Found 2 bookmarks
Custom sorting
Meet NailaoLocker: a ransomware distributed in Europe by ShadowPad and PlugX backdoors
Meet NailaoLocker: a ransomware distributed in Europe by ShadowPad and PlugX backdoors
  • An unknown threat cluster has been targeting at least between June and October 2024 European organizations, notably in the healthcare sector. Tracked as Green Nailao by Orange Cyberdefense CERT, the campaign relied on DLL search-order hijacking to deploy ShadowPad and PlugX – two implants often associated with China-nexus targeted intrusions. The ShadowPad variant our reverse-engineering team analyzed is highly obfuscated and uses Windows services and registry keys to persist on the system in the event of a reboot. In several Incident Response engagements, we observed the consecutive deployment of a previously undocumented ransomware payload. The campaign was enabled by the exploitation of CVE-2024-24919 (link for our World Watch and Vulnerability Intelligence customers) on vulnerable Check Point Security Gateways. IoCs and Yara rules can be found on our dedicated GitHub page here.
·orangecyberdefense.com·
Meet NailaoLocker: a ransomware distributed in Europe by ShadowPad and PlugX backdoors
UK Hospital Hackers Say They’ve Demanded $50 Million in Ransom - Bloomberg
UK Hospital Hackers Say They’ve Demanded $50 Million in Ransom - Bloomberg
A cohort of Russian-speaking hackers is demanding $50 million from a UK lab-services provider to end a ransomware attack that has paralyzed services at London hospitals for weeks, according to a representative for the group. #Britain #Cancer #Ciaran #Europe #Government #Great #HEALTH #Kingdom #London #Martin #NATIONAL #Regulation #SERVICE #United #business #cybersecni #cybersecurity #technology
·bloomberg.com·
UK Hospital Hackers Say They’ve Demanded $50 Million in Ransom - Bloomberg