Schneier on Security's Journal
 
[Most Recent Entries] [Calendar View]

Friday, May 21st, 2021

    Time Event
    5:45p
    Double-Encrypting Ransomware

    This seems to be a new tactic:

    Emsisoft has identified two distinct tactics. In the first, hackers encrypt data with ransomware A and then re-encrypt that data with ransomware B. The other path involves what Emsisoft calls a “side-by-side encryption” attack, in which attacks encrypt some of an organization’s systems with ransomware A and others with ransomware B. In that case, data is only encrypted once, but a victim would need both decryption keys to unlock everything. The researchers also note that in this side-by-side scenario, attackers take steps to make the two distinct strains of ransomware look as similar as possible, so it’s more difficult for incident responders to sort out what’s going on.

    << Previous Day 2021/05/21
    [Calendar]
    Next Day >>

Schneier on Security   About LJ.Rossia.org