—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Author: admin
On Cell Phone Metadata
Interesting Twitter thread on how cell phone metadata can be used to identify and track people who don’t want to be identified and tracked.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
The Ultimate Holiday Shopping Guide: Secure Gadgets for Everyone
The holidays are almost here! That means it’s time to start making your list and checking it twice. To help prepare you for this year’s holiday shopping spree, McAfee is providing you with the ultimate holiday shopping list for every Tech lover in your family. Here are the devices to keep on your radar this holiday shopping season and what you should use to protect them.
For the Gaming Guru
Know someone who enjoys vanquishing aliens, building virtual amusement parks, and online battle royale? There’s a good chance that you do, as online gaming traffic increased 30% from the first to the second quarter of 2020. For the gaming guru in your life, consider gifting them a top-of-the-line gaming laptop so, they don’t have to compromise portability for playability. If they prefer to play in the comfort of their own home, consider giving the gamer in your life a snazzy new gaming monitor. This will allow them to enjoy a crystal-clear resolution, rapid refresh rate, and size to bring their virtual world to life. And to truly immerse your gamer in a new realm, gift them a new gaming console so they can enjoy optimal speed and stellar game lineups.
When shopping for your gamer, consider how you can empower them to stay secure while they play. A security solution like McAfee Gamer Security not only delivers a faster, quieter, and safer experience, but it can also boost a rig’s performance. This antivirus software detects threats through the cloud and optimizes resources to minimize frame drops. Gamers can even customize which games to boost (or even add other apps they’d like to boost), which background services to pause, and more. This improves your gamer’s experience and also keeps them safe while they play.
For the Mobile Mastermind
Does your tech-savvy teen love to browse on the go? Or perhaps you have a college student who likes to bring their online studying and video streaming with them beyond the home. For the mobile mastermind in your family, gift them a new smartphone or tablet this holiday season. These devices will allow your loved ones to access all their favorite apps and surf the web anytime, anywhere.
With the World Wide Web constantly at their fingertips, enable your family members to surf the internet with confidence by employing the help of a safe browsing solution like McAfee WebAdvisor. This trusty companion, available for free and included in the McAfee Total Protection app for iOS and Android, helps keep users safe from threats like malware and phishing attempts. Web Advisor blocks malicious sites, scans downloads, and alerts the user if a known threat is detected. With comprehensive security on their side, your mobile user will be free to search, stream, and download on the go.
For the Smart Home Supervisor
The number of smart households (households that contain connected technology and can interact with other IoT devices) in the U.S. is expected to grow to 77.05 million by 2025. That may not come as a surprise, since IoT devices have upped the convenience of tech users’ lives everywhere. Perhaps your spouse or parents love filling their home with the latest and greatest smart home gadgets. This holiday season, give them the gift of convenience with a smart TV, speaker, thermostat, kitchen appliances, a personal home assistant – the list of smart home devices goes on!
While these devices can provide greater efficiency to anyone’s life, it’s important to be aware of the potential risks that come with this level of interconnectivity. Many product designers treat security as an afterthought, rushing to get their smart devices to market and consequentially creating an easy access point for criminals to exploit. But fear not! A solution like McAfee Secure Home Platform can automatically secure connected devices through a router with McAfee protection. It can hide your IoT devices from hackers, giving you the confidence that you have a solid line of defense against online threats.
For the Fitness Fanatic
At the onset of the pandemic, people adjusted their workout routines to accommodate for gym closures and began to rely on other solutions to stay fit. In fact, many turned to IoT devices used for virtual fitness, including wearable fitness trackers and stationary machines equipped with digital interfaces. Sound like someone you know? Consider giving them a stylish new or upgraded smartwatch that allows them to track their daily step count, heart rate, and sleep patterns.
While these devices can be instrumental in tracking users’ activity levels, it’s important to remember that wearable gadgets collect valuable health and location data a criminal could exploit. To keep your fitness fanatic happy and healthy without sweating their security, encourage them to install software updates immediately. This will protect your loved one’s device from reported bugs, enhance functionality, and seal up any security loopholes.
Secure for the Holidays
As you plan your holiday shopping list this year, don’t forget about the gift that keeps on giving: the peace of mind that comes with having the right online security! With comprehensive solutions built to safeguard your loved one’s devices, personal data, and everything they do online, they can continue to live their digital lives with confidence.
The post The Ultimate Holiday Shopping Guide: Secure Gadgets for Everyone appeared first on McAfee Blogs.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Squid Game App or Mobile Malware in Disguise?
It’s safe to say that many Americans are obsessed with Squid Game. According to Business Insider, the Korean drama series has driven the newest engagers to a Netflix title of any Netflix series over the last three years. And while word-of-mouth buzz has played a big part in the show’s success, TV watchers aren’t the only ones taking note. Cybercriminals are also formulating ways to profit off the show’s popularity. According to the New York Post, a malicious app based on Squid Game was recently found on the Google Play Store, infecting users’ devices with malware.
Red Light: Joker Malware in Disguise
The app in question, called “Squid Game Wallpaper 4K HD,” was one of the 200 Squid Game-related apps on the Google Play Store. This particular app masqueraded as a place to download cool Squid Game backgrounds for Android devices. However, once a user downloaded the app, it infected their smartphone with a strain of Joker malware. Joker malware is a type of billing fraud malware that usually disguises itself as a messenger, photo editor, camera, or in this case, wallpaper apps.
You may wonder how an app like this even ends up on a legitimate app purchasing store. In order to bypass Google Play’s app review process, Joker malware hides its malicious payload during the review process. This means that when the app is published in the Google Play Store, there’s no sign of malware. It’s only when a user installs the app that the malware downloads the malicious payload. Once the malware successfully installs itself, it secretly signs the user up for premium subscriptions, intercepts all their SMS messages, and can upload all their contacts to the malware operators.
Green Light: Secure Your Device From Mobile Malware
The “Squid Game Wallpaper 4K HD” app received 5,000 downloads before it was removed from the Google Play Store. It’s likely that cybercriminals will continue to use the show’s popularity to exploit its fans and make a profit, whether that be through malicious apps disguised as a place where viewers can watch the show or fraudulent websites selling Squid Game merchandise. But fear not! There are steps you can take to help ensure that you steer clear of malware:
1. Avoid third-party app stores
Unlike Google Play and Apple’s App Store, which have measures in place to review and vet apps to help ensure that they are safe, third-party sites may not have that process in place. In fact, some third-party sites may intentionally host malicious apps as part of a broader scam. However, cybercriminals have found ways to work around Google and Apple’s review process (such as with “Squid Game Wallpaper 4K HD”), but the chances of downloading a safe app from these stores are far greater than anywhere else. Additionally, Google and Apple are quick to remove malicious apps once discovered.
2. Do your research before you download
Before you download a new app, do some quick research. Check out the developer. Have they published several other apps with many downloads and good reviews? A legit app typically has several reviews, whereas malicious apps may have only a handful of fake five-star reviews. Lastly, look for typos and grammatical errors in both the app description and screenshots. They could be a sign that a hacker slapped the app together and quickly deployed it.
3. Keep a close eye on your accounts
Certain types of malware strains operate stealthily behind the scenes, commandeering login credentials or banking information right under a user’s nose. Check your accounts every so often and if you notice any suspicious activity, report it and change your passwords. You can also use ID monitoring tools, which will notify you of uncharacteristic changes or actions.
4. Use a comprehensive security solution
Just like you secure your computers and laptops, it’s important to secure the minicomputer in your pocket—your smartphone! For the strongest protection, use comprehensive security software that shields your device from malware and risky websites, links, and files. With a few key steps, you can boost your confidence in the safety of your devices and personal information and enjoy your favorite binge-worthy shows to the fullest!
The post Squid Game App or Mobile Malware in Disguise? appeared first on McAfee Blogs.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
The ‘Groove’ Ransomware Gang Was a Hoax
A number of publications in September warned about the emergence of “Groove,” a new ransomware group that called on competing extortion gangs to unite in attacking U.S. government interests online. It now appears that Groove was all a big hoax designed to toy with security firms and journalists.
