HomeSecurityRansomware groups use virtual machines to "cover up" their attacks

Ransomware groups use virtual machines to "cover up" their attacks

Cybercriminals are increasingly using virtual machines to compromise networks with ransomware. By using virtual machines as part of their attacks, ransomware groups are able to conduct their activity with additional “subtlety” because executing the payload in a virtual environment reduces the chances of the activity being detecteduntil it is too late and the ransomware has encrypted a target device’s files.

During a recent investigation into an attempted ransomware attack , Symantec security researchers found that ransomware "enterprises" are using VirtualBox – a legitimate form of open-source virtual machine software – to run instances of Windows 7, in order to make it easier to install the ransomware.

Read also: Clop ransomware: The gang returns after the arrests of its members

As Symantec pointed out, the ransomware payload “hides” inside a VM while encrypting files on the device.

Ransomware groups virtual machines
Ransomware groups use virtual machines to "cover" their attacks

While a virtual machine runs separately on the machine it is hosted on, it can access the host computer's files and directories through shared folders, which cybercriminals can exploit to allow the payload hosted on the virtual machine to encrypt files on the computer.

While researchers were unable to fully identify the ransomware found running on a virtual machine, the way the malware operated provided strong evidence that the Conti gang was behind it – a notorious form of ransomware used by cybercriminals in several malicious campaigns targeting high-profile targets , including the ransomware attack that hit Ireland's national health service, the HSE

See also: Hackers combine ransomware and DDoS attacks to target victims

However, that wasn't the only activity detected. The researchers found evidence that a malicious actor attempted to run Mount Locker on the host computer. The researchers speculate that the attacker attempted to run Conti via the virtual machine, but when that didn't work, he turned to using Mount Locker.

Ransomware groups virtual machines
Ransomware groups use virtual machines to "cover" their attacks

This is not the first time ransomware groups have been observed using virtual machines to deploy ransomware, but researchers warn that this could make detecting the attacks much more difficult.

Suggestion: Ransomware: Most companies face a second attack if they pay ransom

While cybercriminals could target devices that already have virtual machine environments, in this case they appear to have downloaded the tools that allow them to “run.” Dick O’Brien, director of Symantec’s Threat Hunter Team, pointed out that one way to address this is to monitor and control what software is installed on machines so that potentially malicious, but legitimate, tools cannot be downloaded without approval.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS