Korea, Ransomware, Iran, IcedID, Healthcare, Maui, Quantum, Hospital
Executive Summary
Multiple ransomware families have been used to target the healthcare vertical in the past year. In this report, we cover recently reported attacks on the healthcare vertical leveraging Maui and Quantum ransomware families.
HavanaCrypt Distributed Via Fake Google Software Update
Jul 18, 2022 12:04:52 PM / by PolySwarm Tech Team posted in Threat Bulletin, Ransomware, HavanaCrypt
Executive Summary
Trend Micro recently reported on HavanaCrypt ransomware, which is being distributed disguised as a fake Google software update.