Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
New RedAlert Ransomware targets Windows, Linux VMware ESXi servers

New RedAlert Ransomware targets Windows, Linux VMware ESXi serversPost Views: 5
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time:  3 Minutes
A new ransomware operation called RedAlert, or N13V, encrypts both Windows and Linux VMWare ESXi servers in attacks on corporate networks.
The new operation was discovered today by MalwareHunterTeam, who tweeted various images of the gang’s data leak site.

The ransomware has been called ‘RedAlert’ based on a string used in the ransom note. However, from a Linux encryptor obtained by BleepingComputer, the threat actors call their operation ‘N13V’ internally, as shown below.
https://www.bleepstatic.com/images/news/ransomware/r/redalert-n13v/help-file.jpg
-w Run command for stop all running VM`s
-p Path to encrypt (by default encrypt only files in directory, not include subdirectories)
-f File for encrypt
-r Recursive. used only with -p ( search and encryption will include subdirectories )
-t Check encryption time(only encryption, without key-gen, memory allocates ...)
-n Search without file encryption.(show ffiles and folders with some info)
-x Asymmetric cryptography performance tests. DEBUG TESTS
-h Show this messageWhen running the ransomware with the ‘-w‘ argument, the Linux encryptor will shut down all running VMware ESXi virtual machines using the following esxcli command: esxcli --formatter=csv --format-param=fields=="WorldID,DisplayName" vm process list | tail -n +2 | awk -F $',' '{system("esxcli vm process kill --type=force --world-id=" $1)}'See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png When encrypting files, the ransomware utilizes the NTRUEncrypt public-key encryption algorithm, which support various ‘Parameter Sets’ that offer different levels of security.

An interesting feature of RedAlert/N13V is the ‘-x’ command-line option that performs ‘asymmetric cryptography performance testing’ using these different NTRUEncrypt parameter sets. However, it is unclear if there is a way to force a particular parameter set when encrypting and/or if the ransomware will select a more efficient one.

The only other ransomware operation known to use this encryption algorithm is FiveHands.
https://www.bleepstatic.com/images/news/ransomware/r/redalert-n13v/encryption-algo-test.jpg
.log
.vmdk
.vmem
.vswp
.vmsnIn the sample analyzed by BleepingComputer, the ransomware would encrypt these file types and append the .crypt658 extension to the file names of encrypted files.
https://www.bleepstatic.com/images/news/ransomware/r/redalert-n13v/encrypted-files.jpg
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking New RedAlert Ransomware targets Windows, Linux VMware ESXi servers New RedAlert Ransomware targets Windows, Linux VMware ESXi serversPost Views: 5 Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Patreon.png…
ription of the stolen data and a link to a unique TOR ransom payment site for the victim.
https://www.bleepstatic.com/images/news/ransomware/r/redalert-n13v/n13v-ransom-note.jpg
“Board of Shame”Like almost all new enterprise-targeting ransomware operations, RedAlert conducts double-extortion attacks, which is when data is stolen, and then ransomware is deployed to encrypt devices.

This tactic provides two extortion methods, allowing the threat actors to not only demand ransom to receive a decryptor but also demand one to prevent the leaking of stolen data.

When a victim does not pay a ransom demand, the RedAlert gang publishes stolen data on their data leak site that anyone can download.
https://www.bleepstatic.com/images/news/ransomware/r/redalert-n13v/data-leak-site.jpg
Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/django-5-90x90.jpg Django fixes SQL Injection vulnerability in new releases1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ezgif.com-gif-maker-1-90x90.jpg Rogue HackerOne employee steals bug reports to sell on the side2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ezgif.com-gif-maker-2-90x90.jpg Microsoft Exchange servers worldwide backdoored with new malware5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ezgif.com-gif-maker-1-90x90.jpg CISA warns of hackers exploiting PwnKit Linux vulnerability6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/eba5863be05547fb146c9c8c0ed43c52-90x90.jpg Dozens of cryptography libraries vulnerable to private key theft1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ezgif.com-gif-maker-90x90.jpg Researchers crack MEGA’s ‘privacy by design’ storage, encryption1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/f9ed623c5c-90x90.jpg Google Warns Spyware Being Deployed Against Android, iOS Users1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/170720-poulsen-fancy-bear-tease_zzzwzw-90x90.jpg Fancy Bear Uses Nuke Threat Lure to Exploit 1-Click Bug2 weeks ago
* https://www.blackhatethicalhacking.com/wp-co[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
ription of the stolen data and a link to a unique TOR ransom payment site for the victim. https://www.bleepstatic.com/images/news/ransomware/r/redalert-n13v/n13v-ransom-note.jpg “Board of Shame”Like almost all new enterprise-targeting ransomware operations…
ntent/uploads/2022/06/intro_toddycat_apt-800x450-1-90x90.jpg Elusive ToddyCat APT Targets Microsoft Exchange Servers2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/office-365-90x90.jpg Office 365 Config Loophole Opens OneDrive, SharePoint Data to Ransomware Attack2 weeks ago
The post New RedAlert Ransomware targets Windows, Linux VMware ESXi servers first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Found 13 vulnerabilities on an application as an intern, now I don't know what to do, 2 months left.
https://www.reddit.com/r/Pentesting/comments/vsmm9f/found_13_vulnerabilities_on_an_application_as_an/

Hello, I've gotten an internship as a pentester and have been testing a fun application for a month now and I have found 13 vulnerabilities so far. Now, I really don't know what to do, I feel like I hit a wall and stagnated for a bit. Currently doing a bit of bug bounties on HackerOne or reading about vulnerabilities to spend my time well to an extent. ​ Do you have any advice, feedback? ​ Much appreciated! submitted by /u/belusic (https://www.reddit.com/user/belusic)
[link] (https://www.reddit.com/r/Pentesting/comments/vsmm9f/found_13_vulnerabilities_on_an_application_as_an/) [comments] (https://www.reddit.com/r/Pentesting/comments/vsmm9f/found_13_vulnerabilities_on_an_application_as_an/)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Do any hackable flip phones or slide phones exist?

First off sorry if this isn’t the ideal sub for this but I couldn’t think of a better place. I used an Alcatel for about 3 years and now I’m temporarily on a smartphone again. I want something with hotspot support and that allows for easily running custom code on. I’ve tried to investigate it but the market seems lacking.

submitted by /u/GuyInTheYonder
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How do you hack an IDE

So my school has an IDE compiler for c that students have access to for coding and submitting coding assignments. It doesn’t allow copy and pasting

Theoretically how can I hack into it to enable that. Throw as much terminology as you want and give a detailed description. I’m very interested to learn more

submitted by /u/jjuliius
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
"Unsolicited incoming ICMP6 reply detected, this is a kind of MAC spoofing that may consequently do harm to your computer"

I am getting this on the notification tray on the laptop with symantec security. Can someone explain what this means in simple terms? This message is only shown on the device with symantec security, other devices have malwarebytes antivirus and not getting any message. I am worried that my network might be compromised and some middle man is stealing my info. Please help

submitted by /u/CraftingBlue28
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is there a market for mail server logs?

I sometimes came across offers for mail server logs in fraud forums. Since then i wonder whether there is a market for this? Those logs would expose mail adresses, names and context suitable for phishing or spear phising campaigns. Are actually people with access to suitable servers selling those logs in order to make some money? And is there a demand for it on a larger scale?

submitted by /u/rollerjunge
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video