CERT mailing list archives

ACSC Releases Advisory on Mailto Ransomware Incidents


From: "US-CERT" <US-CERT () ncas us-cert gov>
Date: Thu, 06 Feb 2020 14:26:29 -0600

Cybersecurity and Infrastructure Security Agency Logo

National Cyber Awareness System:



ACSC Releases Advisory on Mailto Ransomware Incidents [ 
https://www.us-cert.gov/ncas/current-activity/2020/02/06/acsc-releases-advisory-mailto-ransomware-incidents ] 
02/06/2020 02:13 PM EST 
Original release date: February 6, 2020

The Australian Cyber Security Centre (ACSC) has released an advisory on Mailto ransomware incidents. The ACSC has 
limited information regarding the initial intrusion vector for Mailto, also known as Kazakavkovkiz, but evidence 
suggests that Mailto actors may have used phishing and password spray attacks to comprise user accounts. The ACSC 
provides recommendations for users to detect and mitigate these types of attacks and assist with limiting their spread 
within networks.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the ACSC 
advisory [ https://www.cyber.gov.au/threats/advisory-2020-003-mailto-ransomware-incidents ] on Mailto ransomware 
incidents and CISAs Tip on Protecting Against Ransomware [ https://www.us-cert.gov/ncas/tips/ST19-001 ] for more 
information.



This product is provided subject to this Notification [ https://www.us-cert.gov/privacy/notification ] and this Privacy 
& Use [ https://www.dhs.gov/privacy-policy ] policy.

body { font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight: normal; font-style: normal; color: 
#333333; } ________________________________________________________________________

A copy of this publication is available at www.us-cert.gov [ https://www.us-cert.gov ]. If you need help or have 
questions, please send an email to info () us-cert gov. Do not reply to this message since this email was sent from a 
notification-only address that is not monitored. To ensure you receive future US-CERT products, please add US-CERT () 
ncas us-cert gov to your address book. 

OTHER RESOURCES: Contact Us [ http://www.us-cert.gov/contact-us/ ] | Security Publications [ 
http://www.us-cert.gov/security-publications ] | Alerts and Tips [ http://www.us-cert.gov/ncas ] | Related Resources [ 
http://www.us-cert.gov/related-resources ]  

STAY CONNECTED: Sign up for email updates [ http://public.govdelivery.com/accounts/USDHSUSCERT/subscriber/new ] 


Current thread: