Intuit Warns QuickBooks Customers Of Ongoing Phishing Campaign

Intuit is warning its Quickbooks users that they may be targeted by an ongoing phishing campaign impersonating the company and trying to lure potential victims with fake renewal charges.

The company stated that they have been receiving reports from its users about an on-going phishing campaign. “This email did not come from Intuit. The sender is not associated with Intuit, is not an authorized agent of Intuit, nor is their use of Intuit’s brands authorized by Intuit,” Intuit explained.

The financial software firm advises all customers who received one of these phishing messages not to click any links embedded in the emails or open attachments.

Users who have already click-through links on the phishing emails are advised to do the following:

  • Delete any downloaded files immediately.
  • Scan their systems using an up-to-date anti-malware solution.
  • Change their passwords.
  • Intuit also provides information on how customers can protect themselves from phishing attempts on its support website.

Intuit’s users are common targets for phishing attacks. In July, Intuit also alerted its customers of phishing emails, asking them to call a phone number to upgrade to QuickBooks 2021 until the end of the month to avoid having their databases corrupted or company backup files removed automatically.

Intuits is also being impersonated by other hackers in a fake copyright scam, according to SlickRockWeb CEO Eric Ellason said today.

Recipients targeted by these emails risk infecting themselves with the Hancitor (aka Chanitor) malware downloader or have Cobalt Strike beacons deployed on their systems.

The embedded links send the potential victims through advanced redirection chains using various security evasion tactics and victim fingerprinting malspam.

In June, Intuit also notified TurboTax customers that some of their personal and financial info was accessed by attackers following a series of account takeover attacks. The company also said that that was not a “systemic data breach of Intuit.”

The company’s investigation revealed that the attackers used credentials obtained from “a non-Intuit source” to access the customers’ accounts and their name, Social Security number, address(es), date of birth, driver’s license number, financial information, and more.

TurboTax customers were targeted in at least three other account takeover attack campaigns in 2014/2015 and 2019.

Protection Against Phishing

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

Ecuador’s Largest Bank Taken Offline By Cyberattack

Ecuador’s largest private bank Banco Pichincha has suffered a cyberattack that disrupted operations to the extent that ATMs and the online banking portal were taken out. The cyberattack occurred this weekend, causing Banco Pichincha to shut down parts of their network to halt the spread of the infection.

The shutdown of their systems due to the cyberattack lead to widespread disruptions, with ATMs and the bank’s online service showing maintenance messages.

In an internal notification sent to the Bank’s agencies, employees are notified that bank applications, email, digital channels, and self-services will not be operational due to a technology issue.

The document goes on to say that self-service customers should be directed to bank teller windows to be served during the outage.

After two days of silence regarding the outage, Banco Pichincha issued a statement Tuesday afternoon admitting that they suffered a cyberattack that led to the disruption of their systems.

The banks statement in English can be found here:

“In the last few hours, we have identified a cybersecurity incident in our computer systems that have partially disabled our services. We have taken immediate actions such as isolating the systems potentially affected from the rest of our network and have cybersecurity experts to assist in the investigation.

At the moment, our network of agencies, ATMs for cash withdrawals and payments with debit and credit cards are operational.

This technological incident did not affect the financial performance of the bank. We reiterate our commitment to safeguard the interests of our clients and restore normal care through our digital channels in the shortest possible time.

We call for calm to avoid generating congestion and to stay informed through the official channels of Banco Pichincha to avoid the spread of false rumors.”

Today, the only banking portal still shows a maintenance message but customers are able to access their online accounts. The mobile application is still shut down from the cyberattack.

At this time, the bank has not disclosed the nature of the cyberattack. However, researchers at BleepingComputer believe that it is a ransomware attack with threat actors installing a Cobalt Strike beacon on the network.

Ransomware gangs and other threat actors commonly use Cobalt Strike to gain persistence and access to other systems on a network.

In February, Banco Pichincha suffered another cyberattack by cybercriminals known as ‘Hotarus Corp’ who claimed to have stolen files from the bank’s network.

Pichincha disputed the hacker’s claims and said that one of their providers was breached instead.

“We know that there was unauthorized access to the systems of a provider that provides marketing services for the Pichincha Miles program,” Banco Pichincha said at the time.

“In relation to this information leak, and based on an extensive investigation, we have found no evidence of damage or access to the Bank’s systems and, therefore, the security of our clients’ financial resources is not compromised.”

Protection Against Cyberattacks

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

Identity Theft Alarms Sound as Data Breach Affects 1.6 Million Mercedes-Benz Customers

Identity Theft may become a concern for Mercedes-Benz owners and even potential buyers as the company has disclosed a massive data breach recently. The automobile company assessed 1.6 million customer records, including customer names, addresses, emails, phone numbers, and some purchased vehicle information to determine the impact. It appears that much of the data exposed in the data breach includes social security numbers, driver license numbers, and credit card information. Currently, it is not believed that all of the 1.6 million individuals affected have had their more personal information like SSNs exposed.

On June 11th, a vendor for the German automotive brand informed the company that the personal information of a number of customers was exposed due to an insufficiently secured cloud storage instance.

According to Mercedez-Benz, the breach affects customers and potential buyers who has entered sensitive information on the company website between 2014 and 2017. This also applies to Mercedez-Benz website.

“It is our understanding the information was entered by customers and interested buyers on dealer and Mercedes-Benz websites between January 1, 2014 and June 19, 2017.”

“No Mercedes-Benz system was compromised as a result of this incident, and at this time, we have no evidence that any Mercedes-Benz files were maliciously misused.”

“Data security is a serious matter for MBUSA. Our vendor confirmed that the issue is corrected and that such an event cannot be replicated.”

“We will continue our investigation to ensure that this situation is properly addressed,”  said Mercedes-Benz in a press release.

Given the lengthy time scale and the number of uses affected, fears of identity theft have been sparked. Information such as social-security numbers are the key to carry out identity theft on unsuspecting victims.

The vendor who notified Mercedez-Benz of the data breach states that the exposed information included:

  • Self-reported customer credit scores
  • Driver license numbers
  • Social Security Numbers (SSNs)
  • Credit card numbers
  • Dates of Birth

The company also stated in their press release that the information would not have been searchable on or indexed by a typical search engine.

“To view the information, one would need knowledge of special software programs and tools – an Internet search would not return any information contained in these files,” says Mercedes-Benz.

The company is in the process of contacted affected individuals whose data was exposed in the breach.

“Any individual who had credit card information, a driver’s license number or a social security number included in the data will be offered complimentary 24-month subscription to a credit monitoring service. We will also notify the appropriate government agencies,” says the vehicle company.

The full amount of users affected by the breach is not known. Cybersecurity researchers at BleepingComputer have reached out to the company for more details but have yet to get a response.

The Dangers of Identity Theft

Identity Theft can be absolutely devastating for an individual. Usually, in the world of malware, we know certain things can be harmed. Our devices may need to be replaced, we may lose access to accounts for a few days or even forever, we may even need to pay a ransom for access to our data. The point is, with most types of Malware, we can eventually rebuild, though it may take longer than we anticipate. The fallout from identity theft is much longer.

Once your stolen information is used once, it can take anywhere from a few days to six months for that one incident. But your information is out there for a very, very long time. This means you could end up dealing with identity theft for many years, even decades.

Identity Theft has been around for a very long time and predates our modern technology by thousands of years. There have always been individuals that try to impersonate others for their own gain, financial or otherwise. However, the internet’s birth and wide adoption have led to new attack vectors, dwarfing any possible past attempts.

Now more than ever do we have data tied into our personal identity. Email addresses, banking numbers, phone numbers, social security numbers, home addresses – All of these and more form a picture of us as lines in a database.

And when this information falls into the wrong hands, it can do a lot of damage. Bank accounts can be drained, and your credit rating can get rattled; you can end up with medical bills or even a criminal record. The list of potential mishaps that can arise from identity theft is endless.

To hackers, identity theft represents a lucrative stream of income, and they can very easily cover their tracks. After they have seized personal information, they sell it on the dark web. This information can be sold over time, repeatedly, meaning that if you notice your identity has been stolen and used, it can be used in several instances over a long period of years.

There are some guidelines from the US government in discovering if you are a victim of identity theft if it is not immediately obvious:

  • You stop receiving your regular bills and credit card statements.
  • You receive statements for accounts you never opened.
  • Debt collectors start calling you day and night about debts you’ve never heard of.
  • The IRS alleges you failed to report income for a company you never worked for.
  • You see withdrawals/charges on your bank or credit card statement that you didn’t make.
  • You try to file your taxes only to discover that someone else beat you to it.
  • You try to file your taxes and find someone claimed your child as a dependent already.
  • Your credit report includes lines of credit you never opened.
  • Your credit score fluctuates wildly and for no apparent reason.
  • The most obvious sign—you receive a notification that you’ve been the victim of a data breach.
  • If you are unsure, it is always best to check with the authorities on the US government’s identity theft website.

Protection

In some cases, a victim cannot be faulted for identity theft. For example, those affected by the data breach handed their information over to companies in good faith in the story above. Unfortunately, these companies, or more specifically the vendor, failed in protecting this information. However, many other times, business owners and families are singled out and targeted in their offices and homes.

For times like these, it is critical that you have the right tools to protect yourself. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

 

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

REvil Ransomware hits Fashion Company French Connection

REvil Ransomware has hit high street this week, as the fashion company French Connection has become infected with the notorious strain of ransomware. It is believed that REvil Ransomware operators breached the company’s back-end and stole private internal data. French Connection was established in 1972. Originally founded as a mid-market fashion brand, the company has since expanded to include men’s and women’s accessories.

While the exact attack vector has not yet been confirmed, cybersecurity researchers believe that the hackers exploited a security vulnerability on the back-end to carry out the attack. It is likely that unpatched software or hardware led to the breach and following encryption.

The gang has been using the scans of several high-profile individuals, including those of the founder and chief executive Stephen Marks, chief financial officer Lee Williams, and chief operating officer Neil Williams, to prove the breach took place.

French Connection has confirmed that it was the target of a cyber-attack that affected its back-end servers. Although it is believed that the front-end servers – those that process payments for French Connection’s online outlets – were not affected by the attack, the company noted.

Due to a breach, the company immediately suspended all systems and engaged third-party experts to help resolve the situation:

“As soon as it became aware of the breach, the company took immediate action, suspending all affected systems and engaging third-party experts to assist with resolving the situation,” French Connection’s statement continued. “The company is now actively working to restore its systems as quickly and safely as possible and where necessary is using manual overrides to ensure that the company can continue to operate.”

French Connection said it had no evidence that any data related to its customers was accessed during the breach, and the company is “continuing to operate largely as normal.”

The company have yet to disclose the amount demanded by REvil Ransomware operators.

REvil Ransomware Analysis

REvil Ransomware is a Ransomware-as-a-Service (RaaS), meaning it can be sold on a subscription basis and is usable by just about anybody. In 2020, it extorted large amounts of money for corporations and individuals. According to researchers, it is the most widespread ransomware strain. Groups using have a knack for shaking down businesses that don’t meet their demands, often through threats or leaking dating.

REvil Ransomware, also known as Sodinokibi, first appeared in April 2019 and rose to prominence after another RaaS gang called GandCrab shut down its service. REvil was first advertised on Russian-language cybercrime forums. The main actor associated with advertising and promoting REvil ransomware is called Unknown aka UNKN.  In the early days of REvil, researchers and security firms identified it as a strain of GandCrab, or at least established multiple links between the two. An alleged member of the group, using the handle Unknown, confirmed in an interview that the ransomware was not a new creation and that it was built on top of an older codebase that the group acquired.

The group behind REvil Ransomware and other groups selling RaaS often do so on a commission basis. Usually, this means a cut of between 20% and 30% of the money earned through infecting victims with ransomware.

In 2020, the IBM Security X-Force Incident Response reported that 1 in 3 Ransomware infections were caused by REvil Ransomware.

In February 2021, the REvil ransomware operation posted a job notice where they were looking to recruit people to perform DDoS attacks and use VOIP calls to contact victims and their partners.

In March, a security researcher known as 3xp0rt discovered that REvil has announced that they were introducing new tactics that affiliates can use to exert even more pressure on victims.

These new tactics include a free service where the threat actors, or affiliated partners, will perform voice-scrambled VOIP calls to the media and victim’s business partners with information about the attack. The ransomware gang is likely assuming that warning businesses that their data may have been exposed in an attack on of their partners, will create further pressure for the victim to pay.

REvil Ransomware is also providing a paid service that allows affiliates to perform Layer 3 and Layer 7 DDoS attacks against a company for maximum pressure. A Layer 3 attack is commonly used to take down the company’s Internet connection. In contrast, threat actors would use a Layer 7 attack to take down a publicly accessible application, such as a web server.

It is highly configurable, and it can be customized to behave differently depending on the host. This makes it a highly attractive RaaS client. Some of its features include:

  • Exploits a kernel privilege escalation vulnerability to gain SYSTEM privileges using CVE-2018-8453.
  • Whitelists files, folders and extensions from encryption.
  • Kills specific processes and services prior to encryption.
  • Encrypts files on local and network storage.
  • Customizes the name and body of the ransom note, and the contents of the background image.
  • Exfiltrates encrypted information on the infected host to remote controllers.
  • REvil Ransomware uses Hypertext Transfer Protocol Secure (HTTPS) for communication with its controllers.

REvil ransomware exploits a kernel privilege escalation vulnerability in win32k.sys tracked as CVE-2018-8453 to gain SYSTEM privileges on the infected host. If the configuration instructs a sample to execute this exploit, it will allocate executable memory, decrypt the exploit code in the newly allocated region and invoke it.

Protection Against Ransomware

REvil Ransomware and other Ransomware clients are some of the most common and deadly cybersecurity threats out there today. Families and businesses should be aware of these threats, and equip the right tools to tackle them. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

REvil Ransomware infects network of diagnostics corporation Grupo Fleury

REvil Ransomware has struck the healthcare industry once again, infecting the network of healthcare giant Grupo Fleury, an attack that disrupted business operations and forced company systems offline. Grupo Fleury is a Brazilian healthcare company founded in 1926, whose main activity is the provision of medical services and diagnostic medicine. With around 60 million exams performed in 2016, it is the second-largest company in the area in Brazil. The company has 200 service centers and more than 10,000 employees in the region.

Since the attack, the Fleury website displayed an alert stating that they suffered an attack and systems were not accessible.

“Please be advised that our systems are currently unavailable and that we are prioritizing the restoration of services. The causes of this unavailability originated from the attempted external attack on our systems, which are having operations reestablished with all the resources and technical efforts for the rapid standardization of our services.” read the alert translated into English.

Announcement of the attack on the Grupo Fleury website

Due to the REvil Ransomware infection, patients are unable to schedule tests, be they lab or clinical.

While local media has received confirmation that the company has suffered a cyberattack, Grupo Fleury has not officially confirmed a ransomware attack. However, many independent cybersecurity researchers have been analyzing the incident, and researchers at BleepingComputer have confirmed it is a REvil Ransomware infection.

This ransomware operation is responsible for numerous high-profile attacks, including Brazil’s Rio Grande do Sul court system, nuclear weapons contractor Sol Oriens, and JBS, the world’s largest meat producer.

In the sample BleepingComputer is working with, it is believed that the ransom demanded by the gang in this case is $5 Million.

Ransom demands, discovered by REvil Ransomware

REvil is known for stealing files before encrypting devices and then using the stolen data as leverage to get a company to pay the ransom.

From the ransomware sample, no proof of stolen data or mention of the victim’s name has been shared by the attackers at this time.

If data has been stolen, Grupo Fleury’s data is of significant concern as it could contain enormous amounts of personal and medical data of patients.

REvil Ransomware Analysis

REvil Ransomware is a Ransomware-as-a-Service (RaaS), meaning it can be sold on a subscription basis and is usable by just about anybody. In 2020, it extorted large amounts of money for corporations and individuals. According to researchers, it is the most widespread ransomware strain. Groups using have a knack for shaking down businesses that don’t meet their demands, often through threats or leaking dating.

REvil Ransomware, also known as Sodinokibi, first appeared in April 2019 and rose to prominence after another RaaS gang called GandCrab shut down its service. REvil was first advertised on Russian-language cybercrime forums. The main actor associated with advertising and promoting REvil ransomware is called Unknown aka UNKN.  In the early days of REvil, researchers and security firms identified it as a strain of GandCrab, or at least established multiple links between the two. An alleged member of the group, using the handle Unknown, confirmed in an interview that the ransomware was not a new creation and that it was built on top of an older codebase that the group acquired.

The group behind REvil Ransomware and other groups selling RaaS often do so on a commission basis. Usually, this means a cut of between 20% and 30% of the money earned through infecting victims with ransomware.

In 2020, the IBM Security X-Force Incident Response reported that 1 in 3 Ransomware infections were caused by REvil Ransomware.

In February 2021, the REvil ransomware operation posted a job notice where they were looking to recruit people to perform DDoS attacks and use VOIP calls to contact victims and their partners.

In March, a security researcher known as 3xp0rt discovered that REvil has announced that they were introducing new tactics that affiliates can use to exert even more pressure on victims.

These new tactics include a free service where the threat actors, or affiliated partners, will perform voice-scrambled VOIP calls to the media and victim’s business partners with information about the attack. The ransomware gang is likely assuming that warning businesses that their data may have been exposed in an attack on of their partners, will create further pressure for the victim to pay.

REvil Ransomware is also providing a paid service that allows affiliates to perform Layer 3 and Layer 7 DDoS attacks against a company for maximum pressure. A Layer 3 attack is commonly used to take down the company’s Internet connection. In contrast, threat actors would use a Layer 7 attack to take down a publicly accessible application, such as a web server.

It is highly configurable, and it can be customized to behave differently depending on the host. This makes it a highly attractive RaaS client. Some of its features include:

  • Exploits a kernel privilege escalation vulnerability to gain SYSTEM privileges using CVE-2018-8453.
  • Whitelists files, folders and extensions from encryption.
  • Kills specific processes and services prior to encryption.
  • Encrypts files on local and network storage.
  • Customizes the name and body of the ransom note, and the contents of the background image.
  • Exfiltrates encrypted information on the infected host to remote controllers.
  • REvil Ransomware uses Hypertext Transfer Protocol Secure (HTTPS) for communication with its controllers.

REvil ransomware exploits a kernel privilege escalation vulnerability in win32k.sys tracked as CVE-2018-8453 to gain SYSTEM privileges on the infected host. If the configuration instructs a sample to execute this exploit, it will allocate executable memory, decrypt the exploit code in the newly allocated region and invoke it.

Protection Against Ransomware

REvil Ransomware and other Ransomware clients are some of the most common and deadly cybersecurity threats out there today. Families and businesses should be aware of these threats, and equip the right tools to tackle them. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all 

Intuit TurboTax Warns Customers of Identity Theft Following Data Breach

Identity Theft is on the cards again for users of Intuit TurboTax as the company has suffered a significant data breach – One of many in the last few years. The company notified customers of the breach, in which hackers stole personal and financial information following a series of account takeovers. In a breach notification letter sent to affected customers earlier this month, the company said that this was not a “systemic data breach of Intuit.” In account takeover attacks, cybercriminals gain access to their victims’ accounts using credentials stolen from other online services following past data breaches.

This type of attack works incredibly well against targets who use the same login credentials for multiple sites or services. “We have more than 100 million customers and see billions of transactions per year with ATO notifications going to less than .0003% of customers and some of those confirmed by the customer after the fact as their activity (not an ATO),” Rick Heineman, Intuit Corporate Communications Vice President, said in a statement to BleepingComputer.

TurboTax is a software package for the preparation of American income tax returns, produced by Intuit. TurboTax is a market leader in its product segment, competing with H&R Block Tax Software and TaxAct. TurboTax was developed by Michael A. Chipman of Chipsoft in 1984 and was sold to Intuit in 1993.

Intuit discovered the breach during a security review, in which they found an undisclosed number of TurboTax accounts were breached and customer info was exposed. This has lead to a fear of identity theft.

“By accessing your account, the unauthorized party may have obtained information contained in a prior year’s tax return or your current tax return in progress, such as your name, Social Security number, address(es), date of birth, driver’s license number and financial information (e.g., salary and deductions), and information of other individuals contained in the tax return,” Intuit explained.

“We deeply regret that this incident may affect you. Intuit has taken various measures to help ensure that the accounts of affected customers are protected. We are notifying you so you can take steps to help protect your information,” the company added.

After discovering the attacks, Intuit temporarily disabled the breached TurboTax accounts. Users who had their accounts deactivated must contact Intuit’s Customer Care department at 1-800-944-8596 and say “Security” when prompted.

This is not the first time a TurboTax breach has sparked identity theft concerns.

TurboTax customers were previously targeted in at least three other series of account takeover attacks in 2014/2015 and again in 2019.

Just as after the previous three incidents, Intuit provides one year of free identity protection, credit monitoring, and Experian IdentityWorks identity restoration services to impacted customers.

The Dangers of Identity Theft

Identity Theft can be absolutely devastating for an individual. Usually, in the world of malware, we know certain things can be harmed. Our devices may need to be replaced, we may lose access to accounts for a few days or even forever, we may even need to pay a ransom for access to our data. The point is, with most types of Malware, we can eventually rebuild, though it may take longer than we anticipate. The fallout from identity theft is much longer.

Once your stolen information is used once, it can take anywhere from a few days to six months for that one incident. But your information is out there for a very, very long time. This means you could end up dealing with identity theft for many years, even decades.

Identity Theft has been around for a very long time and predates our modern technology by thousands of years. There have always been individuals that try to impersonate others for their own gain, financial or otherwise. However, the internet’s birth and wide adoption have led to new attack vectors, dwarfing any possible past attempts.

Now more than ever do we have data tied into our personal identity. Email addresses, banking numbers, phone numbers, social security numbers, home addresses – All of these and more form a picture of us as lines in a database.

And when this information falls into the wrong hands, it can do a lot of damage. Bank accounts can be drained, and your credit rating can get rattled; you can end up with medical bills or even a criminal record. The list of potential mishaps that can arise from identity theft is endless.

To hackers, identity theft represents a lucrative stream of income, and they can very easily cover their tracks. After they have seized personal information, they sell it on the dark web. This information can be sold over time, repeatedly, meaning that if you notice your identity has been stolen and used, it can be used in several instances over a long period of years.

There are some guidelines from the US government in discovering if you are a victim of identity theft if it is not immediately obvious:

  • You stop receiving your regular bills and credit card statements.
  • You receive statements for accounts you never opened.
  • Debt collectors start calling you day and night about debts you’ve never heard of.
  • The IRS alleges you failed to report income for a company you never worked for.
  • You see withdrawals/charges on your bank or credit card statement that you didn’t make.
  • You try to file your taxes only to discover that someone else beat you to it.
  • You try to file your taxes and find someone claimed your child as a dependent already.
  • Your credit report includes lines of credit you never opened.
  • Your credit score fluctuates wildly and for no apparent reason.
  • The most obvious sign—you receive a notification that you’ve been the victim of a data breach.
  • If you are unsure, it is always best to check with the authorities on the US government’s identity theft website.

Protection

In some cases, a victim cannot be faulted for identity theft. For example, those affected by the data breach handed their information over to companies in good faith in the story above. Unfortunately, these companies, or more specifically the vendor, failed in protecting this information. However, many other times, business owners and families are singled out and targeted in their offices and homes.

For times like these, it is critical that you have the right tools to protect yourself. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

Ransomware Hits Catering Service Supplier Edward Don

Ransomware has hit one of the nation’s largest catering service suppliers, Edward Don. Edward Don and Company is one of the largest distributors of foodservice equipment and supplies, such as kitchen supplies, bar supplies, flatware, and dinnerware. The ransomware attack has forced the company to take down parts of its network, affecting customer relations and communications. The infection has disrupted their business operations, including their phone systems, network, and email.

The email outage forced company employees to use personal Gmail accounts to communicate with customers and vendors regarding urgent orders or fulfillment issues.

Reporters at BleepingComputer have pressed the company for information regarding the ransomware attack, but Edward Don has yet to release a statement. However, employees have stated that they cannot accept new orders until the systems are brought back online.

As Edward Don is one of the leading distributors of foodservice supplies, this attack will cause a significant disruption in the supply chain for hospitals, restaurants, hotels, and bars.

There has yet to be confirmation on what strain of ransomware is responsible for the attack. However, given the current ransomware climate, it could be one of many. Despite this, Advanced Intel CEO Vitali Kremez stated that the company might have been infected by the Qbot malware based on their adversarial visibility.

Following Kremez’ suggestion, other researchers have confirmed the Qbot trojan was on Edward Don’s network, and as such likely became a foothold for ransomware to enter their system. In the past, the ProLock and Egregor ransomware gangs partnered with Qbot. Since their shutdown, the REvil ransomware gang has been utilizing the botnet.

The Qbot Trojan has been plaguing computer users and businesses for over a decade and the cybercriminals behind it are still coming up with new tricks that keep it one of the most prevalent and successful malware threats.

Qbot, also known as Qakbot or Pinkslipbot, started out as a banking Trojan focused on stealing online banking credentials, but has since evolved into a “Swiss Army knife” that’s used for a variety of purposes including distributing ransomware.

LAst year, a new Qbot variant started being distributed by another Trojan called Emotet as part of a new spam campaign that affected many organizations worldwide. That new variant exhibited new features and a new command-and-control infrastructure. This continued with a renewed Qbot distribution campaign late last year.

“One of Qbot’s new tricks is particularly nasty, as once a machine is infected, it activates a special ‘email collector module’ which extracts all email threads from the victim’s Outlook client, and uploads it to a hardcoded remote server,” Check Point researchers said in a report. “These stolen emails are then utilized for future malspam campaigns, making it easier for users to be tricked into clicking on infected attachments because the spam email appears to continue an existing legitimate email conversation.”

Qbot Trojan Analysis: A Foothold For Ransomware

Note: This analysis of Qbot was carried out by independent cybersecurity researcher Abdallah Elshinbary.

QBot can be delivered in various different ways including Malspam (Malicious Spam) or dropped by other malware families like Emotet.

The infection flow for this campaign is as follows:

First, the victim receives a phishing email with a link to a malicious zip file. The zip file contains a very obfuscated VBS file which downloads and launches Qbot executable. The VBS file tries to download Qbot from several addresses.

Most of QBot strings are encrypted (stored in a continuous blob) and they are decrypted on demand. The decryption routine accepts one argument which is the index to the string then it XORs it with a hardcoded bytes array until it encounters a null byte.

QBot spawns a new process of itself with the “/C” parameter, this process is responsible for doing Anti-Analysis checks. The trojan performs this to try stop researchers examining it.

In VMWare, communication with the host is done through a specific I/O port (0x5658), so QBot uses the in assembly instruction to detect VMWare by reading from this port and checking the return value in ebx if it’s equal to VMXh. Another Anti-VM trick is to check hardware devices against known devices names used by VMs and Sandboxes.

The last check is done using CPUID instruction. First it is executed with EAX=0 to get the CPU vendor and compares it with GenuineIntel (Intel processor). Then it is executed with EAX=1 to get the processors features. On a physical machine the last bit will be equal to 0. On a guest VM it will equal to 1.

After the Anti-Analysis checks, QBot drops a copy of itself along with a configuration file at “%APPDATA%\Microsoft\”. Finally, QBot starts the dropped copy in a new process and overwrites itself with a legitimate executable.

The dropped configuration file is accessed frequently by Qbot, this file is RC4 encrypted.

QBot obfuscates its communication with the C2 (Command-and-Control) server by encrypting the payloads using RC4 and encoding the result using Base64. The communication is also done over SSL.

After establishing communication, the C2 server will send commands indexes to be executed.

QBot can spread through the network by enumerating network shares using WNetOpenEnumW() and WNetEnumResourceW() then it drops a copy of Qbot into the shared folders.

When Qbot ensures it is not in analysis, and communication to the C2 server has been established, it can begin delivering other malware such as ransomware onto the system.

Protection

Ransomware is a serious online threat, one that is faced by businesses and families globally. It is critical that you use the right tools to keep your digital life protected. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

REvil Ransomware Strikes US Nuclear Weapons Contractor

REvil Ransomware has struck again, this time at Sol Oriens, a subcontractor for the Department of Energy (DOE). Sol Oriens works on nuclear weapons with the National Nuclear Security Administration (NNSA). The REvil Ransomware attack occurred last month. The companies website has been unreachable since June 3rd, but Sol Oriens spokespeople confirmed to Fox News and CNBC that they became aware of the REvil Ransomware infection a month ago. The REvil Ransomware operators said of the attack, “We hereby keep a right to forward all of the relevant documentation and data to military agencies of our choice.”

The company said in a statement, “In May 2021, Sol Oriens became aware of a cybersecurity incident that impacted our network environment. The investigation is ongoing, but we recently determined that an unauthorized individual acquired certain documents from our systems. Those documents are currently under review, and we are working with a third-party technological forensic firm to determine the scope of potential data that may have been involved. We have no current indication that this incident involves client classified or critical security-related information. Once the investigation concludes, we are committed to notifying individuals and entities whose information is involved.”

Eamon Javers of CNBC noted, “we don’t know everything this small company does,” but he posted a sample job posting that indicates that it handles nuclear weapons issues: “Senior Nuclear Weapon System Subject Matter. Expert with more than 20 years of experience with nuclear weapons like the W80-4.” The W80 is a type of nuclear warhead carried on air-launched cruise missiles.

According to an archived version of the companys’ LinkedIn profile, Sol Oriens is a “small, veteran-owned consulting firm focused on managing advanced technologies and concepts with strong potential for military and space applications” that works with the “Department of Defense and Department of Energy Organizations, Aerospace Contractors, and Technology Firms (sic) carry out complex programs. We focus on ensuring that there are well-developed technologies available to maintain a strong National Defense.”

Brett Callow, a threat analyst and ransomware expert at the security firm Emsisoft, told Mother Jones that he had spotted Sol Oriens’s internal information posted to the REvil Ransomware’s dark web blog.

According to Callow, the leaked information so far seems relatively benign. Callow described the data as, “a company payroll form from September 2020, outing a handful of employees’ names, social security numbers, and quarterly pay. There’s also a company contracts ledger, and a portion of a memo outlining worker training plans.”

It remains to be seen if the REvil Ransomware gang has got its hands on more sensitive information. Regardless, the attack is concerning for many, given that a company working with nuclear armaments was able to be breached from the outside. As Mother Jones pointed out, the NNSA is responsible for maintaining and securing the nation’s nuclear weapons stockpile and works on nuclear applications for the military, along with other highly sensitive missions.

The REvil Ransomware gang blamed the victim in the attack, stating Sol Oriens “did not take all necessary action to protect personal data of their employees and software development for partner companies.”

REvil Ransomware Analysis

REvil Ransomware is a Ransomware-as-a-Service (RaaS), meaning it can be sold on a subscription basis and is usable by just about anybody. In 2020, it extorted large amounts of money for corporations and individuals. According to researchers, it is the most widespread ransomware strain. Groups using have a knack for shaking down businesses that don’t meet their demands, often through threats or leaking dating.

REvil Ransomware, also known as Sodinokibi, first appeared in April 2019 and rose to prominence after another RaaS gang called GandCrab shut down its service. REvil was first advertised on Russian-language cybercrime forums. The main actor associated with advertising and promoting REvil ransomware is called Unknown aka UNKN.  In the early days of REvil, researchers and security firms identified it as a strain of GandCrab, or at least established multiple links between the two. An alleged member of the group, using the handle Unknown, confirmed in an interview that the ransomware was not a new creation and that it was built on top of an older codebase that the group acquired.

The group behind REvil Ransomware and other groups selling RaaS often do so on a commission basis. Usually, this means a cut of between 20% and 30% of the money earned through infecting victims with ransomware.

In 2020, the IBM Security X-Force Incident Response reported that 1 in 3 Ransomware infections were caused by REvil Ransomware.

In February 2021, the REvil ransomware operation posted a job notice where they were looking to recruit people to perform DDoS attacks and use VOIP calls to contact victims and their partners.

In March, a security researcher known as 3xp0rt discovered that REvil has announced that they were introducing new tactics that affiliates can use to exert even more pressure on victims.

These new tactics include a free service where the threat actors, or affiliated partners, will perform voice-scrambled VOIP calls to the media and victim’s business partners with information about the attack. The ransomware gang is likely assuming that warning businesses that their data may have been exposed in an attack on of their partners, will create further pressure for the victim to pay.

REvil Ransomware is also providing a paid service that allows affiliates to perform Layer 3 and Layer 7 DDoS attacks against a company for maximum pressure. A Layer 3 attack is commonly used to take down the company’s Internet connection. In contrast, threat actors would use a Layer 7 attack to take down a publicly accessible application, such as a web server.

It is highly configurable, and it can be customized to behave differently depending on the host. This makes it a highly attractive RaaS client. Some of its features include:

  • Exploits a kernel privilege escalation vulnerability to gain SYSTEM privileges using CVE-2018-8453.
  • Whitelists files, folders and extensions from encryption.
  • Kills specific processes and services prior to encryption.
  • Encrypts files on local and network storage.
  • Customizes the name and body of the ransom note, and the contents of the background image.
  • Exfiltrates encrypted information on the infected host to remote controllers.
  • REvil Ransomware uses Hypertext Transfer Protocol Secure (HTTPS) for communication with its controllers.

REvil ransomware exploits a kernel privilege escalation vulnerability in win32k.sys tracked as CVE-2018-8453 to gain SYSTEM privileges on the infected host. If the configuration instructs a sample to execute this exploit, it will allocate executable memory, decrypt the exploit code in the newly allocated region and invoke it.

Protection Against Ransomware

REvil Ransomware and other Ransomware clients are some of the most common and deadly cybersecurity threats out there today. Families and businesses should be aware of these threats, and equip the right tools to tackle them. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

Prometheus Ransomware Emerges and Targets Businesses Globally

Prometheus Ransomware is an emerging threat in the malware scene, and it has breached 30 business organizations in just four months since it went operational. The strain is somewhat riding on the coattails of another notorious ransomware syndicate, REvil. Prometheus Ransomware was first spotted in the wild in February 2021, and researchers quickly deduced it was a rebuild of another infamous strain named Thanos. Thanos had previously seen action when deployed against government organizations in Africa and the Middle East last year.

The targets of Prometheus Ransomware are varied, and they include government, financial services, manufacturing, logistics, consulting, agriculture, healthcare services, insurance agencies, energy and law firms in the U.S., U.K., and a dozen more countries in Asia, Europe, the Middle East, and South America. These attacks have been tracked and reported by Palo Alto Networks’ Unit 42 threat intelligence team.

Like many ransomware operations, Prometheus Ransomware carries out double-extortion tactics on its victims, where it names new victims and leaks data from a Dark Web site. This is often done to put pressure on the target to pay the ransom.

“Prometheus runs like a professional enterprise,” Doel Santos, Unit 42 threat intelligence analyst, said. “It refers to its victims as ‘customers,’ communicates with them using a customer service ticketing system that warns them when payment deadlines are approaching and even uses a clock to count down the hours, minutes and seconds to a payment deadline.”

Unit 42 discovered just 4 of the 30 affected organizations opted to pay the ransom to date. These include a Peruvian agricultural company, a Brazilian healthcare services provider, and two transportation and logistics organizations in Austria and Singapore.

Manufacturing was the most impacted industry among the victim organizations observed by researchers, closely followed by the transportation and logistics industry.

Prometheus Ransomware has strong links to Thanos, yet the gang claims to be a “group of REvil.” The REvil gang is one of the most infamous ransomware-as-a-service (RaaS) cartels in recent years. Researchers are speculating that this could be an attempt to deflect attention from Thanos or a deliberate ploy to trick victims into paying up by piggybacking on an established operation.

Prometheus Ransomware attack vector is unclear currently, though it is expected the gang targets networks by using spear-phishing attacks. Following a successful compromise, the Prometheus modus operandi involves terminating backup and security software-related processes on the system to lock the files behind encryption barriers.

“The Prometheus ransomware operators generate a unique payload per victim, which is used for their negotiation site to recover files,” Santos said, adding the ransom demand ranges anywhere between $6,000 and $100,000 depending on the victim organization, a price that gets doubled if the victim fails to pay up within the designated time period.

Prometheus Ransomware Analysis

Note: This analysis was carried out by Doel Santos of Unit 42.

When Prometheus ransomware is executed, it tries to kill several backups and security software-related processes, such as Raccine, a ransomware prevention tool that tries to stop ransomware from deleting shadow copies in Windows.

Prometheus ransomware appends an extension using the following format .[XXX-XXX-XXXX]. Unit 42 found that the extensions are hardcoded into the sample. They believe that the Prometheus ransomware operators generate a unique payload per victim, which is used for their negotiation site to recover files. Researchers obfuscated the extensions because they could be used to identify the victims on the leak site. Prometheus also adds an hexadecimal string of GotAllDone at the end of all encrypted files.

After the backup and security processes are terminated and encryption is complete, Prometheus ransomware drops two ransom notes: a RESTORE_FILES_INFO.TXT file and a RESTORE_FILES_INFO.TXT.hta file , both containing the same information.

The ransom note also includes instructions for contacting Prometheus ransomware operators to recover files, as well as informing the victim that, if the demands are not met, the threat actors will release the data to the public or sell it to a third party.

Since the extensions are used as a victim identifier, by following the instructions on the ransom note, we were able to take a look at the negotiation part of their site using the extensions ID to gain access. Interestingly, this group uses a ticketing system for tracking victims. The tickets include a tracking ID, created date, resolution status and priority. A victim can even open a ticket with the threat actors to request data recovery – though this will cost you extra, according to the site.

The Prometheus ransomware operators include a status per victim. Unit 42 found that some of the information posted on the leak site has already been sold to an unknown third party. There are also posts showing that victims within impacted industries paid the ransom and their data was removed from the site.

Protection

Malware is an ever-present threat for governments, businesses, and homes. It is important to also have the tools necessary for protection against threats at any level. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

Canada Post Suffers Data Breach As Supplier Ensnared By Lorenz Ransomware

Lorenz Ransomware has claimed its latest victim – a third-party supplier to Canada Post, which resulted in a sizeable data breach for the postal service. Last week, Canada Post informed 44 of its largest customers that the Lorenz Ransomware attack on a third-party service supplier took place, which exposed shipping information belonging to their customers. Canada Post is the primary postal operator in Canada, and serves 16.5 Million residential and business addresses.

The data exposed in the attack includes manifest information for large parcel business customers, which is made up of send and receiver contact information, names, and mailing addresses.

In total, the breach affected 44 Canada Post commercial customers and 950,000 receiving customers.

“After a detailed forensic investigation, there is no evidence that any financial information was breached. In all, the impacted shipping manifests for the 44 commercial customers contained information relating to just over 950 thousand receiving customers. After a thorough review of the shipping manifest files, we’ve determined the following:

  • The information is from July 2016 to March 2019
  • The vast majority (97%) contained the name and address of the receiving customer
  • The remainder (3%) contained an email address and/or phone number”

In December 2020, Lorenz Ransomware posted on their Dark Web leak site that they had successfully breached Commport Communications. Since that date, the Lorenz Ransomware gang has leaked over 35GB of data stolen in the attack.

Screen Capture from Lorenz Ransomware Data Leak Site

While Canada Post states that at the time of the attack, Commport did not believe that any of their data was accessed, based on the leaked data, it appears that this was not the case. Canada Post states that they have hired external cybersecurity experts to assist in the investigation and have notified the Office of the Privacy Commissioner of Canada.

Lorenz Ransomware first appeared in December. It targets organizations around the world with customized attacks, showing that the operators behind the malware are skilled individuals.

According to cybersecurity researcher Michael Gillespie, Lorenz Ransomware shares much of the same code as the ThunderCrypt Ransomware operation. It is believed that Lorenz Ransomware is perhaps a reworking of ThunderCrypt.

Like other ransomware attacks, Lorenz Ransomware breaches a network and spreads laterally to other devices until it gains access to Windows domain administrator credentials.

Lorenz Ransomware Analysis

Note: The following is an analysis of ThunderCrypt, carried out by TrendMicro. Though there are some differences between ThunderCrypt and Lorenz, the core of the malware as shown below is the same.

Generally, Lorenz Ransomware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

It adds the following processes:

It adds the following mutexes to ensure that only one of its copies runs at any one time:

  • {Organization Name}

Lorenz Ransomware registers as a system service to ensure its automatic execution at every system startup by adding the following registry keys:

Lorenz Ransomware Additional Registry Keys

 

Lorenz Ransomware then carries out the following:

  • It only proceeds to its encryption routine if its filename is MoUsoCoreWorker program.
  • It encrypts FIXED, REMOVABLE, and NETWORK Drives.
  • It appends the extension .sz40 to the file that it is currently encrypting and will rename the file back to its original filename without the appended extension after the encryption has finished.
  • It uses SpVoice Interface functionality to play the following message:
    • You’ve been hacked! Your files are stolen and encrypted. Follow our instructions!
  • It creates a one-time remote scheduled task to execute its copy.
  • It sends the information it gathers to the following URL:
    • {BLOCKED}.{BLOCKED}.251.27:55
  • Task Name: voise
    Trigger: Daily
    Task Action: %Windows%\tWjdf.js
  • Task Name: sz40
    Trigger: ONLOGON
    Task Action: \{Domain}.net\NETLOGON\sinhost.e x e

Lorenz Ransomware avoids encrypting files found in the following folders:

  • $Recycle.Bin
  • All Users
  • Local
  • Microsoft
  • Packages
  • Program Files
  • Program Files (x86)
  • ProgramData
  • Temp
  • WINDOWS
  • Windows

It drops the following file(s) as ransom note:

  • %Desktop%\HELP_SECURITY_EVENT.html
  • %Desktop%\{Encrypted Directory}\HELP_SECURITY_EVENT.html
Lorenz Ransomware Note

Protection

Ransomware is a crowded scene, with new threats rising and falling almost every day. It is important that business owners and families have the best tools for the job when it comes to protecting their devices. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.