ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

Double-Encrypting Ransomware

highRansomwareimportance 57
Full article143 words · extracted from schneier.com · click to collapse

This seems to be a new tactic:

Emsisoft has identified two distinct tactics. In the first, hackers encrypt data with ransomware A and then re-encrypt that data with ransomware B. The other path involves what Emsisoft calls a “side-by-side encryption” attack, in which attacks encrypt some of an organization’s systems with ransomware A and others with ransomware B. In that case, data is only encrypted once, but a victim would need both decryption keys to unlock everything. The researchers also note that in this side-by-side scenario, attackers take steps to make the two distinct strains of ransomware look as similar as possible, so it’s more difficult for incident responders to sort out what’s going on.

Tags: encryption, extortion, malware, ransomware

Posted on May 21, 2021 at 8:50 AM53 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2021/05/double-encrypting-ransomware.html