Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Bitcoin Is Now a Viable Currency and the Government Is Freaking Out – Featured Bitcoin News bitcoin news
  • Bitcoin Price Resumes Decline, Why BTC Remains At Risk bitcoin news
  • MicroStrategy Will Not Dump Any Of Its Bitcoin, CFO Reveals bitcoin news
  • Bitcoin, Ethereum Down 50% From All-Time Highs — Billions Leave Crypto Economy – Market Updates Bitcoin News bitcoin news
  • Proposed Crypto Mining Ban in Norway Fails to Gain Support in Parliament – Mining Bitcoin News bitcoin news
  • Bitcoin Halving Model Suggests $24,000 Bottom Before Year’s End bitcoin news
  • Internet Service Company Cloudflare to Run Ethereum Validator Nodes as Part of Its Web3 Focus – Bitcoin News bitcoin news
  • BTC Drops Below $29,000 to Start the Weekend – Market Updates Bitcoin News bitcoin news

AvosLocker Ransomware Variant Using New Trick to Disable Antivirus Protection

Posted on May 3, 2022 By root


AvosLocker Ransomware

Cybersecurity researchers have disclosed a new variant of the AvosLocker ransomware that disables antivirus solutions to evade detection after breaching target networks by taking advantage of unpatched security flaws.

“This is the first sample we observed from the U.S. with the capability to disable a defense solution using a legitimate Avast Anti-Rootkit Driver file (asWarPot.sys),” Trend Micro researchers, Christoper Ordonez and Alvin Nieto, said in a Monday analysis.

“In addition, the ransomware is also capable of scanning multiple endpoints for the Log4j vulnerability (Log4shell) using Nmap NSE script.”

AvosLocker, one of the newer ransomware families to fill the vacuum left by REvil, has been linked to a number of attacks that targeted critical infrastructure in the U.S., including financial services and government facilities.

A ransomware-as-a-service (RaaS) affiliate-based group first spotted in July 2021, AvosLocker goes beyond double extortion by auctioning data stolen from victims should the targeted entities refuse to pay the ransom.

Other targeted victims claimed by the ransomware cartel are said to be located in Syria, Saudi Arabia, Germany, Spain, Belgium, Turkey, the U.A.E., the U.K., Canada, China, and Taiwan, according to an advisory released by the U.S. Federal Bureau of Investigation (FBI) in March 2022.

Telemetry data gathered by Trend Micro shows that the food and beverage sector was the most hit industry between July 1, 2021 and February 28, 2022, followed by technology, finance, telecom, and media verticals.

The entry point for the attack is believed to have been facilitated by leveraging an exploit for a remote code execution flaw in Zoho’s ManageEngine ADSelfService Plus software (CVE-2021-40539) to run an HTML application (HTA) hosted on a remote server.

“The HTA executed an obfuscated PowerShell script that contains a shellcode, capable of connecting back to the [command-and-control] server to execute arbitrary commands,” the researchers explained.

CyberSecurity

This includes retrieving an ASPX web shell from the server as well as an installer for the AnyDesk remote desktop software, the latter of which is used to deploy additional tools to scan the local network, terminate security software, and drop the ransomware payload.

Some of the components copied to the infected endpoint are a Nmap script to scan the network for the Log4Shell remote code execution flaw (CVE-2021-44228) and a mass deployment tool called PDQ to deliver a malicious batch script to multiple endpoints.

The batch script, for its part, is equipped with a wide range of capabilities that allows it to disable Windows Update, Windows Defender, and Windows Error Recovery, in addition to preventing safe boot execution of security products, creating a new admin account, and launching the ransomware binary.

Also used is aswArPot.sys, a legitimate Avast anti-rootkit driver, to kill processes associated with different security solutions by weaponizing a now-fixed vulnerability in the driver the Czech company resolved in June 2021.

“The decision to choose the specific rootkit driver file is for its capability to execute in kernel mode (therefore operating at a high privilege),” the researchers pointed out. “This variant is also capable of modifying other details of the installed security solutions, such as disabling the legal notice.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: Chinese Hackers Caught Exploiting Popular Antivirus Products to Target Telecom Sector
Next Post: Former Nintendo President Believes Gaming Experiences Could Benefit From Blockchain And ‘Play to Earn’ Models – News Bitcoin News

Related Posts

  • Hackers Exploiting VMware Horizon to Target South Korea with NukeSped Backdoor cyber security news
  • Google Created ‘Open-Source Maintenance Crew’ to Help Secure Critical Projects cyber security news
  • Google to Add Passwordless Authentication Support to Android and Chrome cyber security news
  • North Korean Hackers Target Journalists with GOLDBACKDOOR Malware cyber security news
  • Critical RCE Bug Reported in dotCMS Content Management Software cyber security news
  • Russian Hackers Targeting Diplomatic Entities in Europe, Americas, and Asia cyber security news

Archives

  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Bank of Russia Steps Up Efforts to Issue Digital Ruble Due to Sanctions – Finance Bitcoin News
  • Sequel to Iconic RPG Ni No Kuni to Feature NFT Integration and Play-to-Earn Mechanics – News Bitcoin News
  • India’s Central Bank RBI to Adopt a ‘Graded Approach’ to Digital Currency Launch – Regulation Bitcoin News
  • Ethereum Slips, What Are The Next Vital Trading Levels For The Coin?
  • We’re Approaching a Recession but It’s ‘Actually a Good Thing’ – Economics Bitcoin News

Recent Comments

No comments to show.
  • Web3 Gaming Company Metatheory Raises $24 Million With Backing From A16z, Pantera, and FTX – Bitcoin News bitcoin news
  • Are You Investing in Securing Your Data in the Cloud? cyber security news
  • [Template] Incident Response for Management Presentation cyber security news
  • 9 out of 10 Central Banks Worldwide Are Exploring Digital Currencies — Driven by Crypto Market – Featured Bitcoin News bitcoin news
  • Leading European and Ukrainian Charity Foundations Announced Their Participation in the World’s First Innovative ChariFi’s Project bitcoin news
  • Terra Beats Tesla As Second-Largest Corporate Bitcoin Holder After $1.5B Purchase bitcoin news
  • North Korean Hackers Target Journalists with GOLDBACKDOOR Malware cyber security news
  • Rich Dad Poor Dad’s Robert Kiyosaki Plans to Buy Bitcoin When the ‘Bottom Is In’ — Says It Could Be at $17K – Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme