Threat Advisory

Ransomware and wiper signed with stolen certificates

Threat: Ransomware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Recently a massive cyberattack had affected Albanian goverment e-service. According to researchers these cyberattacks were part of coordinated operation to bring the country's computer systems to a halt. After few months same threat attacker was using same attack type to target Albania's TIMS (Text Information Management System), ADAM (Automatic Document Analysis and Management), and MEMEX (Memory Extended) systems. Researchers identified the ransomware and wiper samples signed with Nvidia’s leaked code certificate to sign the malware. Malware samples are seen to be resembling those used in first attack which allowed evasion of security controls and better attack speeds.[/subscribe_to_unlock_form]

Summary:

Recently a massive cyberattack had affected Albanian goverment e-service. According to researchers these cyberattacks were part of coordinated operation to bring the country's computer systems to a halt. After few months same threat attacker was using same attack type to target Albania's TIMS (Text Information Management System), ADAM (Automatic Document Analysis and Management), and MEMEX (Memory Extended) systems. Researchers identified the ransomware and wiper samples signed with Nvidia’s leaked code certificate to sign the malware. Malware samples are seen to be resembling those used in first attack which allowed evasion of security controls and better attack speeds.[emaillocker id="1283"]

Threat Profile:

References:

The following reports contain further technical details:

https://securelist.com/ransomware-and-wiper-signed-with-stolen-certificates/108350/

[/emaillocker]
crossmenu