November 11, 2019 By David Bisson 3 min read

Last week in security news, researchers revealed that the average ransomware payment surpassed $40,000 between the second and third quarters of 2019. Speaking of ransomware, security professionals explored an emerging means of distribution for the Nemty family and investigated the Buran ransomware-as-a-service (RaaS) platform. Others also observed multiple binaries of DoppelPaymer hosted on a server along with samples of TinyPOS malware and other digital threats.

Top Story of the Week: Ransomware Payments Grew in Q3 2019

In its “Q3 Ransomware Marketplace” report, Covewave found that the average ransomware payment had increased by 13 percent to $41,198 between the second and third quarters of 2019. Even so, the security firm’s researchers observed that the rate of increase for ransom payments had largely plateaued. They attributed this development to victims’ growing efforts to recover their files without paying ransomware attackers.

According to the report, victims began looking for other means of recovering their files despite the fact that they received a working decryptor after paying the ransom in 98 percent of infections. Additionally, 94 percent of victims found that the decryptor provided by attackers successfully recovered their affected data.

Source: iStock

Also in Security News

  • Digital Attack Strikes Renewable Energy Provider: Back in March, renewable energy provider SPower was the first U.S. company of its kind to suffer a digital attack against its IT infrastructure. The attack was also the first to compromise connections with power installations on U.S. soil.
  • First Wave of BlueKeep Attacks Underwhelm Security Observers: Security researchers saw a wave of attacks exploiting the BlueKeep zero-day vulnerability disclosed by Microsoft in May. But as reported by WIRED, those attacks didn’t cause as much destruction as experts feared, as they mainly consisted of installing and running a cryptocurrency miner on vulnerable machines.
  • Over 40 Million Users Exposed to Malicious Android Emoji Keyboard: Upstream blocked over 14 million suspicious transactions from 110,000 Android devices that had downloaded ai.type, an emoji keyboard. The keyboard disappeared from the Google Play store in June 2019, but the security firm noted that the 40 million users who had already installed the keyboard were still at risk.
  • Nemty Relying on Trik Botnet for Distribution: Symantec revealed that Nemty ransomware has partnered with the Trik botnet. This new technique expanded the reach of Nemty, a threat that also uses the RIG exploit kit and malspam campaigns as means of delivery.
  • Ransomware, POS Malware and Other Threats Hosted by Single C&C: Researchers at Cisco Talos uncovered a command-and-control (C&C) server that hosted several different binaries of the BitPaymer-derived DoppelPaymer ransomware family. They also found that the server contained TinyPOS malware, Mimikatz and tools for remotely connecting to Windows systems.
  • Buran Revealed to Have Evolved From Other Ransomware Families: McAfee analyzed the behavior, TTPs and artifacts of a Buran sample and determined that the ransomware was in fact an evolution of Jumper, a family that emerged two months before Buran. Jumper was the second iteration of the family’s lineage; researchers identified VegaLocker as its origin point.
  • Malvertisers Leveraged Fake Blockchain Ad to Distribute Capesand EK: Back in October, Trend Micro saw a malvertising campaign abruptly switch tactics and use a blockchain ad to begin linking to a new exploit kit instead of RIG. Researchers analyzed the exploit kit, which they named Capesand, and found it was unique in that its source code did not contain its exploit code.
  • Firefox Bug Abused by Tech Support Scammers to Prey Upon Users: Bleeping Computer found that digital fraudsters are using a Firefox browser lock bug to prevent users from closing the browser tab without viewing a fake tech support page. This scam instructed users to contact an illegitimate Windows Support line that likely tried to trick them into buying fake antivirus software.
  • Vulnerable Routers at Risk of Gafgyt Infection, DDoS Attacks: Palo Alto Networks’ Unit 42 research team uncovered an updated variant of the Gafgyt malware family. It found that the malware could target vulnerable wireless routers and enlist them into botnets for the purpose of conducting distributed denial-of-service (DDoS) attacks.

Security Tip of the Week: Defend Against a Ransomware Infection

Security professionals can help defend their organizations against a ransomware infection by using test phishing engagements to evaluate employees’ awareness of phishing attacks, one of the most common ransomware distribution vectors. Companies should also implement a backup strategy and regularly test it to make sure they can recover their files in the event of a ransomware infection.

More from

Cloud Threat Landscape Report: AI-generated attacks low for the cloud

2 min read - For the last couple of years, a lot of attention has been placed on the evolutionary state of artificial intelligence (AI) technology and its impact on cybersecurity. In many industries, the risks associated with AI-generated attacks are still present and concerning, especially with the global average of data breach costs increasing by 10% from last year.However, according to the most recent Cloud Threat Landscape Report released by IBM’s X-Force team, the near-term threat of an AI-generated attack targeting cloud computing…

Testing the limits of generative AI: How red teaming exposes vulnerabilities in AI models

4 min read - With generative artificial intelligence (gen AI) on the frontlines of information security, red teams play an essential role in identifying vulnerabilities that others can overlook.With the average cost of a data breach reaching an all-time high of $4.88 million in 2024, businesses need to know exactly where their vulnerabilities lie. Given the remarkable pace at which they’re adopting gen AI, there’s a good chance that some of those vulnerabilities lie in AI models themselves — or the data used to…

FBI, CISA issue warning for cross Apple-Android texting

3 min read - CISA and the FBI recently released a joint statement that the People's Republic of China (PRC) is targeting commercial telecommunications infrastructure as part of a significant cyber espionage campaign. As a result, the agencies released a joint guide, Enhanced Visibility and Hardening Guidance for Communications Infrastructure, with best practices organizations and agencies should adopt to protect against this espionage threat. According to the statement, PRC-affiliated actors compromised networks at multiple telecommunication companies. They stole customer call records data as well…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today