In early December, GoldenEye ransomware (detected by Trend Micro as RANSOM_GOLDENEYE.A) was observed targeting German-speaking users—particularly those belonging to the human resource department. GoldenEye, a relabeled version of the Petya (RANSOM_PETYA) and Mischa (RANSOM_MISCHA) ransomware combo, GoldenEye not only kept to the James Bond theme of its earlier iteration, but also its attack vector.
Given ransomware’s likely outlook to reach a plateau, persistence in the threat landscape and diversification of target victims are the names of the game. GoldenEye exemplifies bad guys trying to gain scale, leverage, and profit with rehashed malware.
Apart from GoldenEye, we also saw spam runs and observed a surge in detections of Cerber (RANSOM_CERBER), Petya (RANSOM_PETYA), and Locky (RANSOM_LOCKY) in Germany. The social lures of these malware may be German, but the risks and impact are the same for everyone.
Post from: Trendlabs Security Intelligence Blog – by Trend Micro
Recent Spam Runs in Germany Show How Threats Intend to Stay in the Game