This new ransomware strain wants to get your insurance details so it can negotiate a bigger price

Ransomware
(Image credit: Pixabay)

Operators of a new ransomware strain have been seen trying to encourage victims to pay the ransom demand by pitting them against their insurance companies. 

The HardBit 2.0 variant has been seen carrying a few novel tricks up its sleeve, including a modified ransom note in which the attackers say that if their ransom demand is within the range covered by the insurance company, then that company is obliged to cover the costs of the cyberattack.

But the problem is, the crooks never know what the insurance details are, and the victims are contractually obliged to keep that information secret. Still, the crooks try to talk the victim into sharing that information, albeit privately.

Voiding the insurance contract

"To avoid all this and get the money on the insurance, be sure to inform us anonymously about the availability and terms of the insurance coverage, it benefits both you and us, but it does not benefit the insurance company," the note says.

The note essentially shows insurance companies as the bad guys, and further tells the victims not to engage with intermediaries or third parties, as that would only drive up the costs. 

Besides suggesting action that would void the insurance contract, the crooks made other changes to the ransomware strain, as well. Now, the malware is able to modify the endpoint’s Registry and disable Windows Defender real-time behavioral monitoring, process scanning, and on-access file protections, BleepingComputer reported. Furthermore, it tries to kill 86 processes to better encrypt sensitive files. 

Lastly, it doesn’t write encrypted data to file copies and then delete the originals, but rather opens the files and overwrites the content with encrypted data. That, allegedly, makes the encryption process faster, and recovery more difficult. 

Disclosing insurance detail is something no one can recommend. Instead, businesses would be better off educating their employees on the dangers of phishing and social engineering, installing a strong firewall and cybersecurity solution, and keeping their backups fresh. 

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A computer being guarded by cybersecurity.
The impact of the cyber insurance industry in resilience against ransomware
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Bad news - businesses who pay ransomware attackers aren’t very likely to get their data back
Image of laptop infected with malware
Ransomware criminals are now sending their demands...by snail mail?
Representational image of a cybercriminal
Should ransomware payments be illegal?
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Less than half of ransomware incidents end in payment - but you should still be on your guard
Hands typing on a keyboard surrounded by security icons
35 years on: The history and evolution of ransomware
Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does