2279
We help victims of Ransomware! O foco deste grupo é soluções em tema RANSOMWARE, ou assuntos relacionados a MALWARE ANALYSIS. Decriptografia.
Someone can help to repair one .db file? Almost 5gb, and its with SQLAnywhere, SAP
Читать полностью…
Shhh... quiet now.
Muted Nathan for 10 minutes.
Reason:
Automated blocklist action, due to a match on: https://t.me
fw from: @ransomwareworld
🚨 Update Trend Micro / Cisco Talos Analysis: Qilin ransomware abuses WSL to run Linux encryptors in Windows
Trend Micro and Cisco Talos identified that Qilin affiliates are using Bring Your Own Vulnerable Driver (BYOVD) attacks to disable security tools before launching ransomware. They deployed signed but vulnerable drivers such as eskle.sys to terminate antivirus and EDR processes, and used DLL sideloading to load kernel drivers like rwdrv.sys and hlpdrv.sys for elevated privileges. The attackers also used tools including dark-kill and HRSword to stop security software and erase traces of activity. Additionally, Qilin affiliates were observed deploying a Linux-based encryptor on Windows systems through the Windows Subsystem for Linux (WSL). After gaining access, they transferred the ELF encryptor via WinSCP and executed it through Splashtop’s SRManager.exe, allowing it to run within WSL and evade Windows-focused EDR detection. This method demonstrates how ransomware groups are increasingly exploiting hybrid Windows-Linux environments to maximize impact while bypassing conventional security defenses.
Reference 1: https://blog.talosintelligence.com/uncovering-qilin-attack-methods-exposed-through-multiple-cases/
Reference 2: https://www.trendmicro.com/en_us/research/25/j/agenda-ransomware-deploys-linux-variant-on-windows-systems.html
Reference 3: https://www.bleepingcomputer.com/news/security/qilin-ransomware-abuses-wsl-to-run-linux-encryptors-in-windows/
Any solution for this virus .PIIQ affected in my system
Читать полностью…
"Please follow @stopransomware for decryptor"
Читать полностью…
Do you know of any AI that does Ethical hacking and penetration tests?
Читать полностью…
Alguém sabe onde contrato um serviço de hacking?
Читать полностью…
Халтура
Свободный график, еженедельные выплаты
25.000 неделя. + премии и аванс
еще актуально @dlr66
Any software like sql anywhere to test db files?
Читать полностью…
⟡ ═══════════════ ⟡
𝐖 𝐔 𝐙 𝐄 𝐍
安卓顶级隐匿访问框架
⟡ ═══════════════ ⟡
╔═━━━━━━━━━━━═╗
Managed Service
╚═━━━━━━━━━━━═╝
➤ Zero-Detect APK Guarantee
➤ Instant Replacement if Flagged
➤ Global Bulletproof C2 Server
➤ No Tech Skills Required
╔═━━━━━━━━━━━═╗
Elite Capabilities
╚═━━━━━━━━━━━═╝
⟡ HVNC – Invisible Device Control
⟡ 300+ Native Phishing Injections
⟡ Live Key & Screen Logger
⟡ Crypto Clipper (15+ Coins)
⟡ Ransomware & OS Lock Module
⟡ Biometric Bypass Suite
╔═━━━━━━━━━━━═╗
Build Options
╚═━━━━━━━━━━━═╝
⟡ Auto-C2 — $9.99 (Instant Setup)
⟡ Manual — Provide Token/Chat ID
╔═━━━━━━━━━━━═╗
Subscription Tiers
╚═━━━━━━━━━━━═╝
➤ WUZEN LITE — $49/wk
➤ WUZEN PRO — $149/wk
╔═━━━━━━━━━━━═╗
Task Guarantee
╚═━━━━━━━━━━━═╝
⟡ 24/7 dedicated support
⟡ Weekly stealth updates
➤ For demos, vouches & orders:
@WuzenHQ @WuzenSupport
@WuzenShadow
#AndroidRAT2025 #Wuzen #AndroidRAT #FUD2025 #TelegramBasedRat #RAT
Alguém consegue me ajudar? Já estou há um bom tempo tentando e nada
Читать полностью…
Fwd: @ransomwareworld
🚨 Prosecutors allege incident response pros used ALPHV/BlackCat to commit string of ransomware attacks
The alleged cybersecurity turncoats attacked at least five U.S. companies while working for their respective employers, officials said.
ID: https://cyberscoop.com/?p=86605
fwd: @ransomwareworld
⚖️ Conti Ransomware Case – Extradition
The U.S. Department of Justice announced the extradition of Ukrainian national Oleksii Lytvynenko (43, Cork, Ireland) to face charges related to the Conti ransomware operation.
Between 2020–2022, Lytvynenko allegedly conspired with others to deploy Conti, encrypt victim data, and demand ransom in cryptocurrency. The group is linked to over 1,000 victims across more than 30 countries, extorting at least $150 million in payments.
Conti was one of the most prolific ransomware strains, responsible for numerous critical infrastructure attacks.
The extradition was coordinated by Irish police (An Garda Síochána) and the FBI, reflecting growing international cooperation against cybercrime.
Full details: https://www.justice.gov/opa/pr/ukrainian-national-extradited-ireland-connection-conti-ransomware
fw from: @ransomwareworld
Qilin Ransomware – Updated Threat Overview (Oct 2025)
Ransomware-as-a-Service active since 2022, written in Golang and Rust, targeting Windows and VMware ESXi. Qilin shares traits with Black Basta, REvil, and BlackCat, and has impacted sectors like healthcare and education across multiple continents.
🧩 Key Techniques
🔑 Privilege Escalation (T1548.002) – Bypasses UAC with stolen tokens.
🧠 Credential Access (T1003.001, T1134) – Uses Mimikatz for LSASS dumping and token manipulation.
💾 Encryption (T1486) – AES-256/ChaCha20 + RSA-2048/4096 for keys.
🧱 Defense Evasion (T1562.001, T1562.009) – Kills AV, boots in Safe Mode.
⚙️ Persistence (T1547.001, T1547.004) – RunOnce & Winlogon registry entries.
🌐 Initial Access (T1190, T1566) – Exploits Citrix/RDP and spearphishing.
🧹 Impact (T1490, T1070) – Deletes shadow copies, event logs, and itself.
🕹 Lateral Movement (T1021.002, T1053.005) – Uses PsExec & GPO tasks.
🧩 Obfuscation (T1027.013) – Encrypted strings, renamed functions.
💡 Guardrails (T1480) – Requires password to execute.
🧿 VM Awareness (T1673) – Detects virtual environments.
📚 MITRE ATT&CK ID: S1242
Associated Software: Agenda
For full details, see the MITRE ATT&CK® entry for Qilin (S1242): https://attack.mitre.org/software/S1242/
fw from: @ransomwareworld
🚨 Ransomware Payments Dropped in Q3 2025: Analysis
Coveware has attributed the drop to large enterprises increasingly refusing to pay up and smaller amounts paid by mid-market firms.
ID: https://www.securityweek.com/?p=44100
fw from: @ransomwareworld
🚨 Security Incident Summary (Qilin Group) - Ransomware
Japanese retail company Muji has taken its online store offline following a ransomware attack that affected its delivery partner Askul.
On Sunday evening, Japan time, Muji reported that the incident disrupted all online retail services. Customers were unable to browse or make purchases on Muji’s website, view order histories in the Muji app, or access certain parts of the company’s web content.
According to Askul’s announcement, the ransomware attack caused a system failure that forced a suspension of order processing and delivery operations. The company stated that it is still investigating the scope of the incident, including whether any personal data was compromised.
Muji has not yet provided an estimated time for restoring its online services. The case highlights the growing supply chain risks in the retail industry, where a single partner’s cybersecurity breach can disrupt operations across multiple businesses.
Source 1 - Askul Announcement: https://www.askul.co.jp/snw/newsDispView/?newsId=18364
Source 2 - Bleeping Computer: https://www.bleepingcomputer.com/news/security/retail-giant-muji-halts-online-sales-after-ransomware-attack-on-supplier/
Tracks recent ransomware leaks in real time.
Great if you follow threat intel stuff 👇
https://www.ransomware.live/
Hi All
Any new solutions released for STOP ransomware (with the extension .remk) ?
My files have been encrypted since March 2020.🫠
🔤🔤🔤 🔤🔤 🔤🔤🔤
Tem conta nessas plataformas?
(Pix bet, Bet 7K, Esporte da Sorte, Bet365, 1xBet, Estrela Bet) 📌
Se sim — nova ou antiga — subida de saldo 10 a 15k.
🔒 Nada de login ou senha. Tudo feito por você.
❌ Sem cobrança antecipada.
No final, lucro dividido só manda minha parte.
Me chama no privado que te explico melhor. 🎚
Халтура
Свободный график, еженедельные выплаты
25.000 неделя. + премии и аванс
еще актуально @dlr66
🔤🔤🔤 🔤🔤 🔤🔤🔤
Tem conta nessas plataformas?
(Pix bet, Bet 7K, Esporte da Sorte, Bet365, 1xBet, Estrela Bet) 📌
Se sim — nova ou antiga — subida de saldo 10 a 15k.
🔒 Nada de login ou senha. Tudo feito por você.
❌ Sem cobrança antecipada.
No final, lucro dividido só manda minha parte.
Me chama no privado que te explico melhor. 🎚
🔤🔤🔤 🔤🔤 🔤🔤🔤
Tem conta nessas plataformas?
(Pix bet, Bet 7K, Esporte da Sorte, Bet365, 1xBet, Estrela Bet) 📌
Se sim — nova ou antiga — subida de saldo 10 a 15k.
🔒 Nada de login ou senha. Tudo feito por você.
❌ Sem cobrança antecipada.
No final, lucro dividido só manda minha parte.
Me chama no privado que te explico melhor. 🎚
🔤🔤🔤 🔤🔤 🔤🔤🔤
Tem conta nessas plataformas?
(Pix bet, Bet 7K, Esporte da Sorte, Bet365, 1xBet, Estrela Bet) 📌
Se sim — nova ou antiga — subida de saldo 10 a 15k.
🔒 Nada de login ou senha. Tudo feito por você.
❌ Sem cobrança antecipada.
No final, lucro dividido só manda minha parte.
Me chama no privado que te explico melhor. 🎚
Tô precisando muito quebrar a senha de uma pasta .zip pra acessar duas dll
Читать полностью…
🔤🔤🔤 🔤🔤 🔤🔤🔤
Tem conta nessas plataformas?
(Pix bet, Bet 7K, Esporte da Sorte, Bet365, 1xBet, Estrela Bet) 📌
Se sim — nova ou antiga — subida de saldo 10 a 15k.
🔒 Nada de login ou senha. Tudo feito por você.
❌ Sem cobrança antecipada.
No final, lucro dividido só manda minha parte.
Me chama no privado que te explico melhor. 🎚