57
57
57
57
57
57
Threat Brief: Maze Ransomware
Unit 42 issued a threat brief on Maze ransomware, noting an uptick across industries and exploitation of Pulse VPN and IE flaws for initial access.
Palo Alto Networks detected an uptick in Maze ransomware samples across finance, healthcare, government, and other sectors. Maze, a variant of ChaCha ransomware first seen in May 2019, is distributed via weaponized Word/Excel attachments and the Spelevo exploit kit leveraging CVE-2018-15982 and CVE-2018-4878, and has used CVE-2019-11510 (Pulse VPN) and CVE-2018-8174 (Internet Explorer). Operators establish a foothold, escalate privileges, move laterally, and exfiltrate files before encryption for extortion leverage.
55
57
57
57
57
57
57
57
57
57
57
57
57
CSC 3D Domain Monitoring enables enterprises to identify suspicious domains created by third parties
57
57
57
Fog ransomware attack on Asia financial org draws attention over use of employee monitoring software
57
57
57
57
57
57
57
60
57
57
57
57
57
57
57
57
57
57