Between 2022 and 2025, McKenzie Health System, which operates the McKenzie Memorial Hospital in rural Michigan, was hit by two major data breaches. Combined, the attacks compromised the personal and medical information of more than 79,000 patients.

https://www.suspectfile.com/two-data-breaches-in-three-years-the-mckenzie-health-system-case/

#AvosLocker #Data_Breach #McKenzie_Health_System #McKenzie_Memorial_Hospital #PHI #PII #Ransomware #Infosec

OK, I confess: I do not understand why CISA / #StopRansomware did an update on #AvosLocker based on what they saw up to May. AvosLocker's leak site went silent in May, he hasn't been on his Jabber since May, and I got no response from him on Tox since May. So is AvosLocker still active? Anyone seen evidence of new victims or anything since May? Ransomlook.io doesn't show anything since that time, either.

@allan @brett @BleepingComputer

#ransomware #infosec

A distinguishing feature of AvosLocker attacks is their reliance on open-source tools and living-off-the-land (LotL) tactics, leaving minimal traces for attribution.

#CISA #Cybersecurity #FBI #AvosLocker #Ransomware #Cyberthreat #CriticalInfrastructure

https://cybersec84.wordpress.com/2023/10/13/avoslocker-ransomware-cisafbi-warn-of-rising-attacks-on-critical-infrastructure/

AvosLocker Ransomware: CISA,FBI Warn of Rising Attacks on Critical Infrastructure

The AvosLocker ransomware group has been associated with attacks on critical infrastructure sectors in the United States, some of which were detected as recently as May 2023. This information comes…

CyberSec84 | Cybersecurity news.
FBI and CISA published a new advisory on AvosLocker ransomware

FBI and CISA published a joint Cybersecurity Advisory to disseminate IOCs, TTPs, and detection methods associated with AvosLocker ransomware

Security Affairs

Avoslocker #ransomware group again added Bluefield University (bluefield.edu) to their victim list. They claims to publish the organizations data in 19 hours and the alleged data is 1.2TB in size which contains admissions details, Financial Aid applications, Transcripts, etc.

#USA
#Avoslocker #DarkWeb #DataBreach #cyberrisk

🔒 Souvenez-vous, c'était le 13 septembre 2022 au matin. Les étudiants des écoles de Toulouse INP - Institut National Polytechnique de Toulouse étaient accueillis par un message les informant de la survenue d'une #cyberattaque. On apprend ce matin, plusieurs mois plus tard, que la #ransomware appelé #AvosLocker était impliqué. C'est à lire après le clic 👇
https://www.lemagit.fr/actualites/252524874/Cyberattaque-dampleur-a-linstitut-national-polytechnique-de-Toulouse
Ransomware : en septembre 2022, Toulouse INP a été frappé avec AvosLocker

Toulouse INP fait encore face aux suites d'une cyberattaque avec rançongiciel découverte le lundi 12 septembre à 21h, heure à laquelle le chiffrement a été déclenché. Le rançongiciel impliqué était AvosLocker. La cyberattaque n'a pas été revendiquée à ce jour.

LeMagIT.fr

#AvosLocker has listed Pembina County Memorial Hospital while Royal has listed Clarke County Hospital. #PCMH #CCH #ransomware

@PogoWasRight

#AvosLocker has listed #VMedia, which offers internet and streaming services in multiple Canadian provinces. #ransomware

My latest blog: Decoding a New JavaScript Malware Campaign!
🔗​ https://www.th3protocol.com/2023/New-JS-Malware-Fake-Invoices

Earlier today researchers from HuntressLabs shared observations about a #AvosLocker case involving RClone. They identified initial access as a javascript file named “Invoice-DocuSign-Mar03-2023.js"

In my blog post I walk through analyzing this JavaScript malware, identifying persistency and decoding C2 traffic!
#IOCs: https://github.com/colincowie/colincowie.github.io/blob/master/assets/iocs/js_avoslocker/file_iocs.csv

🔗​ poc for decoding the C2 traffic:
https://gist.github.com/colincowie/2bb637259c38e1c6da3f2464ec92ed0e

💬​ Authors Note:
Recently I've been feeling a little bit burnt out - this research excited me and provided some internal encouragement 😃

#ThreatIntel #CTI #Malware #Ransomware #JavaScript #VirusTotal​​

New JavaScript Malware - Fake DocuSign Invoices

AvosLocker looks to be taking a more active stance in purchasing access. They've moved from bidding in single auctions to listing a purchase offer for any valid privileged RDP/VPN/Citrix/RDWeb/Pulse Security access. #ThreatIntelligence #ThreatIntel #CTI #Ransomware #AvosLocker #CTITuesday