The FBI this week released a report detailing indicators of compromise associated with ransomware variants that have compromised at least 60 entities worldwide, and recommendations for organizations to reduce their risk of attack. The Cybersecurity & Infrastructure Agency today encouraged organizations to review and apply the recommendations. 

John Riggi, AHA’s national advisor for cybersecurity and risk, said, “In addition to containing actionable indicators of compromise, this FBI FLASH points out that the BlackCat gang is using advanced programming language (known as RUST) that increases the reliability of their attacks, and offering their capability to other hackers as ‘ransomware as a service.’ It also notes that members of the BlackCat ransomware gang have been linked to the Russian-speaking Darkside/Blackmatter gang responsible for the Colonial Pipeline ransomware attack in 2021 – thereby indicating this group may possess the capability to attack U.S. critical infrastructure. Whether they have the current intent remains to be seen. Given the possible Russian connection and the flurry of recent government warnings of Russian-state sponsored and criminal cyber threats to U.S. critical infrastructure, the BlackCat ransomware group is of significant concern.”   

For more information on this and other cyber risks, contact Riggi at jriggi@aha.org.

Related News Articles

Headline
A critical vulnerability has been identified in 7-Zip, a free software program used for archiving data, according to the National Institute of Standards and…
Headline
U.S. and international agencies Nov. 19 released a guide on mitigating potential cybercrimes from bulletproof hosting providers. A BPH provider is an internet…
Headline
A joint advisory issued yesterday by U.S. and international agencies provides updated guidance to defend against the Akira ransomware group, which…
Headline
The National Security Agency, Cybersecurity and Infrastructure Security Agency and international partners released joint guidance Oct. 30 on best practices for…
Headline
Microsoft has released a security update to address a critical remote code execution vulnerability impacting multiple versions of Windows Server Update…
Headline
In part two of a recent blog, AHA National Advisor for Cybersecurity and Risk John Riggi and AHA Deputy National Advisor for Cybersecurity and Risk Scott Gee…