Ransomware

FBI Warns Organizations of Dual Ransomware, Wiper Attacks

The FBI warns organizations of cyberattacks that employ multiple ransomware families or deploy dormant data wipers.

The FBI warns organizations of cyberattacks that employ multiple ransomware families or deploy dormant data wipers.

The FBI is warning organizations of new trends in ransomware attacks, where victims are targeted by multiple file-encrypting malware families or with wipers.

As part of this trend, which was observed in July 2023, the FBI notes in a new private industry notification, threat actors deploy two ransomware variants in close date proximity to one another.

“During these attacks, cyber threat actors deployed two different ransomware variants against victim companies from the following variants: AvosLocker, Diamond, Hive, Karakurt, LockBit, Quantum, and Royal,” the agency notes.

The FBI says it observed different ransomware combinations being deployed in these attacks, leading to a mixture of data encryption, exfiltration, and financial losses associated with ransom payments.

The federal agency also notes that various ransomware attacks observed in 2022 were characterized by custom data theft tools, wipers, and malware, designed to pressure victims to negotiate with the attackers.

“In some cases, new code was added to known data theft tools to prevent detection. In other cases in 2022, malware containing data wipers remained dormant until a set time, then executed to corrupt data in alternating intervals,” the FBI says.

Advertisement. Scroll to continue reading.

Organizations are advised to strengthen their defenses by securing all accounts with strong passwords and implementing phishing-resistant multi-factor authentication, auditing servers and cloud instances for unrecognized accounts, implementing time-based access for administrative accounts, implementing strict policies for remote access, and monitoring all external remote connections.

Furthermore, organizations should implement network segmentation, monitor all network activity and investigate abnormal behaviors, secure and monitor all remote desktop protocol (RDP) connections, use anti malware solutions, implement timely patching mechanisms, disable or restrict unused ports and services, create regular backups and store them securely, and implement recovery plans.

Additionally, the FBI encourages organizations to report all unusual or criminal activity and to establish and maintain a close relationship with local FBI offices, which can help in identifying and remediating vulnerabilities and threats.

Related: CISA, FBI: Ransomware Gang Exploited PaperCut Flaw Against Education Facilities

Related: Critical Infrastructure Organizations Warned of BianLian Ransomware Attacks

Related: New Babuk-Based Ransomware Targeting Organizations in US, Korea

Related Content

Government

The 13 websites purported to be affiliated with consulting companies that advertised job openings for current and former holders of security clearances

Ransomware

The authentication bypass vulnerability allows attackers to establish VPN connections without a valid password.

Ransomware

Focusing on hacking law firms in the US, the ransomware group relies on fast flux to hide its C&C infrastructure.

Cybercrime

The FBI has issued an alert warning of Silent Ransom Group attacks targeting law firms.

Data Breaches

The non-bank lender discovered a ransomware attack nearly one year ago, but only recently completed its investigation.

Data Breaches

The Nitrogen ransomware group claims to have hacked the company’s systems, stealing 8TB of data, including confidential documents.

Data Breaches

The company took systems offline globally after hackers exfiltrated data and deployed file-encrypting ransomware.

Data Breaches

RansomHouse has published several screenshots to demonstrate access to internal Trellix services.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version