Blog Layout

ChaiChi Malware Is Spreading Ransomware In The Education Sector

sccomputerguys • Jul 03, 2021

If your business has regular dealings with the Education sector of the market, be aware that the PYSA ransomware gang has a new trick up their sleeves.

Recently, they've been using a RAT called ChaChi to create back doors in a wide range of education-oriented organizations and steal data or mass lock files with ransomware then try to extort those organizations.

ChaChi was developed by PYSA sometime in early 2020. When it was first observed in the wild, researchers noted that it was rather crudely designed, lacking any way of hiding from software-based security protocols. They couldn't even do some of the basics, like port forwarding or tunneling.

Unfortunately, the ransomware gang didn't stop at version 1.0. In fact, since it was first spotted, the malware has been in a near constant state of flux, receiving regular updates that have dramatically increased its capabilities.

The ChaChi threat is serious enough that it has even attracted the attention of the FBI. The agency began tracking ChaChi campaigned in March of this year (2020), and has noted a recent increase in the number of PYSA ransomware targets in both the US and the UK.

The gang seems to preferentially target organizations in education and healthcare, and it's not difficult to understand why. Both types of organizations regularly deal with vast amounts of incredibly sensitive data, which has far more value on the Dark Web than a simple collection of credit card numbers.

If you do business in either the education or healthcare spaces, be careful. Especially if the organizations you do business with are using older, legacy systems and/or don't have a robust backup process, you could be placing yourself at risk, as a breach of their system could lead to a breach of your own.

Stay vigilant. ChaChi isn't the only threat out there.

By sccomputerguys 22 Jul, 2022
Do you own one or more of the following products made by Cisco? The RV110W Wireless-N VPN Firewall The RV130 VPN Router The RV130W Wireless-N Multifunction VPN Router The RV215W Wireless-N VPN ...
By sccomputerguys 21 Jul, 2022
Do you use Microsoft Teams?  If so, you'll be thrilled to know that the Redmond Giant is continuing to pour resources into improving the software with a specific focus on audio and ...
By sccomputerguys 20 Jul, 2022
Corporate branding can be worth its weight in gold and certain images are absolutely iconic.  The Golden Arches, the Nike "swoosh," and Apple's Apple all come to mind. Logo images give companies ...
By sccomputerguys 19 Jul, 2022
Remember the Heartbleed scare we had a couple years back?  It was a nasty side-channel attack that was somewhat exotic and difficult to pull off, and it was absolutely devastating and sent ...
By sccomputerguys 18 Jul, 2022
Microsoft Exchange servers are once more in the crosshairs of hackers around the world.  Most recently, hacking groups have been specifically targeting them to deploy BlackCat ransomware. As is common among ransomware ...
By sccomputerguys 16 Jul, 2022
If you grew up in the days before the internet, it's absolutely staggering to think of all the ways that mobile technology has changed our lives (and mostly for the better). Remember ...
By sccomputerguys 15 Jul, 2022
It may seem as though Internet Explorer is the browser that will not die, but according to Microsoft, it is now a step closer to breathing its last virtual breath. Microsoft has ...
By sccomputerguys 14 Jul, 2022
If you're involved with IT Security at any level and if your network includes Linux servers, keep a watchful eye out for the new Panchan botnet. It first appeared in the wilds ...
By sccomputerguys 13 Jul, 2022
These days, companies spend significant sums of money to protect themselves from cyber criminals.  The threat matrix is vast, and attacks can come from almost any quarter. That is why many companies ...
By sccomputerguys 12 Jul, 2022
Do you receive healthcare of any kind from Kaiser Permanente?  If so, be aware that they recently published a data breach notification indicating that an unidentified attacker accessed an email account that ...
More Posts
Share by: