In recent weeks, a relatively new ransomware called Avos Locker has been ramping up its attacks while attempting to disable endpoint security products on targeted systems. Sophos Rapid Response discovered that the attackers behind the Avos Locker ransomware were rebooting target computers into Safe Mode to execute the ransomware (a technique that other well-known ransomware groups, such as Snatch, REvil , and BlackMatter,).
See also: Diavol ransomware spreads via email and steals money

But why do criminals do this (Safe Mode)? One of the most important reasons is that many, if not most, security products do not run in Safe Mode. This way, hackers will be able to easily encrypt victims' data , since they will have disabled the security solutions used.
According to researchers, the attackers behind the Avos Locker ransomware also modify the Safe Mode boot configuration so that they can install and use the IT management tool AnyDeskwhile Windows computers are still running in Safe Mode. Normally, third-party software is disabled on a computer that has been booted into Safe Mode, but the attackers want to continue to have remote access and unhindered control over the targeted machines.
Avos Locker ransomware: Encryption in “Safe Mode”
The operators of the Avos Locker ransomware also leverage PDQ Deploy, a legitimate deployment tool, to install multiple Windows batch scripts on the target machine. According to the researchers, this helps them create the right ground for the attack.
These scripts modify or delete Registry keys belonging to specific endpoint security tools, including Windows Defender and products from Kaspersky, Carbon Black, Trend Micro, Symantec, Bitdefender, and Cylance.
The scripts also create a new user account on the compromised machine, which they name “newadmin” and add it to the Administrators user group.
See also: Report: Increase in attacks by ransomware group PYSA, double extortion technique and new tactics

They then configure this account to automatically log in when the system restarts in Safe Mode.
Finally, the scripts execute a reboot command that puts the machine into Safe Mode. Once it is reactivated, the ransomware payload is executed from a Domain Controller location.
If the automated payload execution process fails, the criminal can take control of the process (manually) using AnyDesk.
“The penultimate step in the infection process is the creation of a “RunOnce” key in the Registry that executes the ransomware payload, filelessly,” the researchers explain.
See also: Windows 10 21H2 also gains ransomware protection
Abuse of Safe Mode to bypass security products
Avos Locker's abuse of Safe Mode to bypass security solutions has been used by other well-known ransomware groups, as mentioned above, so this is a security gap that needs to be addressed.
Thanks to this simple but effective trick, even adequately protected machines can become vulnerable to ransomware attacks.
Source: Bleeping Computer
