Researchers from Deep Instinctrecently discovered a new strain of Snake ransomwarethat isolates the systems it has infected so that it can encrypt their files without interference.

January saw a new wave of attacks targeting primarily corporate organizations. SentinelOne also discovered that the Snake Ransomware targets processes and files related to industrial control systems (ICS).
The creators of the ransomwaretook no action when the coronavirus began to spread, but on May 4 they launched a new operation against major companies around the world.
As expected, some of the victims of the Snake Ransomware include Fresenius Group, the largest hospital services provider in Europe, as well as Japanese automaker Honda.
Snake ransomware works by stopping certain processes, including those related to ICS, to encrypt the relevant files.
However, in the most recent ransomware samples, the ability to enable and disable firewalls has been observed, as well as the exploitation of certain commands so that connections to the system.
“Before starting the encryption, Snake will use the Windows Firewall to block any incoming and outgoing network connections to the victim machine that are not configured in the firewall. The built-in Windows netsh tool will be used for this purpose,” Deep Instinct reports in its research . “Disconnected from the outside world, Snake will then stop processes that may affect the encryption. The list contains processes related to ICS and several security and backup solutions.”

The ransomware stops any process that could affect the encryption, including those related to industrial software, backup solutions, and of course security. The malware then also deletes shadow copies, thus preventing the possibility of recovering files.
Once it manages to complete these actions, it then begins the encryption process. The files it targets are mainly critical folders, as well as databases, documents, extension files, etc.
The malware adds a random five-character string to the extension of encrypted files and the word EKANS at the end of the file.
Although the basic scenario of ransomware is to encrypt important files and demand a ransom to restore them, the methods used and their creators continue to evolve over time.
