/
    Zpět na blog
    Security Sunday

    Ransomware group LockBit disrupted by global police operation


    Ransomware group LockBit disrupted by global police operation#### Welcome to Security Sunday, your cybersecurity news

    image

    Ransomware group LockBit disrupted by global police operation

    The UK’s National Crime Agency (NCA) confirmed on Tuesday that it had obtained the source code of the LockBit group, as well as a wealth of information about its activities and its affiliates, as part of a specialized task force called Operation Cronos.

    The agency also announced the arrest of two LockBit members in Poland and Ukraine. More than 200 cryptocurrency accounts linked to the group have been frozen. Two other Russian nationals have also been indicted and sanctioned in the United States.

    Artur Sungatov and Ivan Gennadyevich Kondratyev (also known as Bassterlord) were indicted by the U.S. Department of Justice (DoJ) for using the LockBit scheme against numerous victims in the United States.

    Kondratyev was also charged with three felonies for using a variant of the Sodinokibi ransomware, also known as REvil, to encrypt data and exfiltrate victims’ information.

    The NCA called LockBit “the world’s most damaging cybercrime group.”

    The agency said it had taken control of LockBit’s services as part of the action. This includes the administration environment used by its affiliates and the publicly accessible leak sites hosted on the dark web.

    In addition, 34 servers were seized and more than 1,000 decryption keys were recovered from the seized servers.

    The U.S. State Department has announced a cash reward of up to $15 million for information leading to the identification of LockBit’s key leaders and the arrest of anyone involved in the operation.


    New SSH-Snake malware steals keys and spreads across the network

    SSH-Snake was discovered by the Sysdig Threat Research Team (TRT), which describes it as a “self-modifying worm” that differs from traditional SSH worms by avoiding patterns typical of scripted attacks.

    The worm looks for private keys in various places, including shell history files, and uses them to stealthily spread to new systems.

    However, researchers at cloud security company Sysdig say that SSH-Snake takes the typical concept of lateral movement to a new level by being more consistent in its search for private keys.

    The researchers also report that one of the peculiarities of SSH-Snake is its ability to modify and shrink when it is first run. It does this by removing comments and unnecessary functions from its code.

    The functionality of SSH-Snake was confirmed after the C2 (command and control) server was discovered to be used by its operators to store data obtained by the worm, including login credentials and IP addresses of victims.

    This data shows signs of active exploitation of known Confluence vulnerabilities (and possibly others) for initial access, leading to the deployment of the worm on these endpoints.

    According to the researchers, the tool has been used to attack approximately 100 victims.

    Sysdig considers SSH-Snake an “evolutionary step” in terms of malware, as it focuses on a secure connection method that is widely used in corporate environments.


    FTC orders Avast to pay $16.5 million for selling user data

    The Federal Trade Commission (FTC) orders Avast to pay $16.5 million and prohibits the company from selling or licensing users’ web browsing data for advertising purposes.

    The complaint alleges that Avast violated the rights of millions of consumers by collecting, storing, and selling their browsing data without their knowledge or consent, and by misleading them that the products used to collect their data would block online tracking.

    “Although the FTC routinely brings privacy lawsuits against companies that misrepresent their privacy practices, Avast’s decision to explicitly market its products as protecting browsing and tracking records, only to then sell those records, is particularly striking,” said FTC Chairwoman Lina M. Khan.

    In addition, the amount of data Avast has collected is staggering. The complaint alleges that the company will have amassed more than eight petabytes of data by 2020.

    Specifically, the FTC alleges that since at least 2014, UK-based Avast Limited has been collecting consumers’ web browsing information without their knowledge or consent through the use of Avast browser extensions and antivirus software.


    Signal introduces usernames to keep phone numbers private

    Popular app Signal says it is testing a new feature that allows users to create unique usernames to protect their phone numbers.

    “By default, when you use Signal, your phone number is no longer visible to anyone you chat with,” said Signal’s Randall Sarafa.

    Setting up a new username requires account holders to enter two or more numbers at the end of the username. Usernames are freely changeable.

    A username is an anonymous way to start a conversation on a chat platform without having to share phone numbers. Signal says it’s also taking steps to hide users’ phone numbers from others who don’t have them in their phone’s contacts by default.

    In addition, users can use other settings to control who can look up their numbers and limit the people who can text them.


    Cyber attack hits pharmacies across America

    Pharmacies across the United States say they are having trouble filling prescriptions for patients because of a cyberattack on a unit of UnitedHealth.

    The company said in a regulatory filing Thursday that its Change Healthcare division, which processes insurance prescriptions for tens of thousands of pharmacies nationwide, was targeted by hackers who gained access to some of its systems.

    The Naval Hospital in Camp Pendleton, California, for example, said in a post on the X network that it could not process any prescriptions.

    “Due to an ongoing company-wide issue, all Camp Pendleton and affiliated pharmacies are unable to process prescription requests,” the hospital said. “As a result, we are only able to assist patients with urgent and emergency prescriptions from hospital providers at this time.”

    Evans Army Hospital in Colorado said in a Facebook post that some prescription orders will be delayed.

    “This outage is impacting the dispensing of prescriptions in the pharmacy — causing delays in processing and in some cases, inability to process,” the hospital said. “Medication refills have also been affected.”

    The American Hospital Association has recommended that organizations using Change Healthcare’s services prepare contingency plans in the event of an extended outage.


    Up to 97,000 Microsoft Exchange servers may be vulnerable to a critical vulnerability

    Up to 97,000 Microsoft Exchange servers may be vulnerable to a critical privilege escalation vulnerability known as CVE-2024–21410 that hackers are actively exploiting.

    Microsoft addressed this vulnerability on February 13. It was already being exploited as a zero-day.

    The vulnerability allows remote unauthenticated actors to perform NTLM relay attacks on Microsoft Exchange servers and elevate their privileges on the system.

    Threat monitoring service Shadowserver announced today that its scanners have identified approximately 97,000 potentially vulnerable servers.

    Out of the total 97,000 servers, 28,500 servers have been confirmed to have the CVE-2024–21410 vulnerability.

    The most affected countries are Germany (22,903 cases), the United States (19,434), the United Kingdom (3,665), France (3,074), Austria (2,987), Russia (2,771), Canada (2,554) and Switzerland (2,119).

    There is currently no publicly available proof-of-concept (PoC) exploit for CVE-2024–21410, which somewhat limits the number of attackers who can exploit this vulnerability in an attack.

    To resolve CVE-2024–21410, system administrators are advised to apply Exchange Server 2019 Cumulative Update 14 (CU14), which will be released on February Patch Tuesday 2024.

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has also added CVE-2024–21410 to its catalog of “Known Exploited Vulnerabilities” and has given federal agencies until 7. March 2024 to apply available updates/fixes or discontinue use of the product.

    Exploitation of the CVE-2024–21410 vulnerability could have serious consequences for an organization because an attacker with elevated privileges on the Exchange server could gain access to confidential data and use the server for other network attacks.


    Interested in cyber security? Check out the next episodes of Security Sunday.

    https://medium.com/@zakpatrikcz/list/security-sunday-en-c438ddf5f168

    Do you need to cyber-security test your IT infrastructure? Contact me

    https://sysnetshield.com/security/

    © 2026 Patrik Žák. Všechna práva vyhrazena.