Cyberattackers explore a new method of cyber extortion

Share post:

Cybersecurity researchers from Cyderes and Stairwell have uncovered a new method of cyber extortion that could be effective for attackers even if victims do not pay a ransom.

The new extortion tactics allow attackers to carry out data destruction during attacks. This is considered a dangerous development for ransomware victims because while it is often possible to retrieve encrypted files without paying ransom, the possibility that servers could be completely corrupted, if extortion demands are not met, could cause the victims to pay ransom.

The tactic of data destruction was discovered when researchers carried out an incident response to a ransomware attack by BlackCat. They linked the data destruction to Exmatter, a .NET exfiltration tool that was previously used as part of the BlackCat ransomware.

The researchers explained that the data destruction capabilities are still in development for several reasons, including the fact that there is no mechanism for removing files from the corruption queue. Also, the feature used by the Eraser class, called Erase, does not appear to be fully implemented and does not decompile correctly.

The sources for this piece include an article in ZDNet.

SUBSCRIBE NOW

Related articles

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Security vendor CrowdStrike issues an update from their initial Post Incident Review

Security vendor CrowdStrike released an update from their initial Post Incident Review (PIR) today. The company's CEO has...

CrowdStrike CEO summoned by Homeland Security committee over software disaster

CrowdStrike CEO George Kurtz has been called to testify before the U.S. House Committee on Homeland Security following...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways