Microsoft warns of new ransomware campaign by Twisted Spider group

Uses malvertising to spread Danbot Trojan, then Cactus ransomware

John Leonard
clock • 2 min read
Microsoft warns of new ransomware campaign by the Twisted Spider group
Image:

Microsoft warns of new ransomware campaign by the Twisted Spider group

According to a series of posts on X by Microsoft Threat Intelligence, Russia-based ransomware actor Storm-0216 (aka Twisted Spider, UNC2198) is using Danabot, an advanced banking Trojan, to deploy Cactus ransomware.

First identified earlier this year, Cactus uses tools and custom scripts to disable security software to ease the distribution of the ransomware binary. In the current campaign, Microsoft Threa...

To continue reading this article...

Join Computing

  • Unlimited access to real-time news, analysis and opinion from the technology industry
  • Receive important and breaking news in our daily newsletter
  • Be the first to hear about our events and awards programmes
  • Join live member only interviews with IT leaders at the ‘IT Lounge’; your chance to ask your burning tech questions and have them answered
  • Access to the Computing Delta hub providing market intelligence and research
  • Receive our members-only newsletter with exclusive opinion pieces from senior IT Leaders

Join now

 

Already a Computing member?

Login

You may also like
Microsoft, Google and Snap report strong quarterly results, IBM and Intel less so

Finance and Reporting

Microsoft and Google see AI investments bearing fruit

clock 26 April 2024 • 4 min read
Big Tech's AI spending spree worries investors

Artificial Intelligence

Zuckerberg says building a leading AI system will take several years and require significant investment

clock 26 April 2024 • 3 min read
BlueVoyant chooses Leeds for new Security Operations Centre

Security

The new SOC will boost customer compliance with regulations like NIS2 and DORA

clock 25 April 2024 • 4 min read

More on Threats and Risks

Leicester streetlights on day and night following cyber-attack

Leicester streetlights on day and night following cyber-attack

Effects of ‘highly sophisticated’ breach still being felt

Penny Horwood
clock 25 April 2024 • 1 min read
Mandiant's 2024 threat report - five takeaways

Mandiant's 2024 threat report - five takeaways

Latest M-Trends report details how ransomware, zero-day attacks and other threats evolved last year.

Kyle Alspach
clock 24 April 2024 • 5 min read
Proportion paying ransoms declines in Q1 2024, even as takings break a new record

Proportion paying ransoms declines in Q1 2024, even as takings break a new record

Only 28% willing to meet ransomware gangs' demands

Muskan Arora
clock 23 April 2024 • 2 min read