REvil Rivals Rip Off Ransomware
Posted by: GuidePoint Security
Once again, threat actors offer proof that there is no honor among thieves. Researchers have discovered a group of ransomware criminals known as “LV” that appear to be pirating the REvil ransomware code. The code was likely derived through reverse engineering a REvil v2.03 beta version. Researchers have discovered that the code structure and functionality of the LV ransomware are identical to REvil. Attack activities also appear to be similar, including information stealing and public victim name shaming. Although the LV gang is a rival to the REvil gang, researchers are also not ruling out the possibility of some partnership between the two that has been covered up.
Next Steps
As ransomware attacks continue to increase, cybersecurity professionals are urging businesses to patch bugs and vulnerabilities immediately, as well as engaging a vulnerability management service. Endpoint security is also a key tool in the fight against ransomware. If organizations believe they have been victims of a ransomware attack, they are urged to work with a professional ransomware investigation and response team.
Check out our other blog posts from this past week.
GuidePoint Security