“An appeal to business brothers!” reads the Oct. 22 post from Groove calling for attacks on the United States government sector.
Groove was first announced Aug. 22 on RAMP, a new and fairly exclusive Russian-language darknet cybercrime forum.
“GROOVE is first and foremost an aggressive financially motivated criminal organization dealing in industrial espionage for about two years,” wrote RAMP’s administrator “Orange” in a post asking forum members to compete in a contest for designing a website for the new group. “Let’s make it clear that we don’t do anything without a reason, so at the end of the day, it’s us who will benefit most from this contest.”
According to a report published by McAfee, Orange launched RAMP to appeal to ransomware-related threat actors who were were ousted from major cybercrime forums for being too toxic, or to cybercriminals who complained of being short-changed or stiffed altogether by different ransomware affiliate programs.
The report said RAMP was the product of a dispute between members of the Babuk ransomware gang, and that its members likely had connections to another ransomware group called BlackMatter.
“[McAfee] believes, with high confidence, that the Groove gang is a former affiliate or subgroup of the Babuk gang, who are willing to collaborate with other parties, as long as there is financial gain for them,” the report said. “Thus, an affiliation with the BlackMatter gang is likely.”
In the first week of September, Groove posted on its darknet blog nearly 500,000 login credentials for customers of Fortinet VPN products, usernames and passwords that could be used to remotely connect to vulnerable systems. Fortinet said the credentials were collected from systems that hadn’t yet implemented a patch issued in May 2019.
Some security experts said the post of the Fortinet VPN usernames and passwords was aimed at drawing new affiliates to Groove. But it seems more likely the credentials were posted to garner the attention of security researchers and journalists.
Sometime in the last week, Groove’s darknet blog disappeared. In a post on the Russian cybercrime forum XSS, an established cybercrook using the handle “Boriselcin” explained that Groove was little more than a pet project to screw with the media and security industry.
“For those who don’t understand what’s going on: I set up a fake Groove Gang and named myself a gang,” Boriselcin wrote. The rest of the post reads:
“They ate it up, I dumped 500k old Fortinet [access credentials] that no one needed and they ate it up. I say that I am going to target the U.S. government sector and they eat it up. Few journalists realized that this was all a show, a fake, and a scam! And my respect goes out to those who figured it out. I don’t even know what to do now with this blog with a ton of traffic. Maybe sell it? Now I just need to start writing [the article], but I can’t start writing it without checking everything.”
A review of Boriselcin’s recent postings on XSS indicate he has been planning this scheme for several months. On Sept. 13, Boriselcin posted that “several topics are ripening,” and that he intended to publish an article about duping the media and security firms.
“Manipulation of large information security companies and the media through a ransom blog,” he wrote. “It’s so funny to read Twitter and the news these days
But the result is great so far. Triggering the directors of information security companies. We fuck the supply chain of the information security office.”
Image: @nokae8
Throughout its short existence, Groove listed only a handful of victims on its darknet victim shaming blog, leading some to conclude the group wasn’t much of a threat.
“I wouldn’t take this call too seriously,” tweeted The Record’s Catalin Cimpanu in response to tweets about Groove’s rallying cry to attack U.S. government interests. “Groove are low-tier actors with few skills.”
Normally, when a cybercriminal forum or enterprise turns out to be fake or a scam, we learn the whole thing was a sting operation by federal investigators from the United States and/or other countries. Perhaps the main reason we don’t see more scams like Boricelcin’s is because there’s not really any money in it.
But that’s not to say his cynical ploy fails to serve a larger purpose. Over the past few years, we’ve seen multiple ransomware gangs reinvent themselves and rebrand to evade prosecution or economic sanctions. From that vantage point, anything which sows confusion and diverts the media and security industry’s time and attention away from real threats is a net plus for the cybercriminal community.
