Search DubaiPRNetwork.com

Dubai and UAE
Home >> Technology

Sophos Uncovers New Version of Snatch Ransomware

Thursday, December 12, 2019/ Editor -  

Share

Home >> Technology

 

Sophos (LSE: SOPH), a global leader in next-generation cybersecurity,  today published an investigative report, Snatch Ransomware Reboots PCs into Safe Mode to Bypass Protection, by SophosLabs and Sophos Managed Threat Response. The report details the changing attack methods of Snatch ransomware, first seen in December 2018, including rebooting PCs into Safe Mode mid-attack in an attempt to bypass behavioral protections that detect ransomware activity. Sophos believes this is a new attack technique adopted by cybercriminals for defense evasion.

Continuing a trend noted in SophosLabs’ 2020 Threat Report, the Snatch cybercriminals are now also exfiltrating data before the ransomware attack begins. This behavior has been used by other ransomware groups, including Bitpaymer. Sophos expects this sequence of exfiltrating data before ransomware encryption to continue. Businesses needing to comply with GDPR, the upcoming California Consumer Privacy Act and other regulatory laws may need to notify data protection regulators if they are victims of Snatch.

Snatch is an example of an automated, active attack, also outlined in SophosLabs’ 2020 Threat Report. Once attackers gain access by abusing remote access services, they use hand-to-keyboard hacking to move laterally and do damage. As explained in the Snatch report, attackers are gaining entry through insecure IT remote access services, such as (but not limited to) Remote Desktop Protocol (RDP). The report shows examples of Snatch attackers recruiting potential collaborators who are skilled in compromising remote access services in dark web forums. Below is a screen shot of the dark web forum conversation in Russian, which states, “Looking for affiliate partners with access to RDP\VNC\TeamViewer\WebShell\SQLinj in corporate networks, stores and other companies.'

Advice for defenders:

Be proactive about threat hunting: use an expert internal or external security operations team to monitor for threats around the clock 
Enable machine/deep learning, active adversary mitigations and behavioral detection in endpoint security
Where possible, identify and shutdown remote access services exposed to the public internet
If remote access is required, use a VPN with industry best practice multi-factor authentication, password audits and precise access control, in addition to actively monitoring remote access
Any servers with remote access open to the public internet need to be up-to-date on patches and protected by preventative controls (such as endpoint protection software), and actively monitored for anomalous login and other abnormal behaviour
Users logged into remote access services should have limited privileges for the rest of the corporate network
Administrators should adopt multi-factor authentication and use a separate administrative account from their normal user account
Actively monitor for open RDP ports in public IP space


Previous in Technology

Next in Technology


Home >> Technology Section

Latest Press Release

MBRU to host Photonics Middle East International Conference – Dubai 2024 from Sa ...

Natuzzi Italia @ Milano Design Week 2024: The Circle Of Harmony – 65th Annivers ...

Ajman Tourism Announces Run Ajman Race at Al Safia Park on 20 April

Ministry of Finance Launches Digital Public Consultation on Potential Implementa ...

Get ready to embark on an unforgettable gastronomical journey at Mercato's Dubai ...

Glam Beaute's Snugberi Launches Exciting New Products to Pamper Your Little Ones

Santoni Presents A Partnership With Patricia Urquiola At The Milan Design Week 2 ...

Superstar Slovenian Tadej Pogaĉar on the hunt for further Monument glory

Tourism leaders from around the world will explore how entrepreneurship and inno ...

Dubai sports council issued a medal to appreciate the first line of defence hero ...

OMODA & JAECOO take global centre stage at Beijing Auto Show 2024

Transform Your Kitchen With Lg's Next-Gen Instaview Oven Designed For The Modern ...

Majid Al Futtaim's 'Feed the Future' Programme Donates 12,000 Meals During Ramad ...

DSMG Wraps Up 2024 Eidiya Campaign with AED 200,000 Cash Prize Bonanza for 22 Wi ...

Kia wins prestigious 2024 Car Design Award for Brand Design Language with ‘Oppo ...

Cleveland Clinic Gastroenterologist Shares Risk-Reduction and Management Strateg ...

The English College Announces Leadership Transition and Reaffirms Commitment to ...

Parmigiani Fleurier – New TORIC Collection

How Not To be Lonely To Be At The Top: The Blueprint for Transformative Leadersh ...

IATA and Partners Release Aviation Net Zero Roadmaps Comparative Review