Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
•
Sichere ProgrammierungVisual Studio Code 1.141 (Insiders)(07.10.2026 um 19:00 Uhr)
•
Linux Tipps & Hardening[$] Comparing Chromium development at Google and Igalia(30.09.2026 um 16:16 Uhr)
•
Sichere ProgrammierungReports from the 2026 Python Language Summit(30.09.2026 um 16:32 Uhr)
•
KI & AI VideosJulian Goldie SEO: NEW LongCat Preview Just Dropped! 🔥(30.09.2026 um 16:00 Uhr)
•
Linux Tipps & HardeningA unified OS installer in systemd (asg2026)(30.09.2026 um 00:00 Uhr)
•
Windows Tipps & SecurityContainers without a new runtime: sdme on systemd-nspawn (asg2026)(30.09.2026 um 00:00 Uhr)
•
Linux Tipps & Hardeningsingle-file containers with statically linked systemd (asg2026)(30.09.2026 um 00:00 Uhr)
•
Linux Tipps & HardeningForget "podman generate systemd": How Quadlet Really Works (asg2026)(30.09.2026 um 00:00 Uhr)
•
IT Security VideoLiveOverflow: Why Old Threat Models Are Dead #shorts(30.09.2026 um 15:55 Uhr)
••
Sichere ProgrammierungVisual Studio Code 1.141 (Insiders)(07.10.2026 um 19:00 Uhr)
•
Linux Tipps & Hardening[$] Comparing Chromium development at Google and Igalia(30.09.2026 um 16:16 Uhr)
•
Sichere ProgrammierungReports from the 2026 Python Language Summit(30.09.2026 um 16:32 Uhr)
•
KI & AI VideosJulian Goldie SEO: NEW LongCat Preview Just Dropped! 🔥(30.09.2026 um 16:00 Uhr)
•
Linux Tipps & HardeningA unified OS installer in systemd (asg2026)(30.09.2026 um 00:00 Uhr)
•
Windows Tipps & SecurityContainers without a new runtime: sdme on systemd-nspawn (asg2026)(30.09.2026 um 00:00 Uhr)
•
Linux Tipps & Hardeningsingle-file containers with statically linked systemd (asg2026)(30.09.2026 um 00:00 Uhr)
•
Linux Tipps & HardeningForget "podman generate systemd": How Quadlet Really Works (asg2026)(30.09.2026 um 00:00 Uhr)
•
IT Security VideoLiveOverflow: Why Old Threat Models Are Dead #shorts(30.09.2026 um 15:55 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

Destructive KillDisk Malware Turns Into Ransomware

wiredmikey writes from a report via SecurityWeek: A recently discovered variant of the KillDisk malware encrypts files and holds them for ransom instead of deleting them. Since KillDisk has been used in attacks aimed at industrial control…

0
↗ Quelle (it.slashdot.org)
Reagiere als Erste:r — dein Feedback zählt!
wiredmikey writes from a report via SecurityWeek: A recently discovered variant of the KillDisk malware encrypts files and holds them for ransom instead of deleting them. Since KillDisk has been used in attacks aimed at industrial control systems (ICS), experts are concerned that threat actors may be bringing ransomware into the industrial domain. CyberX VP of research David Atch told SecurityWeek that the KillDisk variant they have analyzed is a well-written piece of ransomware, and victims are instructed to pay 222 bitcoins ($210,000) to recover their files, which experts believe suggests that the attackers are targeting "organizations with deep pockets." From the report: "The ransomware is designed to encrypt various types of files, including documents, databases, source code, disk images, emails and media files. Both local partitions and network folders are targeted. The contact email address provided to affected users is associated with Lelantos, a privacy-focused email provider only accessible through the Tor network. The Bitcoin address to which victims are told to send the ransom has so far not made any transactions. Atch pointed out that the same RSA public key is used for all samples, which means that a user who receives a decryptor will likely be able to decrypt files for all victims. According to CyberX, the malware requires elevated privileges and registers itself as a service. The threat terminates various processes, but it avoids critical system processes and ones associated with anti-malware applications, likely to avoid disrupting the system and triggering detection by security products."

Read more of this story at Slashdot.

2. Cyber Threat Intelligence & Forensik

CTI Threat Relationship Graph4 Knoten / 3 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
MITRE ATT&CK Matrix Navigator 14 Taktiken
1 belegte TechnikenLive-Mapping
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-82307 | Improper neutralization of special elements used in an SQL command ('SQL…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag