cognitive cybersecurity intelligence

News and Analysis

Search

‘Textbook identity attack’ dropped ransomware via fake KeePass site

‘Textbook identity attack’ dropped ransomware via fake KeePass site

Threat actors carried out a sophisticated identity attack by luring victims to a bogus KeePass password manager download site. After installing the malicious software, the attackers downloaded and launched a Cobalt Strike tool for command-and-control operations, exporting the existing KeePass password database. The attackers, linked to Black Basta, encrypted VMware ESXi datastores, causing the VMs to fail. The incident underlines the need for users to verify software sources and the risks of over-reliance on credentials.

Source: www.scmagazine.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts