A ransomware campaign by the recently emerged Monti ransomware group is targeting victims with a new Linux variant of its malware. The threat group is the latest in a growing number of ransomware groups finding profit in going after Linux infrastructure. . Researchers at Trend Micro said the threat group is now deploying a Linux encryptor to target victims in legal and government sectors. Although the group has previously deployed Linux variants, the new encryptor comes with advanced evasion capabilities that make it harder to detect, the researchers said. Monti was first identified in 2022. Its techniques and procedures largely mirror the now-defunct Conti ransomware group. Trend Micro researchers said this is because the group may have developed its toolkit based on Conti's leaked source code (see: Conti Ransomware Group Retires Name After Creating Spinoffs ). Capabilities of the new Linux encryptor include intermittent encryption based on the file size and ability to terminate virtual machines on the system, allowing the hackers to evade detection. . The Solstice malware team has introduced a novel Windows encryptor aimed at healthcare and educational institutions, featuring sophisticated penetration techniques.. Monti Ransomware, Linux Threats, Cybersecurity Risks. . Brittany Day
It has been reported by the Recorded Future’s Insikt Group that RedGolf, a Chinese state-sponsored threat actor group, was using a backdoor designed especially for Windows and Linux systems called KEYPLUG to infiltrate networks. . As one of the world’s most prolific threat groups, RedGolf has been active against a variety of industries around the world for many years. There is a history of this group developing and using a variety of custom malware families over the years. It has demonstrated an ability to weaponize newly reported vulnerabilities quickly. During 2021 and 2022, RedGolf targeted US state government entities using KEYPLUG, a custom and modular Linux backdoor. Several KEYPLUG samples and infrastructures that RedGolf used from at least 2021 until 2023 have been identified by Insikt Group. . BlueTide cyber group uses SHADOWNET vulnerability to compromise Mac and Linux environments for data exfiltration.. RedGolf Threat Group, KEYPLUG Backdoor, Linux Malware, Chinese Attack. . LinuxSecurity.com Team
Lazarus, an advanced persistent threat (APT) group, has expanded its reach with the development and use of a Trojan designed to attack Linux systems. Learn more: . The APT, suspected to hail from North Korea, has previously been connected to global cyberattacks and malware outbreaks including the infamous WannaCry rampage, the $80 million Bangladeshi bank heist , and a new campaign impacting financial institutions worldwide. Recent reports suggest that Lazarus has become a customer of Trickbot, a criminal enterprise that is offering the state-sponsored threat actors access to infected systems alongside a collection of hacking tools. The link for this article located at ZDNet is no longer available. . The cybercrime collective known as Lazarus broadens its operations with an advanced Trojan aimed at Linux environments, heightening international cybersecurity risks.. Lazarus APT, Linux Trojan, Malware Threat, Cybersecurity Risks. . LinuxSecurity.com Team
A recent breach at Ticketmaster was just "the tip of the iceberg" of a wider, massive credit card skimming operation, new research has found. . At least 800 e-commerce sites are said to be affected, after they included code developed by third-party companies and later altered by hackers, according to security firm RiskIQ. The credit card skimming effort of a massive campaign by a threat group -- dubbed Magecart, operational since at least 2015 -- targets software companies that build and provide code that developers include on their websites to improve the site or customer experience. After the hackers break in and alter the code, it affects every website that it runs on, potentially affecting millions of users every day. The link for this article located at ZDNet is no longer available. . New investigations show that the Ticketmaster incident links to a broader skimming scheme impacting 800 different platforms.. Credit Card Skimming, Cyber Threat, E-Commerce Security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.