Thursday, March 31, 2022

Australia PROMISE to retaliate to any cyber attack from Iran! 😲


Australia WILL RETALIATE to any cyber attack from Iran! 

Earlier this week it was reported that defense minister of Australia Peter Dutton stated that any cyber attack that originates from Iranian regime will be responded to by Australia "by an equal measure" 😮

Peter Dutton also says that officials in Australia are monitoring malicious cyber activity on a daily basis. And even though Australia has not been targeted for a month Peter Dutton is concerned that Australia could become collateral damage in a cyber war between other countries. He give example of instances were Microsoft is hacked like they were last week by Lapsus$. Hacks like this also will affect Australian government and innocent Australian people too. He also says that Australia would anticipate hacks from regimes like Iran ahead of time. 



Microsoft was hacked by Lapsus$ last week

Australia works very closely with the United States and the UK and have just opened up a new cyber security center in Australia capital of Canberra to monitor malicious cyber threats. 

Cyber war is changing especially with Russian invasion of Ukraine. And cyber attacks can cause so much damage such as loss of money or business collapse and at the worst injury or loss of life to people.😢

Iran has been publicly named by Australia since 2017 as a country that has launched malicious cyber activities against Australia and Australia will continue to publicly attribute Iran and expose attacks made by them to deter the threat. Iranian regime needs to change its ways!! 😤 

Sunday, March 27, 2022

NEW RANSOMWARE detected! LokiLocker could originate from Iran!

 


New Ransomware LokiLocker!!! 

It has been reported by BlackBerry Threat Intelligence that a new Ransomware as a Service program has been identified called LokiLocker! 😱

LokiLocker encrypts files and will render a machine unusable if  victim does not pay in time also LokiLocker is a new ransomware software targeting victims who use Windows OS. It also seems that LokiLocker is developed by an Iranian group called AccountCrack also at least three of  known LokiLocker users use usernames that are only found on Iranian hacking channels. LokiLocker should also not be mistaken for Locky or LokiBot as it is a NEW Ransomware program!



LokiLocker config source code 

LokiLocker malware appears to be written in .NET and protected with NETGuard using an additional virtualization plugin called KoiVM. This ransomware then encrypts victim’s files on local drives and network shares with a standard combination of AES for file encryption and RSA for key protection. It then ask victim to email attackers on how to pay ransom. LokiLocker also has a wiper functionality – if victim does not pay all non-system files will be deleted and MBR overwritten - wiping all victim’s files and rendering system unusable!


Could LokiLocker have been developed by Iran?? 

It appears that LokiLocker works as a service that appears to be sold to small number of hackers. It is not clear yet whether this means they come originate from Iran or not, but all evidence seen so far point to corrupt regime!