December 3, 2021

FBI releases flash alert against the Cuba ransomware gang

On Thursday 2nd of December 2021, the United States Federal Bureau of Investigation (FBI) released a joint TLP:WHITE flash alert which revealed the Cuba ransomware gang have compromised at least 49 organizations in five critical infrastructure sectors, including the financial, government, healthcare, manufacturing, and information technology sectors. The FBI also revealed that the Cuba ransomware variant is commonly distributed through […]
November 30, 2021

Australian government-owned energy company, CS Energy confirms they were a target of a ransomware attack

On Tuesday 30th of November 2021, CS Energy, an Australian government-owned energy generator in the Queensland confirmed they had suffered a ransomware attack on Saturday, 27th of November 2021 which occurred on their corporate network but did not impact the electricity generation at either of their power stations in Callide and Kogan Creek. CS Energy CEO Andrew Bills stated they were […]
November 30, 2021

FBI name known affiliate of REvil ransomware gang in court documents that revealed they had seized $2.3 million in Bitcoins

On Tuesday 30th of November 2021, the FBI revealed they had seized $2.3 million in Bitcoins on August 3rd, 2021, from a well-known REvil and GandCrab ransomware affiliate Aleksandr Sikerin, in a “complaint for forfeiture” court documents that were filed. The FBI didn’t disclose how they had gained access to the Exodus wallet where the 39.89138522 Bitcoins were originally being […]
November 25, 2021

Singapore offshore vessel operator, Swire Pacific Offshore experiences ransomware attack by CL0P ransomware group

On Thursday 25th of November 2021, Swire Pacific Offshore (SPO), a Singapore offshore vessel operator confirmed they had suffered a cyber-attack might have resulted in the loss of confidential proprietary commercial information and personal information. They have not disclosed any specifics of the attack but the ransomware group, CL0P have released a listing on their leak blog where they have claimed […]
November 24, 2021

The National Privacy Commission in the Philippines announces that S&R Membership Shopping suffered a ransomware attack

On Wednesday 24th of November 2021, S&R Membership Shopping, a membership-only retail warehouse club chain in the Philippines announced they had suffered a ransomware attack which resulted in data being compromised. The announcement was made via the National Privacy Commission in the Philippines when the Commission was informed of the extent of the compromised data. The National Privacy Commission revealed they […]
November 24, 2021

Lewis & Clark Community College Campuses in Illinois shutdown due to ransomware attack

On Wednesday 24th of November 2021, Lewis and Clark Community College, a public community college in Godfrey, Illinois announced that they had experienced a ransomware attack late on Tuesday 23rd which resulted in all of Lewis and Clark campuses having to be shut down on Wednesday 24th to prevent further spreading of the ransomware. The announcement came in the form of […]
November 22, 2021

Joint advisory released by FBI and CISA in preparation for the upcoming holiday season

On Monday 22nd of November 2021, Federal Bureau of Investigation (FBI), and the Cybersecurity and Infrastructure Security Agency (CISA), released a joint cybersecurity advisory where they warned of upcoming spikes in cyberattacks as the holiday season approaches. The advisory was aimed at all organisations although it had a heavy emphasis on critical networks, systems and infrastructure. The CISA and FBI also emphasised a caution […]
November 17, 2021

US releases joint advisory warning companies of Iranian APT group that has been involved in ransomware attacks

On Wednesday 17th of November 2021, Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Australian Cyber Security Centre (ACSC), and the United Kingdom’s National Cyber Security Centre (NCSC) released a joint cybersecurity advisory where they warned of ongoing malicious cyber activity that FBI, CISA, ACSC, and NCSC have observed and associated with an advanced persistent threat (APT) group that is […]
November 15, 2021

Cyber security research groups observe signs of Emotet malware returning and rebuilding its botnet via TrickBot

On Monday 15th of November 2021, Emotet research groups Cryptolaemus, GData, and Advanced Intel started to observe the TrickBot malware dropping a loader for Emotet on infected devices. The Emotet malware was considered the most widely spread malware in the past although at the start of the year, it was taken down by an international law enforcement action coordinated by Europol […]