New Ransomware Uses Virtual Machine to Launch Attacks

3 years ago 85
BOOK THIS SPACE FOR AD
ARTICLE AD

24. June 2021

This article has been indexed from Softpedia News / Security

Cybercriminals are running more and more malicious payloads via Virtual Machines, according to Symantec Threat Hunter Team.

Help Net Security investigated an attempted ransomware attack that was executed via a VirtualBox Virtual Machine created on some compromised computers. Unlike the documented RagnarLocker attacks using Virtual Machines with Windows XP, the new threat seems to be running Windows 7.

Moreover, according to Dick O’Brien of the Symantec Threat Hunter Team, the VM was deployed via a malicious executable that was pre-installed during the reconnaissance and lateral movement phases of operations. 

So far, the researchers were unable to determine whether the payload in the VM was Mount Locker or Conti ransomware. The later …

Read the original article: New Ransomware Uses Virtual Machine to Launch Attacks

Read Entire Article