North Korean hackers return to actively deploying ransomware after the huge WannaCry debacle. Antivirus maker Kaspersky said in a report today that hackers associated with the North Korean regime are behind a new ransomware strain known as VHD. The report details two incidents to which Kaspersky was privy, where intruders gained access to companies' networks and deployed the VHD ransomware. Kaspersky experts say that tools and techniques used during the two intrusions link the attackers to Lazarus Group -- a generic name given to hackers working for the Pyongyang regime. This included: the use of the MATA (Dacls) malware framework to deploy VHD as a final payload the use of techniques to move across a victim's internal network that were previously observed in past Lazarus campaigns "The data we have at our disposal tends to indicate that the VHD ransomware is not a commercial off-the-shelf product; and as far as we know, the Lazarus group is the sole owner of the MATA fram...
The one-stop for all cyber news around the world