Vulnerabilities in corporate networks are often exploited by malicious actors to gain access to them. However, a researcher's findings overturn this scenario, as bugs appear to exist in even the most common ransomware.
See also: The REvil ransomware group is back with a vengeance

As it turned out, ransomware such as Conti, REvil, Black Basta, LockBit, and AvosLocker had bugs that could be exploited to stop the final and most damaging step of the attack, file encryption.
Analyzing malware strains from these ransomware gangs, a security researcher named hyp3rlinxfound that the samples were vulnerable to DLL hijacking, a method commonly used by attackers to inject malicious code into a legitimate application.
For each piece of malware he analyzed, the researcher provides a report describing the type of vulnerability he discovered, the sample's hash, a PoC, and a demonstration video.
DLL hijacking only works on Windows and exploits the way applications search for and load the DLL files they need into memory.
A program with insufficient checks can load a DLL from a path outside its directory, elevating privileges or executing unwanted code.
In the ransomware samples from Conti, REvil, LockBit, Black Basta, LockiLocker, and AvosLocker that the researcher examined, bugs allow code execution to "control and terminate the pre-encryption of the malware."
See also: Ransom demands account for 15% of the total cost of ransomware attacks

In order to exploit the bugs in the malicious software from the aforementioned gangs, the researcher created exploit code that must be compiled into a DLL with a specific name, so that the malicious code recognizes it as its own and loads it to start encrypting the data.
To protect networks from these ransomware families, hyp3rlinx says the DLL can be placed in a location where cybercriminals are likely to execute their ransomware, such as a network location with important data. Once the DLL exploit is loaded, the ransomware process should be terminated before the data encryption operation can begin.
The researcher notes that, while malware can terminate security solutions on the compromised machine, it cannot do anything against DLLs, as they are merely files stored on the host computer's disk, inert until they are loaded.
It is not clear which ransomware malware versions were found to be vulnerable to DLL hijacking.
If the samples are new, it is possible that the exploit will only work for a short time, as ransomware gangs are quick to patch bugs, especially when they are publicly presented.
See also: Malware Bumblebee: Takes on the Delivery of BazarLoader Ransomware
Even if these findings prove to be viable for a little longer, the companies targeted by ransomware gangs still face the risk of theft and leakage of critical files, as the intrusion to pressure the victim into paying ransom is part of their modus operandi.
However, the exploits discovered by hyp3rlinx could prove useful at least for preventing operational downtime, which could cause significant damage.
