{"id":33222,"date":"2020-03-18T03:13:00","date_gmt":"2020-03-18T07:13:00","guid":{"rendered":"http:\/\/blog.cybercon1.com\/?p=33222"},"modified":"2020-03-18T03:13:00","modified_gmt":"2020-03-18T07:13:00","slug":"beware-of-this-new-windows-10-ransomware-threat-hiding-in-plain-sight","status":"publish","type":"post","link":"https:\/\/blog.cyberconservices.com\/index.php\/2020\/03\/18\/beware-of-this-new-windows-10-ransomware-threat-hiding-in-plain-sight\/","title":{"rendered":"Beware Of This New Windows 10 Ransomware Threat Hiding In Plain Sight"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">By <a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/\">Davey Winder<\/a> &#8211; Windows users have become accustomed to warnings related to system updates, like the recent report of a threat campaign that specifically\u00a0<a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2020\/02\/29\/windows-10-users-warned-as-hackers-target-newly-updated-computers\/\">targets newly updated Windows 10 systems<\/a>, for example. Now, as picked up by the folk over at\u00a0<a rel=\"noreferrer noopener\" href=\"https:\/\/www.bleepingcomputer.com\/\" target=\"_blank\">Bleeping Computer<\/a>, it seems that threat actors are using Windows Explorer as part of their ransomware attack process.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignleft size-large is-resized\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/cdn.pixabay.com\/photo\/2016\/07\/22\/20\/51\/windows-10-1535765__340.jpg?resize=408%2C255&#038;ssl=1\" alt=\"\" width=\"408\" height=\"255\"\/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">A strain of the Mailto (NetWalker) ransomware can inject malicious code right into Windows Explorer, researchers at security solutions company Quick Heal discovered. By using a technique of &#8220;process hollowing&#8221; to achieve this process code injection, the ransomware actors hope to evade detection. Process hollowing is a defense evasion technique, unmapping memory of a suspended state process and replacing it with malicious code, that is effective against whitelisting and signature-based detection. Except that the researchers found that instead of creating the process in suspended mode, the NetWalker actors are using debug mode instead. All of which is bad news, as NetWalker is as nasty as it is sophisticated, targeting both home and business Windows users alike. After the ransomware runs its encryption routines, &#8220;explorer.exe kills the parent process and deletes the original sample,&#8221; the file that has been dropped as well the RUN entry,&nbsp;<a href=\"https:\/\/blogs.quickheal.com\/mailto-ransomware-hiding-under-explorer-exe\/\" target=\"_blank\" rel=\"noreferrer noopener\">the researchers said<\/a>, &#8220;eradicating the traces of its existence.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The recently published FBI Internet Crime Complaint Center (IC3) &#8220;<a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2020\/02\/13\/the-fbi-issues-a-powerful-35-billion-cybercrime-warning\/\">Internet Crime Report<\/a>&#8221; revealed that reported cybercrime had cost individuals and businesses a staggering $3.5 billion (\u00a32.7 billion) in 2019. The FBI has been warning anyone who will listen about\u00a0<a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2019\/10\/03\/fbi-issues-high-impact-cyber-attack-warningwhat-you-need-to-know\/\">the high-impact nature of ransomware<\/a>\u00a0for months now, yet still we see incidents such as the City of New Orleans which\u00a0<a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2019\/12\/14\/new-orleans-declares-state-of-emergency-following-cyber-attack\/\">declared a state of emergency<\/a>\u00a0following such an attack and London-based\u00a0<a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2020\/01\/11\/air-travel-cyber-attacks-new-york-airport-hit-travelex-exchange-held-to-ransom\/\">global foreign currency exchange Travelex suffering massive business disruption<\/a>\u00a0courtesy of ransomware actors. That FBI IC3 report showed that ransomware losses were up from $2.4 million (\u00a31.85 million) in 2016 to $8.9 million (\u00a36.8 million) last year.  <a href=\"https:\/\/www.google.com\/url?rct=j&amp;sa=t&amp;url=https:\/\/www.forbes.com\/sites\/daveywinder\/2020\/03\/05\/beware-of-this-new-windows-10-ransomware-threat-hiding-in-plain-sight\/&amp;ct=ga&amp;cd=CAEYASoTODYzNTQ3NzExNzM3MzY2MDU1MDIaZjk1ZDdkNTc3NTkyZGUyMTpjb206ZW46VVM&amp;usg=AFQjCNHH9L-Yl2lYxv337lvLJdlQWsetUw\">Read On:<\/a><\/p>\n\n\n\n<iframe style=\"width:120px;height:240px;\" align=\"right\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\" frameborder=\"0\" src=\"\/\/ws-na.amazon-adsystem.com\/widgets\/q?ServiceVersion=20070822&#038;OneJS=1&#038;Operation=GetAdHtml&#038;MarketPlace=US&#038;source=ss&#038;ref=as_ss_li_til&#038;ad_type=product_link&#038;tracking_id=cyberconservi-20&#038;language=en_US&#038;marketplace=amazon&#038;region=US&#038;placement=B00E7O0L3G&#038;asins=B00E7O0L3G&#038;linkId=43aa15dd57990a8b534957e5a4e5c802&#038;show_border=true&#038;link_opens_in_new_window=true\"><\/iframe>\n","protected":false},"excerpt":{"rendered":"<p>By Davey Winder &#8211; Windows users have become accustomed to warnings related to system updates, like the recent report of a threat campaign that specifically\u00a0targets newly updated Windows 10 systems, for example. Now, as picked up by the folk over <span class=\"excerpt-dots\">&hellip;<\/span> <a class=\"more-link\" href=\"https:\/\/blog.cyberconservices.com\/index.php\/2020\/03\/18\/beware-of-this-new-windows-10-ransomware-threat-hiding-in-plain-sight\/\"><span class=\"more-msg\">Continue reading &rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_seo_schema_type":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[636],"tags":[637],"class_list":["post-33222","post","type-post","status-publish","format-standard","hentry","category-ransomware","tag-ransomware"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack-related-posts":[{"id":34384,"url":"https:\/\/blog.cyberconservices.com\/index.php\/2020\/06\/16\/new-tycoon-ransomware-strain-targets-windows-linux\/","url_meta":{"origin":33222,"position":0},"title":"New &#8216;Tycoon&#8217; Ransomware Strain Targets Windows, Linux","author":"Rick Backus","date":"June 16, 2020","format":false,"excerpt":"By Kelly Sheridan - A newly discovered form of Java-based ransomware has been spotted in active and seemingly targeted attacks on education and software companies, researchers from BlackBerry and KPMG report. This strain, dubbed Tycoon, uses an obscure Java image format to bypass security tools. The discovery began when KPMG's\u2026","rel":"","context":"In &quot;Ransomware&quot;","block_context":{"text":"Ransomware","link":"https:\/\/blog.cyberconservices.com\/index.php\/category\/ransomware\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/cdn.pixabay.com\/photo\/2012\/04\/12\/20\/37\/moneybags-30556__340.png?resize=350%2C200&ssl=1","width":350,"height":200},"classes":[]},{"id":33052,"url":"https:\/\/blog.cyberconservices.com\/index.php\/2020\/01\/02\/ransomware-situation-goes-from-bad-to-worse\/","url_meta":{"origin":33222,"position":1},"title":"Ransomware Situation Goes From Bad to Worse","author":"Rick Backus","date":"January 2, 2020","format":false,"excerpt":"By Jai Vijayan - The surge in ransomware attacks on cities, municipalities, schools, and healthcare organizations this year is just a foretaste of what is likely come in 2020. Threat actors have sensed a very real opportunity to make big returns attacking enterprise organizations using ransomware and are refining their\u2026","rel":"","context":"In &quot;Ransomware&quot;","block_context":{"text":"Ransomware","link":"https:\/\/blog.cyberconservices.com\/index.php\/category\/ransomware\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/cdn.pixabay.com\/photo\/2012\/11\/07\/07\/31\/man-65049__340.jpg?resize=350%2C200&ssl=1","width":350,"height":200},"classes":[]},{"id":31606,"url":"https:\/\/blog.cyberconservices.com\/index.php\/2019\/05\/14\/this-ransomware-sneakily-infects-victims-by-disguising-itself-with-anti-virus-software\/","url_meta":{"origin":33222,"position":2},"title":"This ransomware sneakily infects victims by disguising itself with anti-virus software","author":"Rick Backus","date":"May 14, 2019","format":false,"excerpt":"By\u00a0Danny Palmer\u00a0- A successful family of\u00a0ransomware\u00a0which