At the end of 2016, there was a major attack against San Franciscos Municipal Transportation Agency. The attack was done using Mamba ransomware. This month, we noted that the group behind this ransomware has resumed their attacks against corporations. Kaspersky Lab products detect this threat with the help of the System Watcher component with the following verdict: PDM:Trojan.Win32. The malware is able to choose between 32- or 64-bit DiskCryptor modules. The necessary modules will be dropped into the C:xampphttp folder.”]
Source: https://securelist.com/the-return-of-mamba-ransomware/79403/