Ransomware Used Against Muni Known As Harsh, Virulent
ID: a0736ccb-382c-5c31-a53a-7c049f69dbf4
STIX ID: report--a0736ccb-382c-5c31-a53a-7c049f69dbf4
Feed Name: Security Ledger
San Francisco MTA was struck by an HDDCryptor (aka Mamba) ransomware outbreak that encrypted systems including fare collection terminals and internal email, forcing turnstiles to be opened and disrupting operations; attackers reportedly infected thousands of machines, demanded a $73,000 bitcoin ransom, and an individual claiming responsibility alleged theft of 30 GB of internal data. The malware described infects the MBR, spreads over SMB to network shares and mapped drives, and has been characterized as highly virulent; the agency reported service safety was unaffected and recovery proceeded without payment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