Tom Hoffman, senior vice president of intelligence at Flashpoint, said mocking Western media outlets and reporters is a constant fixture of the conversation on top-tier cybercrime forums. ”
“It is clear the criminal actors read all the press releases and Twitter claims about them,” Hoffman said. “We know some of them just want to inflict pain on the West, so this type of trolling is likely to continue. With the high level of attention this one got, I would assume we will see some other copycats pretty soon.”
Cyber intelligence firm Intel471 said while it’s possible that a single actor concocted Groove as a way to troll security researchers and the media, they believe it’s more likely that the actor’s attempt to create their own ransomware group didn’t work out as they had planned.
“It’s also important to remember that the true identity and nature of any Ransomware-as-a-Service gang is not always clear and the membership makeup or affiliates of these gangs can be fluid,” Intel 471 wrote. “Despite that and based on our research from multiple sources, which includes but isn’t limited to observations of shared infrastructure and victimology, we believe “boriselcin” operated the Groove blog and the RAMP forum. This individual is a well-known member of the Russian-language cybercrime community with ties to a number of ransomware gangs and in August offered $1000 for someone to design a ransomware victim shaming blog for Groove. We are skeptical of the claims raised by the actor that Groove was an elaborate hoax from the beginning although we wouldn’t be surprised to see further claims by the actor claiming this in future.”
Update, 5:56 p.m. ET: Included perspective from Intel 471.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
#WebSummit2021: Facebook Whistleblower Denounces Meta Rebrand and Calls for Zuckerberg to Step Down
#WebSummit2021: Facebook Whistleblower Denounces Meta Rebrand and Calls for Zuckerberg to Step Down

Facebook prioritizes profits over user safety, according to whistleblower and former Facebook employee, Frances Haugen. She took to the stage at the opening ceremony of Web Summit – her first public address since leaking a collection of damaging Facebook documents – to denounce the social media company’s decisions and ethics.
The interview, led by Laurie Segall, founder and CEO of Dot Dot Media, delved into the motivation behind Haugen’s decision to leave Facebook and expose the social media company’s practices and priorities by leaking internal documents.
“I’m glad I had the opportunity to bring this to life as there has been a pattern of behavior where Facebook has consistently prioritized their profits over our safety,” said Haugen. “Facebook’s content algorithm amplifies the most extreme, polarizing and divisive content.”
Haugen compares this to the three social media companies she worked for prior to Facebook. “It became evident to me that things were substantially worse [at Facebook] than anything else I’d seen.” She suggests that this perhaps gave her the foundation of comparison and the confidence to speak out when other employees did not.
Facebook, Haugen said, tries to reduce the user’s choice down to a false choice: “They try to frame it as ‘do you want censorship?’ or ‘do you want free speech?’…Transparency or privacy. It’s a false choice.” However, she countered, “non content-based solutions exist and are effective to make Facebook safer. Bad people and bad ideas is not the problem, it’s the question of who gets the largest megaphone.”
“Facebook has consistently prioritized their profits over our safety”Haugen
Facebook is reliant on huge groups, with millions of members, “and it ties their hands with those groups because in order to get three pieces of content from that group each day, the algorithm has to work out which three pieces of content to put on your feeds.” Right now, she explains, the most extreme and polarizing content makes the cut.
“One of the things that Facebook has that is different than Twitter, is that at Twitter the branch that makes decisions about safe content and safety on the platform reports through a different chain to the chain that is responsible for making politicians happy. At Facebook, those organizations report to the same people.
Segall’s presented Haugen with Facebook’s accusation that she “cherry picked the documents, taken out of context, to paint a particularly negative picture of the social media giant. Haugen responded: “There is a really easy solution – I could just release more documents.”
“There are major tech companies, like Google and Twitter that are substantially more transparent than Facebook,” said Haugen. “They have a fire hose. But things that make it onto Facebook get caught by the Twitter fire hose, and that’s a red flag.”
Haugen refers to advice given to her by her mother: “Every human being deserves the dignity of knowing the truth. I truly believe that our society also deserves the truth, so we can make decisions for the public good.”
Haugen was also questioned on whether Mark Zuckerberg, Facebook’s CEO, should remain at the helm. “Facebook would be stronger with someone who was willing to focus on safety,” she considered. “I think it is unlikely the company will change if [Zuckerberg] remains the CEO.” Loud applause from the Web Summit audience of 40,000 rewarded this opinion.
Asked about her opinion on the social media company’s recent rebrand – last week Facebook announced it is changing its name to Meta to focus on building the “metaverse” – Haugen was both cynical and critical. “Instead of investing in making people safe, [Facebook] is investing that money in video games instead, and I can’t imagine how that makes sense.” The rebrand, she concluded, makes no sense given the security issues that are yet to be tackled.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
California Health Network Reports Data Breach
California Health Network Reports Data Breach

Cyber-criminals may have accessed the protected health information (PHI) of hundreds of thousands of patients of a network of community health centers based in California.
Nonprofit Community Medical Centers (CMC), which is headquartered in the city of Stockton, primarily serves low-income patients, migrants, and homeless people in the Northern California counties of San Joaquin, Solano, and Yolo.
In a statement issued on October 15, CMC said that “some unusual network activity” had been detected “early on Sunday, October 10.”
As a precaution, the agency shut down its entire network, including its servers, computers, and some phone lines that patients had been using to access their medical records, make appointments, and receive information relating to COVID-19.
“We know how hard this is on our patients,” said Preethi Raghu, chief operating officer at Community Medical Centers. “We are doing everything in our power to continue patient care and restore our systems.”
CMC launched an investigation into the unusual network activity with the help of third-party experts in cybersecurity. An examination of the digital forensic evidence determined that unauthorized individuals had gained access to parts of its network in which patients’ protected health information was stored.
Data that may have been obtained by the hackers includes medical information, first and last names, mailing addresses, dates of birth, demographic information and Social Security numbers.
A breach report filed with the Maine attorney general states that the protected health information of 656,047 individuals was potentially compromised in the incident, 8 of whom are Maine residents.
“Please understand that this situation is fluid, and we will continue to work with law enforcement and cybersecurity experts to assess the full scope and nature of the incident, as well as to fix the situation,” said CMC in a statement that was updated on October 27.
CMC did not say whether their investigation had discovered evidence of a ransomware attack.
Individuals affected by the security breach are being offered complimentary identity theft protection, identity theft resolution, and credit monitoring services.
“We continue to make progress on restoring all systems safely and returning to normal operations,” said CMC.
“We have also taken steps to improve our network security to further secure sensitive data and prevent any misuse of patient information.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Cyber-Incident at South Carolina School District
Cyber-Incident at South Carolina School District

A school district in South Carolina is investigating a “cyber-incident” that it says impacted hundreds of staff computers.
On October 4, some of the networks of Colleton County School District stopped operating. The unusual activity was detected by the district’s information technology staff, who determined that a cybersecurity incident had occurred.
Speaking at the time of the security event, Colleton County School District coordinator of communications Sean Gruber said that because “communication remains intact for the community at large,” student instruction had not been interrupted.
“The district IT staff immediately began investigation and recovery measures and contacted a professional Incident Response and Recovery team to assist,” said Gruber.
The precise nature of the incident has not been made public, but the district has said that no physical security measures in place at Colleton County schools were affected and that district facilities remain secure.
On Wednesday, the Colleton County School Board voted unanimously at a special meeting to spend nearly $200K on keeping three cybersecurity companies on the payroll to manage the district’s recovery from the incident.
The board said that approximately 800 computers used by teaching and administrative staff were involved in the incident, and that the services of a network engineer and a forensics engineer were required to sanitize the machines.
Dell Support Services, Red Cloak, and Carbon Black will continue to be retained at a cost of $190,520 to carry out approximately 480 hours of work to fix the issue.
The school board said that the recovery efforts will involve working with the district’s Active Directory and “shoring up its firewall.”
The vote took place on October 27, eight days after the school board sought legal advice on how to respond to the incident.
According to a report by Count on News 2, on October 27, the district was still working on “sanitization” efforts and the district networks had not yet returned to normal operations.
The school board has not added a notice about the cybersecurity incident to its website. The incident is being reported by Live 5 News as a cyber-attack.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Venmo to Reimburse Hacking Victims
Venmo to Reimburse Hacking Victims

Mobile payment service Venmo has come to the aid of a couple from Florida whose entire bank account was emptied by hackers.
Cyber-thieves stole $19,500 from retired husband and wife Alan and Aviva Sturm earlier this year. The hackers gained access to the couple’s Bank of America bank accounts by creating a fraudulent Venmo account.
The hackers reportedly stole the funds from the Sturms’ bank account through a series of illegal transfers that began in March and carried on until June. The sum of $1,500 was taken every week until every cent of the couple’s savings was gone.
The couple from Boynton Beach discovered the theft when their rent payment bounced. They contacted Bank of America and the Palm Beach County Sheriff’s Office but were unable to recover any of the money.
Aviva told local news source WDSU that before the theft occurred, they hadn’t heard of Venmo and had no idea what it was.
“We’re going around asking people if they’ve ever heard of Venmo, and a lot of people have, but we’ve never heard of it,” she said.
Because of the change in their financial circumstances, Alan and Aviva, who both have heart problems, had to cancel their secondary medical insurance and downsize their accommodations at an assisted living facility to a one-bedroom apartment.
Alan, who is 74, said: “It was just a matter of time until we ended up in the street.”
Bank of America told the Sturms that it couldn’t return any of the stolen money because it had been told by Venmo that the couple had authorized the transfers.
Venmo, which is owned by PayPal, said that the company will reimburse the Sturms for the whole amount stolen. An investigation into how the hackers were able to create a fake account and get the fraudulent transfers authorized is ongoing.
A spokesperson for Venmo said: “When we were contacted about the situation, we worked quickly to investigate the matter and assist our customers. We take every instance of potential fraud very seriously, and the company works diligently to support and protect our customers.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
BlackMatter Group Speeds Up Data Theft with New Tool
BlackMatter Group Speeds Up Data Theft with New Tool

Security researchers have discovered a new data exfiltration tool designed to accelerate information theft for ransomware groups using the BlackMatter variant.
The Symantec Threat Hunter team explained in a new blog post today that the custom tool is the third discovery of its kind, following the development of the Ryuk Stealer tool and the LockBit-linked StealBit.
Dubbed “Exmatter,” it is designed to steal specific file types from selected directories and then upload them to a server under the control of BlackMatter attackers.
This process of whittling down data sources to only those deemed most profitable or business-critical is designed to speed up the whole exfiltration process, presumably so the threat actors can complete their attack stages before being interrupted.
After retrieving the drive names of all logical drives on a victim computer and collecting all file pathnames, Exmatter disregards anything under specific directories such as “C:Documents and Settings.”
It only exfiltrates specific file types such as PDFs, Word docs, spreadsheets and PowerPoints, and aims to prioritize those for exfiltration using LastWriteTime.
Once exfiltration has been completed, Exmatter looks to overwrite and delete any traces of itself from the victim’s computer.
Symantec said it found various versions of the tool, indicating that its developers have tried to refine its functionality to accelerate the process of data theft as far as possible.
The researchers claimed BlackMatter itself is linked to the “Coreid” cybercrime group, which may have also been responsible for Darkside — the variant that led to the Colonial Pipeline outage.
However, it’s unclear whether Exmatter was developed by this group or one of the many affiliates who use BlackMatter in attacks.
“Like most ransomware actors, attacks linked to Coreid steal victims’ data and the group then threatens to publish it to further pressure victims into paying the ransom demand,” Symantec concluded.
“Whether Exmatter is the creation of Coreid itself or one of its affiliates remains to be seen, but its development suggests that data theft and extortion continues to be a core focus of the group.”
The US authorities issued an alert on BlackMatter in mid-October, after it began to target critical infrastructure providers. One vendor claims it may still help victims of the ransomware variant after finding a bug in its code.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains