A new ransomware variant first discovered in January 2023 has been targeting victims mainly in the United States, but also Turkey, the United Kingdom, and the Philippines. The ransomware is based off the Xorist commodity ransomware family, which has been free to decrypt since 2006. The threat actors begin the attack by targeting victims with a phishing email that contains a malicious ZIP file containing a BAT loader script that downloads a second archive from a remote resource. Along with Mortal Kombat ransomware, the threat actors are also using Laplas, a cryptocurrency hijacker that monitors the Windows clipboard for crypto addresses and when found, replaces them with their own address to trick victims into sending money to the threat actors.
12 Essentials for a Successful SOC Partnership
As cyber threats continue to impact businesses of all sizes, the need for round-the-clock security