Get a Pentest and security assessment of your IT network.

Cyber Security

MountLocker ransomware gets slimmer, now encrypts fewer files

New version of MountLocker encrypts files on the infected computers using the ChaCha20 stream cipher. The new code is very similar to the old one, the biggest change being the process for deleting volume shadow copies and for terminating processes. 70% of the code in the new version is the same as in the previous version, including the insecure Windows API function GetTickCount by the malware to generate a random encryption key (session key) BlackBerry says that the use of the GetTICKCount API offers a slim possibility to find the encryption keys through brute-forcing.

Source: https://www.bleepingcomputer.com/news/security/mountlocker-ransomware-gets-slimmer-now-encrypts-fewer-files/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security