HomeSecurityNews sites compromised due to WastedLocker ransomware attacks!

News sites hacked due to WastedLocker ransomware attacks!

The Russian gang “Evil Corp”, also known as “Dridex”, has compromised dozens of US owned by the same company, aiming to infect employees of more than 30 large private companies in the country, using fake software displayed by the malicious SocGholish JavaScript-based framework. The computers of employees of these companies were used as a means for the gang to infiltrate corporate networks, as part of a series of drive-by attacks. Symantec has confirmed the news that dozens of US news sites owned by the same parent company have been compromised by the code . According to Symantec, some organizations targeted by the WastedLocker ransomware could be compromised if an employee browsed the news on one of its sites. Threat Intelligence who discovered these attacks reported that the company that owned the compromised news sites was notified and the malicious code was removed.


Symantec said in a report published late last month that it had prevented the “Evil Corp” gang from deploying WastedLocker ransomware payloads during its attacks on 31 large private companies. Of those companies, 30 were American, including eight Fortune 500 companies.


Evil Corp has carried out attacks across a wide range of industries, with manufacturing, IT and telecommunications also being targeted. Symantec said that if Evil Corp members had not been decimated, they could have carried out successful attacks that could have caused millions in damage. As Symantec researchers explained, Evil Corp’s attacks began with the SocGholish framework, which was used to infect targets who visited more than 150 compromised sites. This was done by displaying fake update that delivered malware payloads to the targets’ devices, disguised as software updates.

attacks

After infecting a company employee, Evil Corp hackers used Cobalt Strike threat simulation software and various tools to steal credentials, achieve privilege escalation, and take control of the network, with the ultimate goal of encrypting computers with the WastedLocker ransomware. Before deploying the ransomware, the hackers disabled Windows Defender across their targets’ entire network using PowerShell scripts and legitimate tools.


If the WastedLocker ransomware payloads were successfully deployed using the Windows Sysinternals PsExec tool, they could encrypt data and delete Windows shadow volumes in order to delete backups and file snapshots and make them unrecoverable.

news sites

Evil Corp has been active since at least 2007 and distributed the Dridex malware toolkit, which was later used to spread malware payloads of other malicious actors. The gang was also involved in the distribution of the Locky ransomware, as well as its own ransomware strain, known as “BitPaymer” until 2019. In addition, two members of the gang were indicted by the US Department of Justice in late 2019 for their involvement in fraud and cyber-intrusions on international banks, resulting in the theft of at least $100 million. Since then, Evil Corp has revamped its tactics and is now back in the ransomware arena, deploying its new WastedLocker ransomware while carrying out attacks targeting businesses, demanding millions of dollars in ransom.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS