Breaking Kenya News Forum

Topics

3AM Ransomware Gang Hacking

While the ransomware attack itself was largely thwarted by the targeted organization’s Sophos network defenses (despite the attackers’ attempts to disable MFA and endpoint protection itself), these cases stress the need for proactive cybersecurity measures. A recent campaign by 3AM ransomware actors found the team using more proactive techniques rather than simple opportunistic hacks by pretending to be IT support. Using a combination of email bombing and spoof IT support calls, unwitting employees dropped their guards, giving the attackers access to their terminals (and thus, corporate systems). From there, the actors were free to deploy whatever nefarious payload they desired.The true innovation in this attack, however, lay in what the attackers deployed next: a pre-configured Windows 7 virtual machine, launched via the Qemu emulator, directly onto the compromised computer. This virtual machine, running a QDoor trojan, served as a hidden foothold, allowing the attackers to establish command and control while largely evading network protection software. Are the network hackers evolving very quickly ?

Leave a Reply

Your email address will not be published. Required fields are marked *.

You may use these <abbr title="HyperText Markup Language">HTML</abbr> tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>