• Home
    • What is
    • Computer security
      • Windows security
      • Mac security
      • Linux security
    • Mobile security
      • Android security
      • iOS Security
    • Data security
    • SCCM
    • Reviews
      • Case studies
    • Advertise
    • Contact
      • Privacy Policy
  • Subscribe now

    Loading
  • Home
  • What is
  • Computer security
    • Windows security
    • Mac security
    • Linux security
  • Mobile security
    • Android security
    • iOS Security
  • Data security
  • SCCM
  • Reviews
    • Case studies
  • Advertise
  • Contact
    • Privacy Policy
Home » Breaking Computer security Cyber Security Latest Cybersecurity News

Night Sky Ransomware is attacking corporate networks for 800K ransom

John Greenwood Posted On January 7, 2022
0



Night Sky Ransomware

The new year comes with a new ransomware variant called Night Sky, targeting corporate networks and stealing information in double-extortion attacks.

The discovery of Night Sky ransomware was first made by MalwareHunterteam on Dec 27th when two victims were affected by the ransomware variant. The ransom demand was $800,000for the decryptor and not publishing the encrypted data.

Modus Operandi of Night Sky Ransomware

Night Sky ransomware comes with a hardcoded credentials to breach the victim’s negotiation page and deliver a customized ransom note. The ransomware will encrypt your data except the .dll and .exe files. Once the files are encrypted the encrypted files will have a extension .nightsky as the shown in the image.

Night Sky Ransomware

Within folders a ransom note with file name NightSkyReadme.hta is available, and this file will have the details of the data that is stolen including emails, credentials, etc. The ransomware uses email and web site with Rocket to communicate with the victims.

Also, the ransom note comes with credentials which should be used to login with the Rocket.Chat URL.

Night Sky Ransomware

Night Sky ransomware employs double-extortion

Like any other ransomware operations Night Sky ransomware also encrypts as well as steals the victim’s data for further leverage. The double-extortion strategy is used to threaten victims to make ransom payments, as leakage of data could be more devastating than just encryption.

The leakage of data is done via the data like site in Tor which already has the two victims from the December breach. These two victims were from Japan and Bangladesh. The recent ransomware attack was from AvosLocker Ransomware Operators on December 30th attacking the US police department, and Night Sky ransomware is the first ransomware threat of 2022 that security professionals and enterprises need to keep an eye on.

While there has not been a lot of activity with the new Night Sky ransomware operation, it is one that we need to keep an eye on as we head into the new year.

Subscribe to our newsletter for daily alerts on cyber events, you can also follow us on Facebook, Linkedin, Instagram, Twitter and Reddit.

You can reach out to us via Twitter or Facebook, for any advertising requests.

Share the article with your friends


Night Sky RansomwareNight Sky Ransowmare Attack


Author

John Greenwood

He has been working with Cybersec and Infosec market for 12+ years now. Passionate about AI, Cybersecurity, Info security, Blockchain and Machine Learning. When he is not occupied with cybersecurity, he likes to go on bike rides!

Leave A Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • Subscribe to our newsletter

    Loading
  • Windows security

    • Recast Software: Advanced Endpoint Management and Security...
      November 16, 2024
    • Patch My PC: Streamlined Software Management for ConfigMgr...
      November 9, 2024
    • Best Microsoft Intune Alternatives: Top 5 MDMs to Consider
      November 4, 2024
    • Top 11 Log Management Tools for Efficient System Management
      September 20, 2024
    • Top 5 Threat Intelligence Tools For 2024
      September 19, 2024


  • About us

    Our vision is to deliver the trending and happening cyber events to the enthusiasts.

    We believe in delivering educational and quality content for hassle-free understanding of the subject.

  • Subscribe to our newsletter

    Loading
  • Follow us

  • Advertise with us

    You can reach us via Facebook, Linkedin, or Twitter for advertising purposes.


© The Cybersecurity Times 2022. All rights reserved.
Press enter/return to begin your search