Publications

GpCode: update

We’re continuing to get requests from users with files which have been encrypted by GpCode.

The good news is that we’ve sorted the encryption algorithm, and added a decryption routine to the latest antivirus database updates.

If you have files which have been encrypted by GpCode, update your antivirus databases, and scan your machine.Your files will be automatically decrypted.

If you’ve updated your antivirus databases, and your files are still encrypted, please send them to newvirus@kaspersky.com

GpCode: update

Your email address will not be published. Required fields are marked *

 

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Reports

ToddyCat: your hidden email assistant. Part 1

Kaspersky experts analyze the ToddyCat APT attacks targeting corporate email. We examine the new version of TomBerBil, the TCSectorCopy and XstReader tools, and methods for stealing access tokens from Outlook.

Crypto wasted: BlueNoroff’s ghost mirage of funding and jobs

Kaspersky GReAT experts dive deep into the BlueNoroff APT’s GhostCall and GhostHire campaigns. Extensive research detailing multiple malware chains targeting macOS, including a stealer suite, fake Zoom and Microsoft Teams clients and ChatGPT-enhanced images.

Mem3nt0 mori – The Hacking Team is back!

Kaspersky researchers discovered previously unidentified commercial Dante spyware developed by Memento Labs (formerly Hacking Team) and linked it to the ForumTroll APT attacks.