Microsoft

Microsoft confirms new ransomware family deployed via Log4j vulnerability

Did you miss a session from the Future of Work Summit? Head over to our Future of Work Summit on-demand library to stream. Microsoft has become the second security vendor to report it has observed a new family of ransomware, known as Khonsari — which the company said has been used in attacks on non-Microsoft hosted Minecraft…

Did you miss a session from the Future of Work Summit? Head over to our Future of Work Summit on-demand library to stream.


Microsoft has become the second security vendor to report it has observed a new family of ransomware, known as Khonsari — which the company said has been used in attacks on non-Microsoft hosted Minecraft servers by exploiting the vulnerability in Apache Log4j.

In a Wednesday night update to its blog post about the Log4j vulnerability, Microsoft said it can confirm the findings of cyber firm Bitdefender, which earlier this week disclosed the existence of the new Khonsari ransomware family. Bitdefender said it had detected multiple attempts to deploy a Khonsari ransomware payload, which targets Windows systems by taking advantage of a flaw in the Log4j logging library.

The vulnerability, known as Log4Shell, was publicly disclosed last Thursday and is considered highly dangerous, as the flaw is both widespread and considered trivial to exploit.

Attacks on Minecraft servers

In its blog update Wednesday, Microsoft said that it has seen ransomware attacks on Minecraft servers that are not hosted by the company that involves the Khonsari ransomware family.

“Microsoft can confirm public reports of the Khonsari ransomware family being delivered as payload post-exploitation, as discussed by Bitdefender,” the company said in the blog post update.

“In Microsoft Defender Antivirus data, we have observed a small number of cases of this [ransomware] being launched from compromised Minecraft clients connected to modified Minecraft servers running a vulnerable version of Log4j 2 via the use of a third-party Minecraft mods loader,” Microsoft said in the post.

In those cases, the threat actor has sent a malicious message in-game to a vulnerable Minecraft server, and the message then exploits Log4Shell in order to execute a payload both on the server and on any vulner

Read More

Be the first to write a comment.

Leave a Reply

Your email address will not be published. Required fields are marked *

Microsoft

Crypto Miners Surge on US$17.4B Microsoft–Nebius AI Chip Deal

Shares of cryptocurrency mining firms rose sharply on Tuesday following news of a major deal between Nebius Group and Microsoft, valued at US$17.4 billion (AU$26.36 billion). The agreement, running through 2031, will see the Netherlands-based Nebius provide dedicated GPU capacity to Microsoft’s artificial intelligence operations, with the option for expansion up to US$19.4 billion (AU$29.37

Shares of cryptocurrency mining firms rose sharply on Tuesday following news of a major deal between Nebius Group and Microsoft, valued at US$17.4 billion (AU$26.36 billion). The agreement, running through 2031, will see the Netherlands-based Nebius provide dedicated GPU capacity to Microsoft’s artificial intelligence operations, with the option for expansion up to US$19.4 billion (AU$29.37 […]
The post Crypto Miners Surge on US$17.4B Microsoft–Nebius AI Chip Deal appeared first on Crypto News Australia…
Read More

Continue Reading
Microsoft

Google, Microsoft, TikTok Closes 13.6 Million Accounts Over ‘Offensive Content’

ABUJA, Nigeria — The Federal Government of Nigeria has disclosed that 13,597,057 social media accounts were shut down in 2024 for violations ranging from offensive content to breaches of the Code of Practice for Internet platforms. The announcement came in the Code of Practice 2024 Compliance Report…

ABUJA, Nigeria — The Federal Government of Nigeria has disclosed that 13,597,057 social media accounts were shut down in 2024 for violations ranging from offensive content to breaches of the Code of Practice for Internet platforms. The announcement came in the Code of Practice 2024 Compliance Report…
Read More

Continue Reading
Microsoft

ASUS Teases Another ‘Extraordinary’ Xbox Reveal For Gamescom 2025

From material to a new form of power.”.We already know that ASUS and Microsoft will be having a lot more to say about the ROG Xbox Ally handheld as part of the Gamescom festivities next week, but apparently we’re also getting another major Xbox reveal from ASUS!This has been teased as part of a short

From material to a new form of power.”.We already know that ASUS and Microsoft will be having a lot more to say about the ROG Xbox Ally handheld as part of the Gamescom festivities next week, but apparently we’re also getting another major Xbox reveal from ASUS!This has been teased as part of a short social media video today…
Read More

Continue Reading
Microsoft

Talking Point: Is Forza Horizon About To Become Xbox’s Main Forza Franchise?

The future of Motorsport is in doubt.Last week, some of the Xbox community started taking note of how quiet Forza Motorsport had been on social media since Microsoft’s recent layoffs, which the Xbox developer swiftly responded to with reassurances that both Forza Motorsport and Forza Horizon 5 are still being supported by the team…

The future of Motorsport is in doubt.Last week, some of the Xbox community started taking note of how quiet Forza Motorsport had been on social media since Microsoft’s recent layoffs, which the Xbox developer swiftly responded to with reassurances that both Forza Motorsport and Forza Horizon 5 are still being supported by the team…
Read More

Continue Reading