{"id":29457,"date":"2019-11-22T06:00:10","date_gmt":"2019-11-22T13:00:10","guid":{"rendered":"https://www.webroot.com/blog/?p=29457"},"modified":"2019-11-21T17:01:54","modified_gmt":"2019-11-22T00:01:54","slug":"cyber-news-rundown-shade-ransomware-most-distributed-variant","status":"publish","type":"post","link":"https://www.webroot.com/blog/2019\/11\/22\/cyber-news-rundown-shade-ransomware-most-distributed-variant\/","title":{"rendered":"Cyber News Rundown: Shade Ransomware Most Distributed Variant"},"content":{"rendered":"\n<h2>Shade Ransomware Takes Crown as Most Distributed Variant<\/h2>\n\n\n\n<p>Over the course of 2019, one ransomware variant, known as <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/shade-ransomware-is-the-most-actively-distributed-malware-via-email\/\">Shade<\/a>, has taken over 50 percent of market share for\nransomware delivered via email. Otherwise known as Troldesh, this variant receives\nregular updates to further improve it\u2019s encrypting and methods of generating\nadditional revenue from both cryptomining and improving traffic to sites that\nrun ads. In just the first half of 2019, attacks using Troldesh dramatically\nrose from 1,100 to well over 6,000 by the second calendar quarter. <\/p>\n\n\n\n<h2>PayMyTab Leaves Customer Data Exposed<\/h2>\n\n\n\n<p>For more than a year sensitive customer data belonging to\nusers of the mobile payment app <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/paymytab-exposes-data-of-us\/\">PayMyTab<\/a>\nhas been publicly exposed in an online database using no security protocols.\nEven after being contacted multiple times regarding the data breach, the\ncompany has yet to fully secure customer data and may have to take drastic\nmeasures to fully secure their data storage after allowing virtually unlimited\naccess to anyone with an interest in personal data. <\/p>\n\n\n\n<h2>Credentials Dump for Major Service Sites<\/h2>\n\n\n\n<p>Login credentials for two highly-trafficked websites were\ndiscovered in a <a href=\"https:\/\/arstechnica.com\/information-technology\/2019\/11\/password-data-dumped-online-for-2-2-million-users-of-currency-and-gaming-sites\/\">data\ndump<\/a> earlier this week. One dump belonged to GateHub, a cryptocurrency\nwallet with potentially up to 1.4 million user credentials stolen, including\nnot only usernames and passwords, but also wallet hashes and keys used for\ntwo-factor authentication. The second dump contained information on 800,000\nusers of EpicBot, a RuneScape bot used to automate tasks in the skill-centric\nMMORPG. While both dumps appeared on dark web marketplaces on the same day, it\nalso seems coincidental that both sites use bcrypt hashing for passwords, which\nshould make them exceedingly difficult to crack assuming it was set up\nproperly. <\/p>\n\n\n\n<h2>Louisiana Government Systems Hit with Ransomware<\/h2>\n\n\n\n<p>Multiple Louisiana state service sites were taken offline\nearly Monday morning following a <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/louisiana-government-suffers-outage-due-to-ransomware-attack\/\">ransomware\nattack<\/a> that affected mostly transportation services. All 79 of the state\u2019s\nDMV locations were forced to close until systems were returned to normal, as\nthey were unable to access DOT services to assist clients. While it is still\nunclear what variant of ransomware was used, the state of Louisiana did have a\ncybersecurity team in place to stop any further spread of the infection. <\/p>\n\n\n\n<h2>Magecart Targets Macy\u2019s Online<\/h2>\n\n\n\n<p>Nearly a week after the initial breach, <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/macys-online-customers-hit-by\/\">Macy\u2019s<\/a>\nofficials noticed some unauthorized access between their main website and an\nundisclosed third-party site. The breach itself appears to have compromised\npayment card data for any customers who input their credentials during the\nfirst couple weeks of October. Macy\u2019s has since removed the illicitly added\ncode from their sites as well as contacted both payment card providers and\naffected customers regarding the breach. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Shade Ransomware Takes Crown as Most Distributed Variant Over the course of 2019, one ransomware variant, known as Shade, has taken over 50 percent of market share for ransomware delivered via email. Otherwise known as Troldesh, this variant receives regular updates to further improve it\u2019s encrypting and methods of generating additional revenue from both cryptomining [&hellip;]<\/p>\n","protected":false},"author":47,"featured_media":29467,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3005],"tags":[],"yst_prominent_words":[25203,3959,4965,6665,4139,25117,3769,21687,4047,20085,25201,8223,20231,25209,3937,25199,25205,4167,25207,5439],"acf":[],"_links":{"self":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/29457"}],"collection":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/users\/47"}],"replies":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/comments?post=29457"}],"version-history":[{"count":1,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/29457\/revisions"}],"predecessor-version":[{"id":29461,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/29457\/revisions\/29461"}],"wp:featuredmedia":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media\/29467"}],"wp:attachment":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media?parent=29457"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/categories?post=29457"},{"taxonomy":"post_tag","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/tags?post=29457"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/yst_prominent_words?post=29457"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}