Blog
January 12, 2022
2
MIN READ
ColdLock Ransomware

Share this post

TABLE OF CONTENT

The current global remote working movement has become an opportunity for cyber attackers. Security researchers at SISA have been observing a persistent ransomware activity around the world. Now, we found another file-encrypting malware, disrupting enterprises in Taiwan.

ColdLock is a newly identified ransomware strain that reportedly focuses on encrypting databases and email servers of the victim organizations. The malware uses a typical intrusion channels to infect and might have relations to various ill-famed threat groups.

Read SISA’s advisory to get more information on ColdLock ransomware.

The advisory covers complete details about the background, attack patterns, and Indicators of Compromise (IoCs) of ColdLock ransomware. Then, the advisory gives a few security best practices to occlude ColdLock from intruding into Information Systems and encrypt critical data files.

This technical advisory was proposed and researched by Priyanka.D, Security Analyst at SISA’s Synergistic-SOC

Get your copy now!

SHARE THIS POST

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript