Ransomware group UNC2447 used an SQL injection bug to attack US and European orgs
30 Apr 2021
Security researchers have discovered a new strain of ransomware designed to exploit a SonicWall VPN zero-day vulnerability before a patch was available.
Related Resource
Everything you need to know to keep your company afloat
According to researchers at Mandiant, the flaw exists in SonicWall’s SMA-100 series of VPN products. Hackers, who Mandiant dubbed UNC2447, targeted organizations in Europe and North America with a new ransomware known as FiveHands, a rewritten version of the DeathRansom ransomware.
Hackers deployed the malware as early as January this year along with Sombrat malware at multiple victims that were extorted. Researchers noted that in one of the ransomware intrusions, the same Warprism and Beacon malware samples previously attributed to UNC2447 were observed. Researchers are certain that the same hacking group used Ragnar Locker ransomware in the past.
Nový SonicWall firewall NSa 2700 channelworld.cz - get the latest breaking news, showbiz & celebrity photos, sport news & rumours, viral videos and top stories from channelworld.cz Daily Mail and Mail on Sunday newspapers.