#1 Trending Cybersecurity News & Magazine
Sunday, September 17, 2023
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Anime About Hacking

    Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    John Blackmon

    Leveraging VR to Train Human Firewall: An Exclusive Interview with John Blackmon

    American Steel & Aluminum data breach

    American Steel & Aluminum Co. Faces Data Breach by Akira Ransomware Group

    Greater Manchester Police Cyber Attack

    Greater Manchester Police Cyber Attack Exposes Extent of Data Vulnerability

    Gerchik Trading Ecosystem data breach

    Gerchik Trading Ecosystem Faces Data Breach Risk: What You Need to Know

    MGM Resorts Cyber Attack

    MGM Resorts Cyber Attack: The Assault, Intrusion, and the ‘Unknown User’ Through the Hacker’s Lens

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    Cyble Partner Network

    Cyble Revolutionizes Cybersecurity Collaboration With Launch of Global Partner Program ‘Cyble Partner Network’

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    •  Cyber Security Webinar
    • Endorsed Events
    • World CyberCon India
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
SUBSCRIBE
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Anime About Hacking

    Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    John Blackmon

    Leveraging VR to Train Human Firewall: An Exclusive Interview with John Blackmon

    American Steel & Aluminum data breach

    American Steel & Aluminum Co. Faces Data Breach by Akira Ransomware Group

    Greater Manchester Police Cyber Attack

    Greater Manchester Police Cyber Attack Exposes Extent of Data Vulnerability

    Gerchik Trading Ecosystem data breach

    Gerchik Trading Ecosystem Faces Data Breach Risk: What You Need to Know

    MGM Resorts Cyber Attack

    MGM Resorts Cyber Attack: The Assault, Intrusion, and the ‘Unknown User’ Through the Hacker’s Lens

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    Cyble Partner Network

    Cyble Revolutionizes Cybersecurity Collaboration With Launch of Global Partner Program ‘Cyble Partner Network’

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    •  Cyber Security Webinar
    • Endorsed Events
    • World CyberCon India
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

Newbie Group Underground Team Ransomware Lists Victim’s Host Information in Ransom Note

The ransom note left by the ransomware instructs the user to contact the attackers for help in recovering your encrypted files or to pay the ransom.

Chandu Gopalakrishnan by Chandu Gopalakrishnan
July 6, 2023
in Firewall Daily, Ransomware News, Threat Intelligence News
0
Underground Team ransomware
655
SHARES
3.6k
VIEWS
Share on LinkedInShare on Twitter

Researchers have found a new strain of ransomware, dubbed “Underground Team”. The Underground Team ransomware strain not only encrypts files but also lists victims’ host information in the ransom note.

Unlike the regular extortion demands, the Underground Team ransomware note offers help in spotting network vulnerabilities and recommendations for information security.

You might also like

US Cybersecurity Regulations: Tracing the Past and Predicting the Future

The Three Trends to Watch in the Growing Threat Landscape

Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

The specific victims targeted by the Underground Team ransomware strain remain unknown, said researchers at Cyble Research and Intelligence Labs (CRIL).

According to the researchers, there have been no reported instances of data leaks associated with this ransomware.

Underground Team ransomware: Deep dive

The Underground Team ransomware is made with Microsoft Visual C/C++ and runs on 64-bit systems.

When it infects a computer, it carries out various actions such as deleting backup copies of your files, changing settings in the computer’s registry, and stopping a specific database service called MSSQLSERVER.

To achieve these actions, the ransomware uses specific commands. For example, it uses a command to delete the backup copies of your files stored on your computer. By doing this, it makes it harder for the user to recover files.

It also uses a command to adjust the settings related to remote desktop sessions, which can impact how the computer is accessed remotely.

Additionally, it forcefully stops the MSSQLSERVER service, which can disrupt the functioning of a particular type of database.

After that, the ransomware looks for the drives and file systems on your computer. It does this by using certain functions provided by your operating system. Once it identifies the drives, it drops a ransom note called “!!readme!!!.txt” in various folders on the computer.

Next, the ransomware starts searching for files and directories to encrypt. It does this by scanning through them one by one. However, it excludes certain filenames, file extensions, and specific folders from the encryption process.

Once the files are identified, the ransomware encrypts them, making them unreadable. However, it doesn’t change the names of the encrypted files or add any new extensions.

Underground Team ransomware: Encryption and negotiation style

After the encryption is complete, the Underground Team ransomware creates a file called “temp.cmd” and runs it. This file is designed to delete specific files, clear event logs, and remove itself from your computer. It does this to hide its presence and cover its tracks.

Underground Team ransomware
Ransom note. Image: CRIL

The ransom note left by the ransomware instructs the user to contact the attackers for help in recovering your encrypted files or to pay the ransom.

