BOOK THIS SPACE FOR AD
ARTICLE AD24. June 2021
This article has been indexed from Softpedia News / Security
Cybercriminals are running more and more malicious payloads via Virtual Machines, according to Symantec Threat Hunter Team.
Help Net Security investigated an attempted ransomware attack that was executed via a VirtualBox Virtual Machine created on some compromised computers. Unlike the documented RagnarLocker attacks using Virtual Machines with Windows XP, the new threat seems to be running Windows 7.
Moreover, according to Dick O’Brien of the Symantec Threat Hunter Team, the VM was deployed via a malicious executable that was pre-installed during the reconnaissance and lateral movement phases of operations.
So far, the researchers were unable to determine whether the payload in the VM was Mount Locker or Conti ransomware. The later …