{"id":354138,"date":"2022-08-31T22:26:21","date_gmt":"2022-08-31T20:26:21","guid":{"rendered":"https:\/\/www.pcnen.com\/portal\/?p=354138"},"modified":"2022-08-31T22:26:21","modified_gmt":"2022-08-31T20:26:21","slug":"cuba-ransomware-vec-duze-vrijeme-pod-lupom-fbi","status":"publish","type":"post","link":"https:\/\/www.pcnen.com\/portal\/2022\/08\/31\/cuba-ransomware-vec-duze-vrijeme-pod-lupom-fbi\/","title":{"rendered":"\u2018Cuba ransomware\u2019 ve\u0107 du\u017ee vrijeme pod lupom FBI"},"content":{"rendered":"<p>O tome svjedo\u010di izvje\u0161taj FBI koji je objavljen u decembru pro\u0161le godine, a gdje se navodi da su ameri\u010dki istra\u017eitelji identifikovali od po\u010detka novembra 2021. da su akteri &#8220;Cuba ransomware&#8221; kompromitovali najmanje 49 subjekata u pet kriti\u010dnih infrastrukturnih sektora, uklju\u010duju\u0107i, ali ne ograni\u010davaju\u0107i se, na sektor finansija, uprave, zdravstva, proizvodnje i informacionih tehnologija.<\/p>\n<p>Kako se navodi u dokumentu, &#8220;Cuba ransomware&#8221; se distribuira preko Hancitor malvera, u\u010ditava\u010da poznatog po tome \u0161to na mre\u017ee \u017ertava ispu\u0161ta kradljivce, kao \u0161to su trojanci za daljinski pristup (RAT) i druge vrste ransomvera, prenosi RTCG.<\/p>\n<p>Akteri zlonamjernog softvera Hancitor koriste &#8220;pecanje mejlova&#8221;, ranjivosti Microsoft Exchange, kompromitovane akreditive ili legitimne alate protokola za udaljenu radnu povr\u0161inu (RDP) da bi dobili po\u010detni pristup mre\u017ei \u017ertve.<\/p>\n<p>Nakon toga, akteri &#8220;Cuba ransomware&#8221; koriste legitimne Windows usluge \u2014 kao \u0161to su PowerShell, PsExec, i druge nespecificirane usluge \u2014 a zatim koriste privilegije Windows administratora da bi svoj ransomvare i druge procese izvr\u0161avali na daljinu.<\/p>\n<p>Akteri &#8220;Cuba ransomware&#8221; kompromituju mre\u017eu \u017ertava kroz \u0161ifrovanje ciljnih datoteka sa ekstenzijom \u201e.cuba\u201c.<\/p>\n<p>&#8220;Cuba ransomware&#8221; je tra\u017eila najmanje 74 miliona dolara i primila najmanje 43,9 miliona dolara kao otkupninu&#8221;, pi\u0161e u dokumentu FBI.<\/p>\n<p>Ministar javne uprave Mara\u0161 Dukaj potvrdio je u Dnevniku TVCG da iza sajber napada na infrastrukturu Crne Gore stoji prepoznata kriminalna grupa &#8220;Cuba ransomware&#8221;.<\/p>\n<p>&nbsp;<\/p>\n<blockquote class=\"wp-embedded-content\" data-secret=\"QBttDXFkde\"><p><a href=\"https:\/\/www.pcnen.com\/portal\/2022\/08\/31\/hakerska-grupa-kuba-ransomver-tvrdi-da-ima-podatke-iz-skupstine-cg\/\">Hakerska grupa \u2018Kuba ransomver\u2019 tvrdi da ima podatke iz Skup\u0161tine CG \u00a0<\/a><\/p><\/blockquote>\n<p><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;Hakerska grupa \u2018Kuba ransomver\u2019 tvrdi da ima podatke iz Skup\u0161tine CG \u00a0&#8221; &#8212; PCNEN\" src=\"https:\/\/www.pcnen.com\/portal\/2022\/08\/31\/hakerska-grupa-kuba-ransomver-tvrdi-da-ima-podatke-iz-skupstine-cg\/embed\/#?secret=7vWMa76RtH#?secret=QBttDXFkde\" data-secret=\"QBttDXFkde\" width=\"600\" height=\"338\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kriminalna grupa &#8220;Cuba ransomware&#8221; koju je ve\u010deras u Dnevniku TVCG ministar javne uprave Mara\u0161 Dukaj pomenuo kao odgovornu za sajber napade na infrastrukturu Crne Gore, ve\u0107 du\u017ee je pod lupom ameri\u010dkog Federalnog istra\u017enog biroa (FBI).<\/p>\n","protected":false},"author":1,"featured_media":354139,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","inline_featured_image":false,"footnotes":""},"categories":[14],"tags":[],"class_list":["post-354138","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-vijesti"],"_links":{"self":[{"href":"https:\/\/www.pcnen.com\/portal\/wp-json\/wp\/v2\/posts\/354138","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.pcnen.com\/portal\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.pcnen.com\/portal\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.pcnen.com\/portal\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.pcnen.com\/portal\/wp-json\/wp\/v2\/comments?post=354138"}],"version-history":[{"count":1,"href":"https:\/\/www.pcnen.com\/portal\/wp-json\/wp\/v2\/posts\/354138\/revisions"}],"predecessor-version":[{"id":354140,"href":"https:\/\/www.pcnen.com\/portal\/wp-json\/wp\/v2\/posts\/354138\/revisions\/354140"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.pcnen.com\/portal\/wp-json\/wp\/v2\/media\/354139"}],"wp:attachment":[{"href":"https:\/\/www.pcnen.com\/portal\/wp-json\/wp\/v2\/media?parent=354138"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.pcnen.com\/portal\/wp-json\/wp\/v2\/categories?post=354138"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.pcnen.com\/portal\/wp-json\/wp\/v2\/tags?post=354138"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}