NCC warns against new ransomware attacking organisational, individuals’ networks

The Nigerian Communications Commission, (NCC), has alerted members of the public that a cybercrime group has perfected a new year scheme to deliver ransomware to targeted organisational networks.

The new ransomware uncovered by security experts has been categorised by the Nigerian Computer Emergency Response Team’s (ngCERT) advisory released over the weekend, as high-risk and critical.

According to the ngCERT advisory, the criminal group is said to have been mailing out USB thumb drives to many organisations in the hope that recipients will plug them into their PCs and install the ransomware on their networks. While businesses are being targeted, criminals could soon begin sending infected USB drives to individuals.

Numerous attack tools are also installed in the process, which allows for exploitation of personal computers (PCs), lateral movement across a network, and installation of additional malware. The tools were used to deploy multiple ransomware strains, including BlackBatter and REvil.

According to ngCERT, “The attack has been seen in the US where the USB drives were sent in the mail through the Postal Service and Parcel Service. One type contained a message impersonating the US Department of Health and Human Services and claimed to be a Covid-19 warning. Other malicious USBs were sent in the post with a gift card claiming to be from Amazon”.

However, ngCERT has offered recommendations that will enable corporate and individual networks to mitigate the impact of this new cyber attack and be protected from the ransomware.

Related posts

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.