Vice Society Ransomware Abuses the PrintNightmare Vulnerability to Spread Laterally

Discoveries of new vulnerabilities in popular software packages, operating systems, and services are usually followed by large-scale malware attacks. In recent weeks, cybersecurity companies have been informing users about the PrintNightmare vulnerability. This particular security hole affects several Windows features related to printing – Print Spooler, Print Drivers, and the Point and Print feature. Successful exploitation of this vulnerability enables attackers to spread laterally through a network. Needless to say, ransomware gangs are among the first to exploit it, with the Vice Society Ransomware leading the charge.

Vice Society Ransomware Gang Switches to Exploiting PrintNightmare

The latest gang to take advantage of this vulnerability is using the Vice Society Ransomware. This new file-encryption Trojan was first seen in July. It appears to be a variant of the HelloKitty Ransomware / FiveHands Ransomware. The threat affects both Windows and Linux systems. Of course, the Windows version is more widespread, and its activity is currently ramping up because of the use of the PrintNightmare vulnerability. Regardless of the operating system that the Vice Society Ransomware infects, its attack does not change much. It encrypts data, wipes out backups, and delivers a ransom note.

The primary targets of the Vice Society Ransomware are small and medium-sized businesses or organizations. They seem to prioritize institutions involved in the educational sector. The ransomware gang makes use of two types of extortion:

  • They offer to decrypt the victim's files in exchange for a ransom payment.
  • They claim to have stolen files from the system and threaten to publish them online if the victim does not pay.

Recovering from this Ransomware is a Challenge

In the world of ransomware attacks, being one of the first gangs to weaponize the latest vulnerability can be a very lucrative opportunity. This is most likely the primary motivation of the Vice Society Ransomware gang. The criminals are currently running a data leak site, but so far, no data has been published there. We are yet to see if they are serious about leaking data stolen from their victims.

Unfortunately, recovering from the Vice Society Ransomware is not easy. This ransomware uses a flawless file-locking mechanism, and free tools cannot reverse it. The best option for its victims is to restore their files from a backup if this option is available. Negotiating with the criminals is not advisable, despite the threats they make. Even if you end up complying with their requests, you may end up empty-handed.

August 16, 2021
Loading...

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.