{"id":17471,"date":"2020-06-08T09:06:45","date_gmt":"2020-06-08T13:06:45","guid":{"rendered":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/?p=17471"},"modified":"2022-10-14T18:26:44","modified_gmt":"2022-10-14T22:26:44","slug":"two-more-universities-hit-with-netwalker-ransomware","status":"publish","type":"post","link":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/security\/two-more-universities-hit-with-netwalker-ransomware.html","title":{"rendered":"Two More Universities Hit with NetWalker Ransomware"},"content":{"rendered":"\n<p>As we have written in the past \u2013 ransomware has become <a href=\"http:\/\/www.apextechservices.com\/topics\/articles\/444313-ransomware-now-extortionware.htm\">Extortionware<\/a> and most recently has an <a href=\"v\">affiliate program<\/a>. NetWalker ransomware has generous payouts allowing an affiliate to earn more than a million dollars if they can infect a large organization. Recently, Michigan State University was <a href=\"https:\/\/www.apextechservices.com\/topics\/articles\/445556-michigan-state-university-hacked-likely-the-new-ransomware.htm\">hacked<\/a> with this Extortionware. In addition, University of California San Francisco (UCSF) and Columbia College Chicago have been infected. Columbia was founded in 1890, it has around six-thousand students and can cost $45,644 per year to attend before financial aid. Many of the degrees are entertainment related such as Acoustics, Arts management and Audio Arts.<\/p>\n\n\n\n<p>The latter two colleges are said to have <a href=\"https:\/\/columbiachronicle.com\/breaking-columbia-student-information-at-risk-in-ransomware-attack\">paid<\/a>\nthe ransom before information was leaked on the internet but it is now owned by\nthe hackers and it is unknown if it could be used to extort from them in the\nfuture. It is also unknown if information contained in the stolen information\ncan or will be used to extort from others.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.msspalert.com\/cybersecurity-breaches-and-attacks\/ransomware\/netwalker-hits-columbia-college-chicago\/?utm_medium=email&amp;utm_source=sendpress&amp;utm_campaign\">NetWalker<\/a>\nwas discovered in August 2019 by&nbsp;<a href=\"https:\/\/id-ransomware.malwarehunterteam.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">ID\nRansomware<\/a>, according to&nbsp;<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/mailto-netwalker-ransomware-targets-enterprise-networks\/\" target=\"_blank\" rel=\"noreferrer noopener\">BleepingComputer<\/a>. It was initially named Mailto based on\nthe extension that was appended to encrypted files, but ransomware recovery\ncompany&nbsp;<a href=\"https:\/\/www.coveware.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Coveware<\/a>&nbsp;later\ndiscovered a decryptor for the ransomware that indicated that the developer\u2019s\nname for the infection was NetWalker.<\/p>\n\n\n\n<p>NetWalker compromises networks and encrypts all Windows devices connected to them, BleepingComputer indicated. When executed, NetWalker uses an embedded configuration that includes a ransom note template, ransom note file names and various configuration options.<\/p>\n\n\n\n<p>To keep your organization secure be sure to schedule regular <a href=\"https:\/\/www.apextechservices.com\/cybersecurity\/\">cybersecurity assessments<\/a>. <\/p>\n\n\n\n<p><strong>See the ONLY cybersecurity companies that&nbsp;<a href=\"https:\/\/www.itexpo.com\/east\/exhibitor-list.aspx\">matter&nbsp;<\/a>at the&nbsp;<\/strong><a href=\"http:\/\/www.itexpo.com\/\"><strong>ITEXPO<\/strong><\/a><strong>&nbsp;#TECHSUPERSHOW<\/strong>. Watch the video below for more.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>This Event has been&nbsp;<a href=\"https:\/\/www.itexpo.com\/east\/testimonials.aspx\">called the&nbsp;<strong>BEST SHOW in 5 YEARS<\/strong>&nbsp;and the&nbsp;<strong>Best TECHNOLOGY EVENT of 2020<\/strong><\/a>.<\/p><\/blockquote>\n\n\n\n<p>2020 participants included: Amazon, Cisco, Google, IBM, ClearlyIP, Avaya, Vonage, 8\u00d78, Comcast Business, BlueJeans, CoreDial, Dell, Edify, Epygi, FreeSWITCH, Grandstream, Granite,&nbsp;Intrado, Frontier Business, Fujitsu, Jenne, West, Konftel, Intelisys, Martello, NetSapiens, OOMA, Oracle, OpenVox, Peerless Network, Phone Sentry, Phone.com, Poly, QuestBlue, RingByName, Sangoma, SingTel, SkySwitch, Spracht, Spectrum, Sprint, Tallac, Tech Data, Telarus, TCG, Teledynamics, Teli, Telinta, Telispire, Telstra, TransNexus, Unified Office, Vital PBX, VoIP Supply, Voxbone, VoIP.MS, Windstream, XCALY, XORCOM, Yealink, Yubox, and ZYCOO.&nbsp;<a href=\"https:\/\/www.itexpo.com\/east\/exhibitor-list.aspx\"><strong>Full List.<\/strong><\/a><\/p>\n\n\n\n<p><strong>Join 8K others with $25B+ in IT buying power who plan 2021 budgets! Including 3,500+ resellers!<\/strong><\/p>\n\n\n\n<p>A unique experience with a collocated&nbsp;<a href=\"http:\/\/www.futureofworkexpo.com\/\">Future of Work Expo<\/a>,&nbsp;<a href=\"http:\/\/www.sdwanexpo.com\/\">SD-WAN Expo<\/a>,&nbsp;and&nbsp;<a href=\"http:\/\/www.mspexpo.com\/\">MSP Expo<\/a>\u2026<\/p>\n\n\n\n<p>June 22-25, 2021, Miami\u00a0<a href=\"https:\/\/www.itexpo.com\/east\/registration.aspx\">Register now<\/a>\u00a0and you could win a Tesla on Feb 12th.<\/p>\n\n\n\n<figure class=\"wp-block-embed-youtube wp-block-embed is-type-video is-provider-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"ITEXPO 2020 Intro 2\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/sZ8nZlOb5Hg?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>As we have written in the past \u2013 ransomware has become Extortionware and most recently has an affiliate program. NetWalker ransomware has generous payouts allowing an affiliate to earn more than a million dollars if they can infect a large organization. Recently, Michigan State University was hacked with this Extortionware. In addition, University of California<\/p>\n","protected":false},"author":44,"featured_media":17472,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[156],"tags":[1796,2875,1839],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/posts\/17471"}],"collection":[{"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/users\/44"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/comments?post=17471"}],"version-history":[{"count":1,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/posts\/17471\/revisions"}],"predecessor-version":[{"id":17473,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/posts\/17471\/revisions\/17473"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/media\/17472"}],"wp:attachment":[{"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/media?parent=17471"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/categories?post=17471"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/tags?post=17471"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}