“The ransom note of the Underground Team ransomware introduces novel elements that distinguish it from typical ransom notes. In addition to guaranteeing a fair and confidential deal within a short timeframe, the group offers more than just a decryptor,” said the CRIL report.

The note provides an Onion URL, which is a way to access a chat platform to communicate with the attackers. This platform looks like a ticketing system, allowing you to negotiate with the attackers about the ransomware incident.

Underground Team ransomware
Chat Platform for Negotiating with Threat Actors. Image: CRIL

“It promises to provide insights into network vulnerabilities and recommendations for information security. Furthermore, qualified data recovery assistance will be extended to the victims if required,” the report said.

“While these novel additions showcase a broader approach by the ransomware group, it is imperative to continue exercising caution and skepticism when evaluating such claims.”

Ransomware mitigation: Begin with the basics

Although the operating style is different, attacks by the Underground Team ransomware strain can be averted to a great extent with some general security practices, CRIL researchers told The Cyber Express.

These include conducting regular backups and keeping them offline or in a separate network, enabling automatic software updates on all devices, using reputable anti-virus and internet security software, and exercising caution when opening untrusted links and email attachments.

“Over time, malicious actors have adjusted their ransomware tactics to be more destructive and impactful and have also exfiltrated victim data and pressured victims to pay by threatening to release the stolen data,” said a CISA advisory on ransomware protection.

“These ransomware and associated data breach incidents can severely impact business processes by leaving organizations unable to access necessary data to operate and deliver mission-critical services,” it said.

“The economic and reputational impacts of ransomware and data extortion have proven challenging and costly for organizations of all sizes throughout the initial disruption and, at times, extended recovery.”

In the event of a ransomware attack, users must disconnect infected devices from the network, detach external storage devices if connected, and inspect system logs for any suspicious events, advised CRIL researchers.

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Tags: Underground Team ransomware
Previous Post

Nagoya Port Cyber Attack: Japan’s Largest Port Paralyzed, LockBit Suspected

Next Post

Cyber Attacks on Sweden Rises: #OpSweden is Back, This Time With Different Results

Chandu Gopalakrishnan

Chandu Gopalakrishnan

Executive Editor, The Cyber Express

Related Posts

US Cybersecurity Regulations: Tracing the Past and Predicting the Future
Firewall Daily

US Cybersecurity Regulations: Tracing the Past and Predicting the Future

by Vishwa Pandagle
September 17, 2023
threat landscape
Cyber Essentials

The Three Trends to Watch in the Growing Threat Landscape

by Editorial
September 17, 2023
Anime About Hacking
Features

Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

by Ashish Khaitan
September 16, 2023
Ransomed Interview: Operator Speaks About No Mercy and All Gain
Firewall Daily

Ransomed Interview: Operator Speaks About No Mercy and All Gain

by Vishwa Pandagle
September 16, 2023
John Blackmon
Firewall Daily

Leveraging VR to Train Human Firewall: An Exclusive Interview with John Blackmon

by Editorial
September 16, 2023
Next Post
cyber attacks on Sweden

Cyber Attacks on Sweden Rises: #OpSweden is Back, This Time With Different Results

Latest Issue is Out. Subscribe Now



Follow Us On Google News

Latest Cyber News

US Cybersecurity Regulations: Tracing the Past and Predicting the Future
Firewall Daily

US Cybersecurity Regulations: Tracing the Past and Predicting the Future

September 17, 2023
threat landscape
Cyber Essentials

The Three Trends to Watch in the Growing Threat Landscape

September 17, 2023
Anime About Hacking
Features

Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

September 16, 2023
Ransomed Interview: Operator Speaks About No Mercy and All Gain
Firewall Daily

Ransomed Interview: Operator Speaks About No Mercy and All Gain

September 16, 2023

Categories

Web Stories

Top 10 CISOs to Follow in 2023
Top 10 CISOs to Follow in 2023
Top 10 Ransomware Gangs in 2023
Top 10 Ransomware Gangs in 2023
Top 5 IoT Security Risks in 2023
Top 5 IoT Security Risks in 2023
Top 10 CTF Platforms in 2023
Top 10 CTF Platforms in 2023
Types of Risks Covered by Cyber Insurance
Types of Risks Covered by Cyber Insurance

About

The Cyber Express by Cyble

#1 Trending Cybersecurity News and Magazine

The Cyber Express  by Cyble is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

For Events & Conferences related information: [email protected]

 

Quick Links

  • About Us
  • Advertise With Us
  • Contact Us
  • Editorial Calendar

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News
  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    •  Cyber Security Webinar
    • Endorsed Events
    • World CyberCon India
  • Products
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Top 10 CISOs to Follow in 2023 Top 10 Ransomware Gangs in 2023 Top 5 IoT Security Risks in 2023 Top 10 CTF Platforms in 2023 Types of Risks Covered by Cyber Insurance