LIVE · cybersecurity feed
Live wire
security

Silent Ransom Group: what you need to know

Most extortion gangs hide behind a keyboard. Silent Ransom Group will phone your staff pretending to be IT support - and if that fails, send someone to your office in person to plug in a USB stick. Read more in my article on the Fortra blog

zeroday.news · 51d ago

A ransomware group known as Silent Ransom Group is employing unusual and aggressive tactics to infiltrate organizations, moving beyond typical digital intrusion methods. Instead of solely relying on remote cyberattacks, this group has been observed initiating contact with employees through phone calls, impersonating IT support personnel.

The group's methods escalate if initial attempts at social engineering via phone are unsuccessful. In such cases, Silent Ransom Group has reportedly sent individuals to the targeted organization's physical office. These on-site operatives then attempt to gain access by physically inserting USB drives into company computers.

This dual approach, combining remote social engineering with physical infiltration, presents a significant challenge for traditional cybersecurity defenses. It bypasses many network-based security measures that are designed to detect and block remote access attempts or malicious file downloads.

The impersonation of IT support staff is a common social engineering tactic, but the addition of physical presence and the use of USB drives marks a notable departure from the modus operandi of many contemporary ransomware operations. This suggests a potentially higher level of sophistication and a willingness to take greater risks by the group.

The use of USB drives, often referred to as "USB drops" or "sneakernet" attacks, is a method that has been employed by various threat actors over the years. It relies on the physical access to a device and the user's trust or lack of suspicion to execute malicious code.

The effectiveness of these tactics hinges on the human element within an organization. Employees who are not adequately trained in recognizing social engineering attempts or who may be less security-conscious are particularly vulnerable to both the phone calls and the physical approach.

Organizations targeted by such methods would need to bolster their security awareness training programs to cover these specific scenarios. This includes educating staff on how to verify the identity of individuals claiming to be from IT support, especially when they request unusual actions or access.

Furthermore, physical security measures and policies regarding the acceptance and use of external media, such as USB drives, become critically important. Strict protocols for handling unsolicited devices and verifying the legitimacy of any on-site personnel are essential deterrents.

ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]