Articles tagged "Symantec"

Found 9 articles

Actively Exploited

A new ransomware strain called Spirals has been linked to a recent attack on an IT services company in South Asia. Cybercriminals quickly gained access to the company's network, executing data theft and encrypting files in less than 24 hours. Spirals, which is written in Rust, employs a unique encryption method by using a separate AES-128 key for each file, making it difficult for victims to recover their data without paying a ransom. This incident highlights the growing sophistication of ransomware attacks and the need for organizations to enhance their cybersecurity measures to protect sensitive information. As ransomware attacks continue to evolve, companies must remain vigilant and prepared for potential threats.

Read Original

Daxin, an advanced malware linked to a Chinese threat actor, has been detected again after a four-year gap, this time within a manufacturing firm in Taiwan. This kernel-mode rootkit, identified as 'srt64.sys', was first reported by Symantec in March 2022. Alongside Daxin, researchers have also discovered a new backdoor called Stupig, which has not been previously documented. The resurgence of Daxin raises concerns about targeted attacks on critical infrastructure, particularly in sectors like manufacturing that are vital to the economy. Organizations in Taiwan and similar industries need to be vigilant and reassess their cybersecurity measures to protect against these sophisticated threats.

Read Original
Actively Exploited

A new ransomware strain called GodDamn has emerged, targeting systems by disabling security software using a signed driver known as PoisonX. Discovered by Symantec's Threat Hunter Team, GodDamn is considered an advanced version of the Beast ransomware family, and it first appeared on May 21, 2026. The ransomware's ability to circumvent security measures poses a significant risk to organizations, as it can lead to data breaches and financial losses. The analysis of an attack in early June indicates that the group behind it is actively exploiting this vulnerability, making it imperative for companies to assess their defenses. Users and companies need to be aware of this threat and take immediate steps to bolster their security protocols.

Read Original

A new ransomware strain called GodDamn has been identified by cybersecurity researchers, specifically the Threat Hunter Team at Symantec. This ransomware uses a malicious kernel driver named PoisonX to disable endpoint security measures, allowing it to operate without detection. GodDamn was first observed in the wild on May 21, 2026, and is believed to be a rebranding of an earlier ransomware known as Beast. The use of PoisonX is particularly concerning as it directly undermines the defenses that companies rely on to protect their systems. Organizations need to be vigilant and update their security protocols to defend against this new threat.

Read Original

Mistic is a new backdoor being used by a group linked to KongTuke, aimed at maintaining long-term access to networks targeted by ransomware attacks. Security researchers from Symantec have identified Mistic in attacks primarily directed at sectors like insurance, education, IT, and professional services. This backdoor allows attackers to operate quietly over an extended period, making it a serious concern for organizations in these industries. The stealthy nature of Mistic means that it can evade detection while enabling further exploitation of compromised systems. Companies should be vigilant and enhance their security measures to prevent such intrusions.

Read Original

A new backdoor known as Mistic has been discovered in a series of financially motivated cyberattacks targeting organizations across various sectors, including insurance, education, IT, and professional services. This backdoor, also referred to as MLTBackdoor, has been linked to an initial access broker called KongTuke. Researchers from Symantec and Carbon Black's Threat Hunter Team have traced the deployment of Mistic back to April 2026. The stealthy nature of this backdoor raises concerns as it allows attackers to infiltrate systems undetected, potentially leading to data theft or other malicious activities. Organizations in the affected sectors should be on high alert and strengthen their cybersecurity measures to combat this emerging threat.

Read Original

A new ransomware strain called Osiris was identified in a November 2025 attack targeting a significant food service franchise in Southeast Asia. Researchers from Symantec and Carbon Black reported that the attackers used a malicious driver known as POORTRY through a technique called Bring Your Own Vulnerable Driver (BYOVD) to disable security tools. This method allowed the ransomware to operate without detection, posing a serious risk to the affected organization. With ransomware attacks on the rise, this incident highlights the need for companies to strengthen their defenses against evolving tactics. The incident serves as a reminder for businesses to continuously update their security measures and remain vigilant against such threats.

Read Original

A new strain of ransomware known as Osiris has been identified, targeting a major food service franchisee operator in Southeast Asia in November 2025. The attackers utilized a malicious driver called POORTRY in a technique known as bring your own vulnerable driver (BYOVD), which helps them disable security measures on the victim's systems. This method allows the ransomware to operate without detection, increasing the risk of data theft and operational disruption. The emergence of Osiris is concerning as it reflects a growing trend in ransomware attacks that exploit existing drivers to bypass security protocols. Organizations, especially those in sensitive sectors like food services, need to be vigilant and ensure their security measures can defend against such sophisticated techniques.

Read Original
Actively Exploited

Ransomware attacks surged to a record high in 2025, with attackers claiming 4,737 incidents, according to research by Symantec and Carbon Black. Despite significant disruptions to major criminal organizations, ransomware activity did not decline as expected; instead, it adapted and diversified its extortion tactics. This ongoing trend indicates that even when law enforcement intervenes, cybercriminals find ways to continue their operations. The rise in ransomware incidents poses serious risks to businesses and individuals alike, as these attacks can lead to data breaches and financial losses. Companies need to prioritize cybersecurity measures to defend against these evolving threats.

Read Original