A new ransomware called RegretLocker uses a variety of advanced features that allow it to encrypt virtual hard drives and lock open files for encryption.

RegretLocker was discovered in October and is a simple ransomware in terms of its appearance, as it does not contain a ransom note and uses emails to communicate.

When encrypting files, it will append the .mouse.

However, its capabilities are very advanced and not something we usually see in ransomware infections.
RegretLocker mounts virtual hard drives
When creating a Windows Hyper-V, a virtual hard disk is created and stored in a VHD or VHDX file.
These virtual hard disk files contain a raw disk image, including the partition table and partitions, and like regular disk drives, can range in size from a few gigabytes to several terabytes.
When a ransomware encrypts files on a computer, it usually does not choose to encrypt a large file as it slows down the speed of the encryption process.
In a ransomware sample discovered by MalwareHunterTeam and analyzed by Advanced Intel, RegretLocker uses an interesting technique of mounting a virtual disk file so that each of its files can be encrypted individually.
To do this, RegretLocker uses the Windows Virtual Storage API functions OpenVirtualDisk, AttachVirtualDisk, and GetVirtualDiskPhysicalPath to attach/mount virtual disks.

As seen from a debug message in the ransomware, it specifically searches for VHDs and mounts them when detected.

Once the virtual drive is mounted as a physical disk in Windows, the ransomware can encrypt each one individually, which increases the speed of encryption.
The code used by RegretLocker to mount a VHD is believed to have come from a recently published investigation by security researcher smelly__vx.
In addition to using the Virtual Storage API, RegretLocker also uses the Windows Restart Manager API to terminate Windows processes or services that are keeping a file open during encryption .
When using this API, Kremez told BleepingComputer that if a process name contains “vnc,” “ssh,” “mstsc,” “System,” or “svchost.exe,” the ransomware will not terminate it. This exclusion is likely used to prevent the termination of critical programs or those used by the threat actor to access the compromised system.

The Windows Restart Manager feature is only used by a few ransomware such as REvil (Sodinokibi), Ryuk, Conti, ThunderX/Ako, Medusa Locker, SamSam, and LockerGoga.
RegretLocker is not very active at this point, but it is a new “family” to keep an eye on.
