March 6th: EUROPOL announced the arrest of 2 individuals tied to DoppelPaymer ransomware group. German authorities state the March 6th arrests were related to a ransomware attack which resulted in the death of a patient September 18th, 2020 at DΓΌsseldorf Hospital.
π’26π3π2π€£2
As well as the arrests, the German government has issued warrants for arrest of 2 individuals.
1. Igor Turashev, the alleged 2nd in command for Evil Corp.
2. Irina Zemlianikina, another ransomware operator associated with Evil Corp.
1. Igor Turashev, the alleged 2nd in command for Evil Corp.
2. Irina Zemlianikina, another ransomware operator associated with Evil Corp.
π€£59π€―10π8β€1
The German government issued a warrant for Irina's arrest right before International Women's Day:(
π€£49π₯°14π«‘11π±2π1π1
The German government now posts images of wanted cyber criminals on posters in Berlin
Images via Joe Tidy / BBC
Images via Joe Tidy / BBC
π€£59π9π’6π4π€1
We've archived the vx-underground APT collection for the year 2022. You can now download every APT sample and paper from the year 2022 in bulk.
- 4,848 malware samples
- 480 papers
- 6.47GB (compressed)
Check it out here: https://samples.vx-underground.org/samples/Blocks/APT%20Collection/
- 4,848 malware samples
- 480 papers
- 6.47GB (compressed)
Check it out here: https://samples.vx-underground.org/samples/Blocks/APT%20Collection/
π13π₯7β€βπ₯2
Some individuals from Fiverr, an online freelancer marketplace, have contacted vx-underground.
A Threat Actor is social engineering freelancers, tricking them into running a loader which executes Redline stealer.
AnyRun Analysis: https://app.any.run/tasks/993103a3-2430-4b1c-8c6f-59a00913067d/
A Threat Actor is social engineering freelancers, tricking them into running a loader which executes Redline stealer.
AnyRun Analysis: https://app.any.run/tasks/993103a3-2430-4b1c-8c6f-59a00913067d/
app.any.run
Analysis php.exe (MD5: 1CEA59865D0DC12DFD361A5AD29B16AF) Malicious activity - Interactive analysis ANY.RUN
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
π24π5
This media is not supported in your browser
VIEW IN TELEGRAM
More context on vx-underground being featured on National Geographic
Video courtesy of realhackhistory
Video courtesy of realhackhistory
π€£66π₯4π2π2π€―1
We've updated the vx-underground Windows malware kernel paper collection.
- Lord Of The Ring0 - Part 1 - Part 4
Check it out here: https://www.vx-underground.org/windows.html#kernel_mode
- Lord Of The Ring0 - Part 1 - Part 4
Check it out here: https://www.vx-underground.org/windows.html#kernel_mode
π14β€7π―2π₯1
Lockbit ransomware group has ransomed a 3rd party parts manufacturer for SpaceX - they claim to possess over 3,000 proprietary schematics for SpaceX.
In the ransom announcement Lockbit issued a message to Elon Musk and SpaceX employees, taunting them.
Information via AlvieriD
In the ransom announcement Lockbit issued a message to Elon Musk and SpaceX employees, taunting them.
Information via AlvieriD
π₯48π€£16π7π±5π1
We've heard your complaints loud and clear. SentinelOne has expanded the giveaway.
tl;dr submit your best malware research and win a Macbook Pro and have your research featured on SentinelOne's website (and VXUG, duh)
*See attached image for details
sentinelone.com/lp/vx-s1/
tl;dr submit your best malware research and win a Macbook Pro and have your research featured on SentinelOne's website (and VXUG, duh)
*See attached image for details
sentinelone.com/lp/vx-s1/
β€27π’10π€1π«‘1
We worked damn hard with SentinelOne to ensure we can give someone a really cool laptop - to give an underdog a voice in research. If you nerds don't submit something cool we will deploy monkey-bonk on a catastrophic scale
π€£46π₯4π’2
March 5th: ALPHV ransomware group began leaking photos of topless female breast cancer patients.
March 14th: Patients effected by the ALPHV ransomware attack filed a class action lawsuit against the hospital.
Information via: AlvieriD
More info: https://www.lehighvalleylive.com/news/2023/03/cancer-patient-sues-lvhn-over-cyberattack-in-which-photos-data-were-leaked-on-dark-web.html
March 14th: Patients effected by the ALPHV ransomware attack filed a class action lawsuit against the hospital.
Information via: AlvieriD
More info: https://www.lehighvalleylive.com/news/2023/03/cancer-patient-sues-lvhn-over-cyberattack-in-which-photos-data-were-leaked-on-dark-web.html
lehighvalleylive
Cancer patient sues LVHN over cyberattack in which photos, data were leaked on dark web
LVHN was targeted by ALPHV, also known as BlackCat, which has threatened weekly releases of sensitive data unless a ransom is paid.
π’44π€£10π€―5π₯°2π1