New Python-based Ransomware Poses as Locky
#1
Quote:A ransomware family used in attacks in July and August was posing as the infamous Locky ransomware that was highly active in 2016, Trend Micro researchers have discovered. 

Written in Python and dubbed PyLocky, the new malware is packaged with PyInstaller, a tool that turns Python applications into standalone executables. 


What makes PyLocky stand out from the crowd compared to other Python malware is anti-machine learning capability. It also uses the open-source script-based Inno Setup Installer and can pose a real challenge to static analysis methods, the security researchers say. 


Furthermore, PyLocky has seen a highly concentrated distribution, with several spam emails targeting European countries, particularly France. Initially low, the spam volume increased in time. 


A spam run observed in early August targeted French businesses, leveraging social engineering in an attempt to lure potential victims into clicking a link that redirects them to a malicious URL to download a ZIP file containing PyLocky.

Source: https://www.securityweek.com/new-python-...oses-locky
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Opera 124.0.5705.65
New update to Oper...harlan4096 — 09:20
Vivaldi 7.7 Build 3851.56
Vivaldi 7.7 Build ...harlan4096 — 09:19
Rest in Peace Windows? Large YouTube cha...
Is Linux an altern...harlan4096 — 09:18
XYplorer
XYplorer ver 28.00 (...damien76 — 17:05
uBlock Origin 1.68.0 (already available ...
uBlock Origin 1.68...harlan4096 — 12:10

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>