HomeSecurityHackers experiment with "data destruction" attacks

Hackers experiment with "data destruction" attacks

Hackers are experimenting with a new type of attack – data destruction – that, instead of encrypting data, completely destroys it. The goal is to make it impossible for victims to recover their data unless they pay the ransom.

See also: New info-stealer malware Erbium is distributed via game cracks

Hackers experiment with "data destruction" attacks

Ransomware is one of the biggest cybersecurity issues facing the world today, and while many victims refuse to give in to blackmail, many believe they have no choice but to pay for a decryption key.

However, according to cybersecurity researchers at Cyderes and Stairwell, at least one ransomware group is testing "data destruction" attacks.

This would be dangerous for ransomware victims because, while it is often possible to recover encrypted files without paying a ransom, the threat of complete server corruption if the extortion demands are not met could push more victims to back down.

Indicators of a possible new tactic were discovered when cybersecurity analysts responded to a BlackCat ransomware attack – also known as ALPHV.

See also: Adware: Ad-fraud apps found in Play Store and App Store

BlackCat is responsible for a number of ransomware incidents around the world, but ransomware criminals are always looking for new ways to make attacks more effective – and it appears they are trying out a new strategy with data-destroying.

Hackers experiment with "data destruction" attacks

The data destruction is linked to Exmatter, a .NET extraction tool that has been used in the past as part of BlackMatter ransomware attacks. It is widely suspected that the BlackCat group is a rebrand of BlackMatter – which in turn was a rebrand of Darkside, the ransomware operation behind the Colonial Pipeline.

In previous ransomware attacks, Exmatter has been used to download specific file types from selected directories and upload them to servers before the ransomware is executed on compromised systems and the files are encrypted – with the attackers demanding payment for the key.

See also: Anonymous hacked the National Bank of Iran (Bank Melli)

However, analysis of the new Exmatter sample used as part of a BlackCat attack suggests that, instead of encrypting files, the extraction tool is used to destroy files instead.

There are several reasons why hackers may be experimenting with this new tactic. First, the threat of data destruction instead of encryption could provide an additional incentive for victims of attacks to pay.

Also, developing destructive malware is less complex than designing ransomware – so using data destruction attacks could take fewer resources and time, providing attackers with greater profits.

data destruction

Ransomware and malware attacks can be extremely damaging, but there are steps organizations can take to make networks more robust and protect against attacks.

These include timely application of security patches and updates to stop hackers from exploiting known vulnerabilities to launch attacks, as well as ensuring that multi-factor authentication is available across the network to protect users.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS