Hacker News new | ask | show | jobs
REvil ransomware hits 200 companies in MSP supply-chain attack (bleepingcomputer.com)
16 points by jnichols35 1807 days ago
2 comments

Good tech details here about the attack.

Also interesting "politically charged" Windows Registry keys and password changes:

"For example, a sample [VirusTotal] installed by BleepingComputer adds the HKLM\SOFTWARE\Wow6432Node\BlackLivesMatter key to store configuration information from the attack.

Advanced Intel's Vitali Kremez told BleepingComputer that another sample is configuring the device to launch REvil Safe Mode with a default password of 'DTrump4ever.'"