Get a Pentest and security assessment of your IT network.

Cyber Security

MountLocker ransomware gets slimmer, now encrypts fewer files

New version of MountLocker encrypts files on the infected computers using the ChaCha20 stream cipher. The new code is very similar to the old one, the biggest change being the process for deleting volume shadow copies and for terminating processes. 70% of the code in the new version is the same as in the previous version, including the insecure Windows API function GetTickCount by the malware to generate a random encryption key (session key) BlackBerry says that the use of the GetTICKCount API offers a slim possibility to find the encryption keys through brute-forcing.

Source: https://www.bleepingcomputer.com/news/security/mountlocker-ransomware-gets-slimmer-now-encrypts-fewer-files/

Related posts
Cyber Security

Zip Codes & PII: Are They Personal Data?

Cyber Security

Zero-Day Vulnerabilities: User Defence Guide

Cyber Security

Zero Knowledge Voting with Trusted Server

Cyber Security

ZeroNet: 51% Attack Risks & Mitigation