HomeSecuritySodinokibi Ransomware: Data leak and NASDAQ update on attacks

Sodinokibi Ransomware: Data Leak and NASDAQ Update on Attacks

The hackers behind the Sodinokibi Ransomware (REvil) have begun urging their associates to copy data before encrypting their victims' their systems. The stolen data will be uploaded to a site to expose victims who do not pay the ransom.

Sodinokibi Ransomware is often used as Ransomware-as-a-Service, where the ransomware operators manage the payment portal and software development, while "partners" distribute the ransomware.

Then, the hackers and their partners split the money they take from the victims.

Following the announcement by DoppelPaymer of a site that would expose victims' data, Sodinokibi's representative, Unknown, made a similar statement on a Russian hacking forum.

According to the post, the Sodinokibi hackers have created a “ blog ” where they will publish the stolen data of victims who do not pay the ransom. However, they will keep some information , such as social security numbers, to sell on the dark web.

Unknown stated that companies that fall victim to Sodinokibi (REvil) have “serious data privacy issues ” and need to move quickly into negotiations.

Unknown also said that he is considering other ways to further pressure victims into paying the ransom.

One idea he is considering is to send auto-emails to stock exchanges, such as NASDAQ, to inform them of attacks on companies and thus damage the value of their shares.

Sodinokibi ransomware NASDAQ

The following is the text, as translated from Russian:

“…..We have also completed our work on a blog where data from compromised systems will be published. We have asked all our “partners” to copy data, so we are confident that this blog will be used effectively. Not all information will be available ….. some information will be put up for sale…. Now we can say with certainty that all companies that have our product have serious privacy problems . We advise companies to start negotiations quickly, as we plan to expand and improve this blog. We are also thinking of sending emails to stockbrokers ( for example, NASDAQ) so that the financial situation of the companies will be directly affected.

Now all the data will be published on this blog.

xxx”.

The Sodinokibi spokesperson also released a file containing financial and tax data of a victim. Unknown stated that he would add more data to the file if the victim did not pay the ransom.

attacks should be treated as data breaches!

We've said it before. Ransomware attacks should breaches data now be treated as , as more and more hackers threaten to release victims' data.

The files stolen by ransomware gangs contain not only company data but also personal information of employees and customers.

Therefore, companies should always report ransomware attacks to keep everyone involved informed.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS