The Sodinokibi (REvil) ransomware has added a new feature that allows it to encrypt most of a victim's files, even those that are open and locked by another process.
Some applications, such as databases or mail servers, will lock files that are open so that other programs cannot modify them. These “file locks” prevent data from two processes that may be running on a file at the same time.
When a file is locked, this also prevents ransomware from encrypting applications without first terminating the process that is locking the file.
For this reason, many ransomware infections will attempt to shut down database servers, mail servers , and other file-locking applications before encrypting a computer
Sodinokibi automatically terminates processes locking a file
While many ransomware attempts to terminate the most common applications known to lock files, they will not be able to close all of them.
In a new report by cybercrime intelligence firm Intel471, researchers found that Sodinokibi now uses the Windows Restart Manager API to shut down Windows processes or services while keeping a file open during encryption .
This API was created by Microsoft to make it easier to install software updates without performing a reboot on free files that need to be replaced by updates.
“The Restart Manager API can eliminate or reduce the number of system restarts required to complete an installation or update. The primary reason software updates require a system during installation or update is that some of the files being updated at the time are being used by a running application or service. The Restart Manager allows all but critical system services to shut down and restart. This frees up files that are in use and allows the installation operations to complete,” Microsoft in the API documentation.
In addition to using the API when encrypting files, ransomware developers also use it in their decryptor.

As noted by security researcher Vitali Kremez, in REvil Decryptor v2.2, shown above, the Windows Restart Manager API is used to make sure no process is keeping a file open when the decryptor is trying to decrypt it.

Sodinokibi/REvil are not the first ransomware families to use this API in malware , as SamsSam and LockerGoga also use it.
Unfortunately, the use of this API by ransomware infections has both disadvantages and advantages.
It will be easier for victims to decrypt files after paying the ransom, but Sodinokibi will now be able to encrypt more files, especially critical ones.
