Tag Archive for: Ransomware

MedStar Health partially restores services after suspected ransomware attack

MedStar Health said Wednesday it is restoring computer systems following a cyberattack that reportedly involved file-encrypting malware.

The not-for-profit organization, which runs 10 hospitals in the Washington, D.C., area, was hit with ransomware, the Baltimore Sun reported on Wednesday, citing two anonymous sources.

MedStar Health officials could not be immediately reached for comment. The organization issued two statements Wednesday, but did not describe what type of malware infected its systems.

It said in one statement that its IT team has worked continuously to restore access to three main clinical systems. It said no patient data or associate data was compromised.

To read this article in full or to leave a comment, please click here

Network World Security

Maryland hospital group hit by ransomware

Baltimore’s Union Memorial is one of the hopitals hit by Samsam, an autonomous ransomware strain spread by exploiting JBoss servers. (credit: MedStar)

Baltimore’s Union Memorial Hospital is the epicenter of a malware attack upon its parent organization, MedStar. Data at Union Memorial and other MedStar hospitals in Maryland have been encrypted by ransomware spread across the network, and the operators of the malware are offering a bulk deal: 45 bitcoins (about $ 18,500) for the keys to unlock all the affected systems.

Reuters reports that the FBI issued a confidential urgent “Flash” message to the industry about the threat of Samsam on March 25, seeking assistance in fighting the ransomware and pleading, “We need your help!” The FBI’s cyber center also shared signature data for Samsam activity to help organizations screen for infections. But the number of potential targets remains vast, and the FBI was concerned that entire networks could fall victim to the ransomware.

According to sources who spoke to the Baltimore Sun, the malware involved in MedStar’s outages is Samsam, also known as Samas and MSIL. The subject of a recent confidential FBI cyber-alert, Samsam is form of malware that uses well-known exploits in the JBoss application server and other Java-based application platforms. As Ars reported on Monday, Samsam uses exploits published as part of JexBoss, an open-source security and penetration testing tool for checking JBoss servers for misconfiguration.

Read 3 remaining paragraphs | Comments

Technology Lab – Ars Technica

Ransomware Was the Largest Threat to UK Android Devices in 2015 – Cellular News

Ransomware Was the Largest Threat to UK Android Devices in 2015
Cellular News
Predominantly distributed through malicious apps, Android.Trojan.Slocker accounted for 22 per cent of Android malware threats in the UK in the latter half of the year. In total, Android ransomware accounted for 28 per cent of reported Android malware

\\”android+ransomware\\” – read more

New ransomware abuses Windows PowerShell, Word document macros

A new ransomware program written in Windows PowerShell is being used in attacks against enterprises, including health care organizations, researchers warn.

PowerShell is a task automation and configuration management framework that’s included in Windows and is commonly used by systems administrators. It has its own powerful scripting language that has been used to create sophisticated malware in the past.

The new ransomware program, dubbed PowerWare, was discovered by researchers from security firm Carbon Black and is being distributed to victims via phishing emails containing Word documents with malicious macros, an increasingly common attack technique.

To read this article in full or to leave a comment, please click here

Network World Security