Posts

Showing posts with the label Worm

Raspberry Robin: A global USB malware campaign providing access to ransomware operators

Image
Logo credit: RedCanary Ever since it first appeared in late 2021, the Raspberry Robin malware campaign has been propagating globally. A number of threat intelligence reports by vendors such as RedCanary (who named it) and Microsoft (who track it as DEV-0856/Storm-0856) have covered the malware campaign in great detail.  In fact, the list of blogs I do recommend to read to catch up on this threat are as follows: https://redcanary.com/blog/raspberry-robin https://www.microsoft.com/en-us/security/blog/2022/10/27/raspberry-robin-worm-part-of-larger-ecosystem-facilitating-pre-ransomware-activity https://blog.sekoia.io/raspberry-robins-botnet-second-life/ https://decoded.avast.io/janvojtesek/raspberry-robins-roshtyak-a-little-lesson-in-trickery/ https://research.checkpoint.com/2023/raspberry-robin-anti-evasion-how-to-exploit-analysis/ https://securityintelligence.com/posts/raspberry-robin-worm-dridex-malware/ https://blogs.cisco.com/security/raspberry-robin-highly-evasive-worm-sprea...

MyDoom persists into 2020

Image
MyDoom still holds the world record for fastest-spreading email worm of all time. It was first discovered in January 2004 and remains active today in 2020. Few threats possess the effectiveness and longevity of MyDoom. MyDoom is also cited as the world’s most costly cyber attack in history. The malware has caused an estimated $38 billion (£31bn) in damage over its lifespan. The initial version of MyDoom was programmed to launch a distributed denial-of-service (DDoS) attack against a site for the SCO Group, which had filed an intellectual property suit against IBM over its alleged use of Linux code. The attack was programmed to launch 1 February, 2004 and end 12 February, sending a request to the website every millisecond. After the worm ended its DDoS attacks, the backdoor left by the worm would still be active. It meant future malware and threat actors can manipulate the infected machines that were never cleaned.  The authors of the initial worm were never found or...