has been terrorising organisations around the world has been updated with a new trick to lure victims into installing file-locking malware: posing as anti-virus software. Dharma first emerged in 2016 and the ransomware has been responsible for a number of high-profile cyber incidents,\u00a0including the\u2026","rel":"","context":"In &quot;Ransomware&quot;","block_context":{"text":"Ransomware","link":"https:\/\/blog.cyberconservices.com\/index.php\/category\/ransomware\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.cyberconservices.com\/wp-content\/uploads\/2019\/05\/hooded-man-2580085__340.jpg?resize=350%2C200","width":350,"height":200},"classes":[]},{"id":33054,"url":"https:\/\/blog.cyberconservices.com\/index.php\/2020\/01\/06\/fbi-issues-lockergaga-megacortex-ransomware-warning\/","url_meta":{"origin":33222,"position":3},"title":"FBI Issues LockerGaga, MegaCortex Ransomware Warning","author":"Rick Backus","date":"January 6, 2020","format":false,"excerpt":"By Dan Kobialka - The\u00a0FBI\u00a0recently warned U.S. organizations about LockerGaga and MegaCortex ransomware attacks, according to\u00a0BleepingComputer. It also provided tips to help organizations guard against LockerGaga and MegaCortex. LockerGaga and MegaCortex control an organization\u2019s network via exploits, phishing attacks, SQL injections and stolen login credentials, FBI noted. They then attempt\u2026","rel":"","context":"In &quot;Ransomware&quot;","block_context":{"text":"Ransomware","link":"https:\/\/blog.cyberconservices.com\/index.php\/category\/ransomware\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/cdn.pixabay.com\/photo\/2019\/01\/05\/10\/00\/personal-data-3914809__340.jpg?resize=350%2C200&ssl=1","width":350,"height":200},"classes":[]},{"id":34410,"url":"https:\/\/blog.cyberconservices.com\/index.php\/2020\/07\/08\/ransomware-has-a-new-and-very-valuable-hostage-in-sight\/","url_meta":{"origin":33222,"position":4},"title":"Ransomware Has A New And Very Valuable Hostage In Sight","author":"Rick Backus","date":"July 8, 2020","format":false,"excerpt":"Bob Zukis - Cybercriminals have figured out that fencing stolen data is a lot more work than just holding it hostage. It also doesn't pay as well. Ransomware is a rapidly growing cyber threat, and attacks overall were\u00a0up 25% in Q1. Ransomware continues to proliferate as an effective cybersecurity threat\u2026","rel":"","context":"In &quot;Ransomware&quot;","block_context":{"text":"Ransomware","link":"https:\/\/blog.cyberconservices.com\/index.php\/category\/ransomware\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/cdn.pixabay.com\/photo\/2020\/01\/07\/09\/33\/matrix-4747148__340.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/cdn.pixabay.com\/photo\/2020\/01\/07\/09\/33\/matrix-4747148__340.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/cdn.pixabay.com\/photo\/2020\/01\/07\/09\/33\/matrix-4747148__340.jpg?resize=525%2C300&ssl=1 1.5x"},"classes":[]},{"id":31827,"url":"https:\/\/blog.cyberconservices.com\/index.php\/2019\/08\/21\/troldesh-ransomware-dropper\/","url_meta":{"origin":33222,"position":5},"title":"Troldesh Ransomware Dropper","author":"Rick Backus","date":"August 21, 2019","format":false,"excerpt":"By Luke Leal\u00a0- Over the past few weeks, we\u2019ve seen an increase in Troldesh ransomware using compromised websites as intermediary malware distributors. The malware often uses a PHP file that acts as a delivery tool for downloading the host\u00a0malware dropper: This type of infected URL is usually spread through malicious\u2026","rel":"","context":"In &quot;Ransomware&quot;","block_context":{"text":"Ransomware","link":"https:\/\/blog.cyberconservices.com\/index.php\/category\/ransomware\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/posts\/33222","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/comments?post=33222"}],"version-history":[{"count":0,"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/posts\/33222\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/media?parent=33222"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/categories?post=33222"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/tags?post=33222"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}