Security experts at Recorded Future tracked a German hacker for the propagation of the Houdini worm through Pastebin sites. The same threat actor appears to be the author of an open source ransomware variant called MoWare H.F.D. Researchers observed three distinct spikes in malicious Visual Basic scripts posted on paste sites, in August, October, and in March 2017. Most of the scripts are used to spread the threat that first appeared in 2013 and was updated in 2016. According to the profile, Mohammed Raad is a member of a German cell of Anonymous, it uses Vicswors Baghdad.”]
Source: https://securityaffairs.co/wordpress/59495/malware/houdini-worm.html

