# Tags

Cosmos Bank website compromised with RIG Exploit Kit which drops Cerber Ransomware

Update: The incident has been taken care of by Cosmos Bank and its website (URL) is now clean and safe to use. Compromising popular websites has become a common strategy for attackers to spread infection in a widespread fashion. Attackers exploit unpatched vulnerabilities present on web servers in order to compromise websites. In addition to this, […]

Beware of Spora – a professionally designed ransomware

Spora is a recent addition to the ransomware family that Quick Heal Lab has come across.  It is a file encryptor ransomware that encrypts a user’s files with strong encryption algorithm and demands a ransom. Spora is launched with a good infection routine, the capability to work offline, well-designed and managed payment portal dashboard, decryption […]

The Remote Desktop Protocol Vulnerability – ‘CVE-2012-0002’ is not dead yet!

On March 13, 2012, Microsoft disclosed the details of a ‘critical vulnerability’ called Remote Desktop Protocol Vulnerability – CVE-2012-0002 in its bulletin. And even four years after this vulnerability was patched, it is still being exploited in the wild by attackers to carry out ‘Remote Code Execution’ on their victims computers. Affected Operating Systems: Microsoft […]

Alert! A Fake Flash Player Website is Spreading Locky Ransomware

The Locky ransomware, like all other ransomware, encrypts user data and demands a hefty ransom in exchange for the key that decrypts the data. A variant of this ransomware called ‘thor’ was recently found being distributed via a fake ‘Flash Player Update’ downloading website that goes by the name ‘fleshupdate.com’. The distribution of unwanted software […]

5-compelling-reasons-not-pay-ransomware-attack

5 Compelling Reasons Not to Pay Ransom to Hackers

Unless you’ve been living under a rock, you would know what a ransomware is and why are computer security folks constantly speaking about it. To put things into context, ransomware is a malicious software that locks your computer or encrypts the files stored in it. It then demands a ransom to let go off the […]

Alert! Ransomware is Being Spread through the Ammyy Admin Website

This is a precautionary advisory for users who frequently visit the website of the popular remote desktop sharing software called Ammyy Admin. Quick Heal Labs has observed that a new variant of the Cerber3 Ransomware is being spread through the Ammyy Admin software on the official Ammyy Admin website. This news, however, is not surprising […]

Be Careful of the KMSPico Activator – It could be a Ransomware!

If you are using KMSPico Activator for activating your Windows or MS Office, then you could be risking yourself to a ransomware infection. Quick Heal Threat Research Labs has recently observed a new variant of ransomware called Domino that is using this activator as a carrier. The malware encrypts the infected files and appends the […]

Recover data after a ransomware attack

How to Recover Files After a Ransomware Attack?

What if you know your data is securely backed up when a ransomware strikes and you don’t have to worry about recovering your files? The Backup and Restore feature of Quick Heal helps you achieve this. What is a Ransomware? Ransomware is a malware that either locks an infected computer or encrypts all the files […]

Ransomware Getting Delivered Using Script Files

The ransomware threat has significantly grown over time. Each day, a new variant gets added to the ransomware family. Malware are usually delivered through exploit kits and spam emails. Speaking of spam emails, they are either loaded with malicious document files installing the malware or malware directly inside a ZIP file. Cyber criminals continue to […]