[HN Gopher] REvil ransomware hits 200 companies in MSP supply-ch...
___________________________________________________________________
REvil ransomware hits 200 companies in MSP supply-chain attack
Author : jnichols35
Score : 12 points
Date : 2021-07-02 20:49 UTC (2 hours ago)
(HTM) web link (www.bleepingcomputer.com)
(TXT) w3m dump (www.bleepingcomputer.com)
| afrcnc wrote:
| dupe: https://news.ycombinator.com/item?id=27716383
| steffanA wrote:
| Good tech details here about the attack.
|
| Also interesting "politically charged" Windows Registry keys and
| password changes:
|
| "For example, a sample [VirusTotal] installed by BleepingComputer
| adds the HKLM\SOFTWARE\Wow6432Node\BlackLivesMatter key to store
| configuration information from the attack.
|
| Advanced Intel's Vitali Kremez told BleepingComputer that another
| sample is configuring the device to launch REvil Safe Mode with a
| default password of 'DTrump4ever.'"
___________________________________________________________________
(page generated 2021-07-02 23:02 UTC)