Showing posts with label Group. Show all posts
Showing posts with label Group. Show all posts

Wednesday, September 8, 2021

Hacker Group Reportedly Selling Rootkit That Plants And Hides Malware Within GPUs

Reports of a new rootkit that allows hackers to hide malware within GPU memory are beginning to surface. The most recent news was reported by Bleeping Computers, who allegedly discovered the rootkit being peddled across several of these forums.

Specifically, the hackers were selling a proof-of-technique concept that enables threat actors to store their malicious code within the GPU memory buffer, instead of hiding it within the RAM, as most malware is typically hidden. Doing this enables the malware to stay hidden from antivirus software, as said programs usually do not scan the memory buffer of the GPU.

This isn’t the first time that a malware of such nature has been created either. Six years ago, a hacker group called Team Jellyfish create the world’s first GPU-based malware, aptly named JellyFish. The rootkit was Linux-based and served as the foundation of other GPU-based rootkits that exist on the market.


As for which GPU the rootkit works on, the seller says that it only works on Windows systems supporting Open CL 2.0. In addition, the GPUs that were tested with the rootkit include Intel’s UHD 620 and 630 integrated graphics, NVIDIA’s GeForce GTX 740M, GTX 1650, and AMD’s Radeon RX 5700.

At the time of writing, the code had already been sold and that the seller is preparing a demonstration, in order to show how it works publicly.

Sunday, September 5, 2021

Ragnarok Group Releases Decryption Keys And Quietly Disappears

Ragnarok, the infamous hacker group, has seemingly and quietly gone off into the night. The ransomware group has reportedly shut up shop and, on top of that, released a master decryption key.

Evidence of the group’s disappearance was discovered by several sites, chief among them being BleepingComputer. Specifically, several elements of the site seemed to have been stripped bare of all visuals. If anything, it seems as if the group did not have any plans on shutting down this fast, indicating that something or someone may have reached key members of the group.

Unsurprisingly, any evidence of the threat actors behind the group no longer exists, save except for the aforementioned decryption key.


The good news is that the master key works and unlocks all files that were encrypted by the group’s ransomware, along with a list of its victims, several of which were also victims of its double extortion tactic; on top of encrypting files and demanding a ransom, the group would also steal data that threaten to post it on a “leak” site.

Ragnarok isn’t the first ransomware to have seemingly vanish this year. Darkside, the hacker group that claimed responsibility for both the Colonial Pipeline and Toshiba’s European business, had apologised and quit the scene after the attacks, although the sincerity of such actions is questionable and rightly so.

Xiaomi Shows Off Physical Concept Of Vision Gran Turismo

At the very tail end of last month, Xiaomi unveiled the Vision Gran Turismo. The car was revealed as a digital hypercar, and one that’s made...