{"id":4209,"date":"2022-06-09T17:08:20","date_gmt":"2022-06-09T22:08:20","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=4209"},"modified":"2022-06-09T17:08:21","modified_gmt":"2022-06-09T22:08:21","slug":"dont-let-yourcyanide-steal-your-information","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/dont-let-yourcyanide-steal-your-information\/","title":{"rendered":"Don&#8217;t let YourCyanide steal your information"},"content":{"rendered":"\n<p>Specialists at Trend Micro analyzed a set of CMD-based ransomware samples that appear to have advanced capabilities to steal sensitive information, bypass remote desktop connections, and a feature to spread via physical drives and emails alike called YourCyanide.<\/p>\n\n\n\n<p>Identified as YourCyanide, this new ransomware integrates documents from PasteBin, Discord and Microsoft to hide its payload before the final stage of infection, in addition to employing other obfuscation methods and exploiting variables in each compromised environment. Although the malware is still under development and some of its tasks are still not working as expected, the researchers believe that this variant could evolve into its final form soon.<\/p>\n\n\n\n<p>While YourCyanide and its other variants don&#8217;t currently have as much of an impact as other families, it does represent an interesting upgrade to ransomware kits by bundling a worm, ransomware, and information stealer into a single mid-tier ransomware framework.<\/p>\n\n\n\n<p>The continued use of obfuscated scripts makes it very difficult to identify YourCyanide malicious payloads, which is very favorable for threat actors. Although this is not a completely new technique, the way it is used by the operators of this malware variant makes the obfuscation process much more efficient.<\/p>\n\n\n\n<p>Furthermore, it is very likely that the developers of this malware continually monitor reports like the one prepared by Trend Micro, collecting a lot of critical information to improve the ransomware&#8217;s performance. As mentioned above, the analyzed samples are incomplete versions of YourCyanide, so it is difficult to say with certainty how dangerous its final version will be, so we must be aware of how this threat will evolve.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Identified as YourCyanide this new ransomware integrates documents from PasteBin, Discord and Microsoft which we will talk about today&#8230;.<\/p>\n","protected":false},"author":1,"featured_media":4211,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-4209","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Don&#039;t let YourCyanide steal your information - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Identified as YourCyanide this new ransomware integrates documents from PasteBin, Discord and Microsoft which we will talk about today....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/dont-let-yourcyanide-steal-your-information\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Don&#039;t let YourCyanide steal your information - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Identified as YourCyanide this new ransomware integrates documents from PasteBin, Discord and Microsoft which we will talk about today....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/dont-let-yourcyanide-steal-your-information\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2022-06-09T22:08:20+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-06-09T22:08:21+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/06\/YourCyanide.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"480\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-yourcyanide-steal-your-information\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-yourcyanide-steal-your-information\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Don&#8217;t let YourCyanide steal your information\",\"datePublished\":\"2022-06-09T22:08:20+00:00\",\"dateModified\":\"2022-06-09T22:08:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-yourcyanide-steal-your-information\\\/\"},\"wordCount\":273,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-yourcyanide-steal-your-information\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/YourCyanide.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-yourcyanide-steal-your-information\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-yourcyanide-steal-your-information\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-yourcyanide-steal-your-information\\\/\",\"name\":\"Don't let YourCyanide steal your information - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-yourcyanide-steal-your-information\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-yourcyanide-steal-your-information\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/YourCyanide.jpg\",\"datePublished\":\"2022-06-09T22:08:20+00:00\",\"dateModified\":\"2022-06-09T22:08:21+00:00\",\"description\":\"Identified as YourCyanide this new ransomware integrates documents from PasteBin, Discord and Microsoft which we will talk about today....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-yourcyanide-steal-your-information\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-yourcyanide-steal-your-information\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-yourcyanide-steal-your-information\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/YourCyanide.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/YourCyanide.jpg\",\"width\":800,\"height\":480},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-yourcyanide-steal-your-information\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Don&#8217;t let YourCyanide steal your information\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Don't let YourCyanide steal your information - Truxgo Server Blog","description":"Identified as YourCyanide this new ransomware integrates documents from PasteBin, Discord and Microsoft which we will talk about today....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/dont-let-yourcyanide-steal-your-information\/","og_locale":"es_MX","og_type":"article","og_title":"Don't let YourCyanide steal your information - Truxgo Server Blog","og_description":"Identified as YourCyanide this new ransomware integrates documents from PasteBin, Discord and Microsoft which we will talk about today....","og_url":"https:\/\/truxgoservers.com\/blog\/dont-let-yourcyanide-steal-your-information\/","og_site_name":"Truxgo Server Blog","article_published_time":"2022-06-09T22:08:20+00:00","article_modified_time":"2022-06-09T22:08:21+00:00","og_image":[{"width":800,"height":480,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/06\/YourCyanide.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/dont-let-yourcyanide-steal-your-information\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/dont-let-yourcyanide-steal-your-information\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Don&#8217;t let YourCyanide steal your information","datePublished":"2022-06-09T22:08:20+00:00","dateModified":"2022-06-09T22:08:21+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/dont-let-yourcyanide-steal-your-information\/"},"wordCount":273,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/dont-let-yourcyanide-steal-your-information\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/06\/YourCyanide.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/dont-let-yourcyanide-steal-your-information\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/dont-let-yourcyanide-steal-your-information\/","url":"https:\/\/truxgoservers.com\/blog\/dont-let-yourcyanide-steal-your-information\/","name":"Don't let YourCyanide steal your information - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/dont-let-yourcyanide-steal-your-information\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/dont-let-yourcyanide-steal-your-information\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/06\/YourCyanide.jpg","datePublished":"2022-06-09T22:08:20+00:00","dateModified":"2022-06-09T22:08:21+00:00","description":"Identified as YourCyanide this new ransomware integrates documents from PasteBin, Discord and Microsoft which we will talk about today....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/dont-let-yourcyanide-steal-your-information\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/dont-let-yourcyanide-steal-your-information\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/dont-let-yourcyanide-steal-your-information\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/06\/YourCyanide.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/06\/YourCyanide.jpg","width":800,"height":480},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/dont-let-yourcyanide-steal-your-information\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Don&#8217;t let YourCyanide steal your information"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4209","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=4209"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4209\/revisions"}],"predecessor-version":[{"id":4212,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4209\/revisions\/4212"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/4211"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=4209"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=4209"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=4209"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}