Archive for Black Fog

MedusaHVNC hijacks browser sessions, bypasses MFA protections

Posted in Commentary with tags on July 28, 2026 by itnerd

In new research, BlackFog’s Darren Williams details how MedusaHVNC gives attackers covert access to live, logged-in browser sessions by opening a legitimate browser on a hidden Windows desktop. Because the activity occurs on the victim’s own device using its existing profile, cookies and session state, the malware can exploit authenticated accounts while remaining invisible to the user.

Jacob Krell, Senior Director, Secure AI Solutions & Cybersecurity, Suzu Labs had this to say:

“MedusaHVNC doesn’t need to steal credentials. It launches a real browser inside a hidden Windows desktop using the victim’s existing profile, so the attacker’s session arrives pre-loaded with every cookie, saved password, and active authentication token the victim already has. Multi-factor authentication (MFA), passkeys, hardware tokens, all of them authenticated that browser before the attacker showed up.

“Most organizations are investing in authentication hardening right now, phishing-resistant MFA, passkey rollouts, conditional access. All of it protects the login. MedusaHVNC operates entirely after the login, where the attacker’s session looks identical to the victim’s, same machine, same IP, same browser fingerprint, same cookies. Token binding and continuous session validation are what cover that gap.

“Hidden Virtual Network Computing (HVNC) used to be one of the hardest malware features to build. MalwareTech documented in 2015 that it essentially required writing your own window manager. MedusaHVNC now sells that capability through a dedicated website and Telegram channel, with an operator panel where you pick a browser from a dropdown and adjust the frame rate. That’s the industrialization of cybercrime compressed into a single feature’s history, a capability that once required deep Windows internals expertise is now a product with customer support.

“The infection chain is a living-off-the-land sequence, wscript.exe to AutoIt to charmap.exe, every binary signed and trusted until the final payload drops. In my experience, living-off-the-land chains evade detection better than custom malware because endpoint detection and response (EDR) flags unknown executables, not trusted ones behaving slightly wrong. Application allowlisting breaks this chain at the first stage. If a workstation doesn’t need wscript.exe or AutoIt, disable them. ‘Ships with Windows’ and ‘needed on this host’ are different questions, and attack surface reduction is how you stop living-off-the-land chains before they reach the payload.”

John Strand, Owner, Black Hills Information Security, Inc. follows with this:

“Browser-based persistence is becoming one of the next major frontiers in cybersecurity. For years, we’ve focused on securing the endpoint, but once malicious activity moves into the browser, visibility becomes much more difficult. Many security vendors intentionally take a hands-off approach to browser activity because of legitimate privacy concerns. A lot of organizations aren’t fully decrypting TLS traffic, let alone inspecting exactly what’s happening inside a user’s browser.

“The reality is that the browser has become the new endpoint. Nearly every business application and cloud service runs through it. Browser-focused attack frameworks have existed for years, but this latest campaign shows they’re becoming more sophisticated. Attackers are shifting away from techniques that target only the operating system and are investing in methods that are harder to detect and much more resilient.”

Organizations need to look at their security in an holistic way. Because only focusing on one area will guarantee that you get pwned.

BlackFog Strengthens Leadership Team with Two Key Appointments 

Posted in Commentary with tags on March 12, 2024 by itnerd

BlackFog, a leader in ransomware protection and anti data exfiltration technology, today announced two key appointments to its leadership team, welcoming Roger Cobb as Senior Vice President Sales and Jonathan Glass, as Vice President of Engineering.  

Cobb brings a wealth of industry experiences in consulting, sales, and security and will be leading the team in driving new business opportunities across North America. A graduate of Colorado State University, he joins BlackFog from HUMAN, where he was Senior Director, Anti Fraud. Prior to his time at HUMAN, he helped to build the channel processes at several IT and security startups including FishNet/Optive Security, Zscaler and Malwarebytes.  

A startup founder himself, Glass will be responsible for growing the engineering team and overseeing product development across different platforms including, desktop, mobile and cloud for BlackFog’s ADX (Anti Data Exfiltration) technology.  

Glass is an experienced developer and software architect and was most recently Senior Director of Engineering at ESO. He brings more than 15 years of experience in leading and growing large engineering teams with agile development processes and holds a Masters in Engineering from Cambridge University. 

BlackFog State of Ransomware Report For August 2023 Is Out

Posted in Commentary with tags on September 6, 2023 by itnerd

BlackFog has today released the State of Ransomware for August 2023. Please feel free to use this report in any news stories, articles or other uses where it will best serve. Additionally, please see below for commentary from Dr. Darren Williams, CEO and Founder, BlackFog:

     “Traditionally a slower month, August this year broke new records and recorded the 2nd highest number of attacks on record with 59 publicly disclosed and 373 non-disclosed attacks. This represents a ratio of 632% between unreported and reported. As with last month the MOVEit exploit continues to generate victims, now totaling 365.

This month also saw some big moves in both the manufacturing and service sectors, with increases of 36% and 31% respectively. While technology, government and education continue to grow with increases of 26%, 23% and 21% respectively.

From a variant perspective, BlackCat and LockBit remain the two dominant variants, each accounting for 17.4% of victims, with Medusa and Play at 5.9% a piece. LockBit dominated in the number of unreported attacks at 35.4%, followed by CLOP at 14.1%.

Data exfiltration affected more than 90% of victims this month and continues to dominate as the primary mechanism for extorting organizations and individuals. China continues to dominate as the main destination for data exfiltration with 39%, with Russia at 9%.”

The State of Ransomware report for August 2023 can be found here: https://privacy.blackfog.com/wp-content/uploads/2023/09/BlackFogRansomwareReport-Aug-2023.pdf

BlackFog Annual State of Ransomware Report For 2022 Is Out

Posted in Commentary with tags on January 18, 2023 by itnerd

BlackFog has today released their 2022 full Annual Ransomware Attack Report. Since 2020 BlackFog has measured publicly disclosed attacks globally. The 2022 ransomware attack report reflects on the key findings from 2022. They have also published a blog discussing the key lessons learned from ransomware in 2022 which expands on the general trends they see going forward. Reading this will give you an idea of what’s likely to come in 2023 based on the attacks of last year.

The full report can be found here: https://www.blackfog.com/wp-content/uploads/2023/01/2022_Ransomware_Report_v2.pdf

The BlackFog State of Ransomware Report December 2022 Report Is Out

Posted in Commentary with tags on January 5, 2023 by itnerd

BlackFog has today released the December 2022 State of Ransomware Report. BlackFog issues a monthly report accounting for cyberattacks within the last month, showing targeted industries and the current active threat groups. 

Key findings for the month of December with perspectives below from Dr. Darren Williams, CEO and Founder, BlackFog:

  • As we say goodbye to 2022, ransomware continued its assault in December with 35 new attacks, the highest in 3 years, and the 4th highest from a record-breaking year.
  • From an industry perspective, Retail and Government saw the biggest increases of 15% and 13% respectively. The government, together with education and healthcare, were the top targets throughout the year, easily outstripping the closest, technology, by more than 30%. This reinforces the trend focusing on industries with the lowest levels of protection and skill shortages.
  • This month we also saw a large increase in attacks using Hive and BlackCat variants with 17% and 16% increases respectively. LockBit, which ended the year as the most effective variant of 2022 ended at 15.7% of all successful attacks.
  • Finally, we ended the year with 87% of all attacks leveraging PowerShell and 89% involving some form of data exfiltration, no surprise given the dramatic shift in attacks focusing almost entirely on data extortion.

Today’s full report can be found here: https://www.blackfog.com/wp-content/uploads/2023/01/BlackFogRansomwareReport-Dec-2022.pdf

Nearly a Third of Cybersecurity Leaders Are Considering Quitting: Black Fog

Posted in Commentary with tags on November 1, 2022 by itnerd

Almost a third (32%) of CISOs or IT Security DMs in the UK and US are considering leaving their current organization, according to new research from BlackFog, released today. Of those considering leaving their current role, a third of those would do so within the next six months. These findings come as demand for cybersecurity talent intensifies, with reports of hard to fill vacancies and skills shortages across UK and US organizations.  

This research, which explored the frustrations and challenges faced by cybersecurity professionals also highlights the impact that cyber incidents have on turnover and job security. It revealed that of those who had been a CISO or IT security leader at a previous organization, two fifths (41%) either left, or were let go, due to an attack or data breach. 

When asked about the aspect of their role that they disliked most, 30% cited the lack of work life balance, with 27% stating that too much time was spent on firefighting rather than focusing on strategic issues.  

However, their role in keeping their organization safe from cyberthreats was clearly valued, with 44% of respondents stating that the most enjoyable aspect of the job is being the company ‘protector’ and having the ability to keep everyone working securely. 

The struggle to keep up with new cyber security approaches 

Escalating cybersecurity threats are driving new innovations to help organizations improve their cybersecurity posture, however, BlackFog’s findings show:

  • More than half, 52%, admitted that they are struggling to keep up to date with new frameworks and models such as Zero Trust.  
  • A further 20% felt that keeping the skill levels of their teams in line with these was a ‘serious challenge’. 
  • 54% also felt that they weren’t able to keep up to date with information on the latest cybersecurity solutions such as anti data exfiltration. 
  • 43% of respondents found it difficult to keep pace with the newest innovations in the cybersecurity market. This number varied by country, with 49% of US respondents agreeing versus 36% in the UK. 

Aligning with Board expectations

There were several key positives reflected in this study, especially in the realm of Board’s expectations for the respondents. BlackFog’s findings show that 3 out of 4 (75%) agree that there is a full alignment between the Board’s expectations of what they can achieve in their role and what they are equipped and able to deliver. In fact, two thirds (64%) of respondents were able to complete their priority tasks within the first six months of their starting date. This may be down to the fact that, on average, 27% of IT spending goes towards the security budget. 

BlackFog June Global Ransomware Report Released

Posted in Commentary with tags on July 5, 2022 by itnerd

BlackFog has today released the latest Monthly Global Ransomware Report. Each month, BlackFog continuously monitors and tracks the latest threats to enterprises, infrastructure and more. Key takeaways from this report include:

  1. They saw a record number of reported attacks in June up from our previous high in February, a 10% total increase.
  2. The most dramatic changes in June saw increases in the attacks on Education, Government and Manufacturing of 33%, 25% and 24% respectively. This reinforces our previous assessment that gangs are more focused on soft targets with a lack of cybersecurity investment and infrastructure.
  3. Attack variants also saw some major changes this month with a renewed focus on Vice Society, BlackCat and Hive with increases of 50%, 30% and 30% respectively.
  4. They also saw a large shift in data exfiltration in June with large increases in exfiltration to Russia and China which now represent 45% of all exfiltration globally.

Dr. Darren Williams, CEO and Founder of BlackFog had this commentary:

     “In June, we recorded 31 publicly disclosed ransomware attacks, the most we’ve seen this year so far. South Africa’s largest supermarket chain made news when they were hit by the RansomHouse criminal gang, and one of Brazil’s largest retail chains, Fast Shop was also hit. The BlackCat gang claimed an attack on the University of Pisa hitting them with a $4.5 million ransom, while Brooks County in Texas admitted to paying their ransom with taxpayer dollars.”

Today’s full report is available here.