Gruppo ECP Advpress Automationtoday AI DevwWrld CyberDSA Chatbot Summit Cyber Revolution Summit CYSEC Global Cyber Security & Cloud Expo World Series Digital Identity & Authentication Summit Asian Integrated Resort Expo Middle East Low Code No Code Summit TimeAI Summit Gruppo ECP Advpress Automationtoday AI DevwWrld CyberDSA Chatbot Summit Cyber Revolution Summit CYSEC Global Cyber Security & Cloud Expo World Series Digital Identity & Authentication Summit Asian Integrated Resort Expo Middle East Low Code No Code Summit TimeAI Summit

Cyclops ransomware: new threats emerge with data theft capabilities

A sophisticated cybercrime strategy carries out cross-platform attacks, affecting Windows, macOS and Linux with theft of sensitive data

This pill is also available in Italian language

Threats related to Cyclops ransomware have been observed offering malware designed to capture sensitive data from infected hosts. The notorious ransomware is notable for its ability to target all major desktop operating systems, including Windows, macOS, and Linux. It is also designed to terminate any potential processes that could interfere with encryption.

Promotion on the dark web and technical details

The threat actor promotes its offer on various forums, Uptycs said in a new report. In these digital spaces, it demands a share of the profits from those who engage in malicious activity using its malware. The macOS and Linux versions of Cyclops ransomware are written in Golang. The ransomware also uses a complex encryption scheme that combines asymmetric and symmetric encryption.

Targets: Windows, Linux and data theft

The Go-based stealer is designed to target Windows and Linux systems, capturing details such as operating system information, computer name, number of processes and files of interest that match specific extensions. The collected data, which includes .TXT, .DOC, .XLS, .PDF, .JPEG, .JPG and .PNG files, is then uploaded to a remote server. The stealer component can be accessed from an admin panel to the client.

The evolution of threats: dot net stealers

This development emerges simultaneously with SonicWall detailing a new malware variant called the Dot Net Stealer, designed to steal information from web browsers, VPNs, installed applications and cryptocurrency wallets. This represents a further evolution of the cybercrime ecosystem into an even more lethal threat. "These capabilities allow attackers to obtain valuable information from victims' systems that can lead to major financial fraud, causing huge financial losses for the victims," SonicWall said.

Follow us on Facebook for more pills like this

06/06/2023 08:06

Marco Verro

Last pills

Cloudflare repels the most powerful DDoS attack ever recordedAdvanced defense and global collaboration to tackle new challenges of DDoS attacks

Silent threats: the zero-click flaw that compromises RDP serversHidden risks in remote work: how to protect RDP servers from invisible attacks

Discovery of vulnerability in Secure Boot threatens device securityFlaw in the Secure Boot system requires urgent updates to prevent invisible intrusions

North korean cyberattacks and laptop farming: threats to smart workingAdapting to new digital threats of remote work to protect vital data and infrastructures

Don’t miss the most important news
Enable notifications to stay always updated