Search DubaiPRNetwork.com

Dubai and UAE
Home >> Technology

Sophos Uncovers New Version of Snatch Ransomware

Thursday, December 12, 2019/ Editor -  

Share

Home >> Technology

 

Sophos (LSE: SOPH), a global leader in next-generation cybersecurity,  today published an investigative report, Snatch Ransomware Reboots PCs into Safe Mode to Bypass Protection, by SophosLabs and Sophos Managed Threat Response. The report details the changing attack methods of Snatch ransomware, first seen in December 2018, including rebooting PCs into Safe Mode mid-attack in an attempt to bypass behavioral protections that detect ransomware activity. Sophos believes this is a new attack technique adopted by cybercriminals for defense evasion.

Continuing a trend noted in SophosLabs’ 2020 Threat Report, the Snatch cybercriminals are now also exfiltrating data before the ransomware attack begins. This behavior has been used by other ransomware groups, including Bitpaymer. Sophos expects this sequence of exfiltrating data before ransomware encryption to continue. Businesses needing to comply with GDPR, the upcoming California Consumer Privacy Act and other regulatory laws may need to notify data protection regulators if they are victims of Snatch.

Snatch is an example of an automated, active attack, also outlined in SophosLabs’ 2020 Threat Report. Once attackers gain access by abusing remote access services, they use hand-to-keyboard hacking to move laterally and do damage. As explained in the Snatch report, attackers are gaining entry through insecure IT remote access services, such as (but not limited to) Remote Desktop Protocol (RDP). The report shows examples of Snatch attackers recruiting potential collaborators who are skilled in compromising remote access services in dark web forums. Below is a screen shot of the dark web forum conversation in Russian, which states, “Looking for affiliate partners with access to RDP\VNC\TeamViewer\WebShell\SQLinj in corporate networks, stores and other companies.'

Advice for defenders:

Be proactive about threat hunting: use an expert internal or external security operations team to monitor for threats around the clock 
Enable machine/deep learning, active adversary mitigations and behavioral detection in endpoint security
Where possible, identify and shutdown remote access services exposed to the public internet
If remote access is required, use a VPN with industry best practice multi-factor authentication, password audits and precise access control, in addition to actively monitoring remote access
Any servers with remote access open to the public internet need to be up-to-date on patches and protected by preventative controls (such as endpoint protection software), and actively monitored for anomalous login and other abnormal behaviour
Users logged into remote access services should have limited privileges for the rest of the corporate network
Administrators should adopt multi-factor authentication and use a separate administrative account from their normal user account
Actively monitor for open RDP ports in public IP space


Previous in Technology

Next in Technology


Home >> Technology Section

Latest Press Release

Ministry of Industry and Advanced Technology extends nomination period for Make ...

Icons shine with OMEGA in Milan

LG Announces First-Quarter 2024 Financial Results

Dubai South Signs Agreement With Agmc To Launch A New AED 500 Million State-Of ...

Terra Nova 40.5 Turning Bezel Power Reserve

ADMAF announces the return of 'Riwaq Al Adab Wal Kitab' with a lively cultural p ...

Formula E And Fia Unveil Gen3 Evo Race Car Capable Of 0-60mph In Just 1.82s

FEST Auto and Abu Dhabi University collaborate to accelerate sustainable urban m ...

Dubai Customs and "Dubai Charity" Distribute Meals and Food Supplies t ...

HM8 MARK 2 Back to the dream

Expo City Dubai to Host The Wings for Life World Run for the 2nd Consecutive Yea ...

Thousand mangrove trees to be planted as part of EarthSoul Festival in Dubai

World Art Dubai 2024 Unveils 12 International Pavilions Showcasing Global Artist ...

A New Blueprint for Health and Vitality at AyurMa: Introducing PraMā at Fou ...

Over AED 768 million worth pension disbursements for the month of April, announc ...

Experts outline a promising future for the GCC hospitality sector, as the UAE ma ...

Union Coop and Ministry of Human Resources and Emiratization Collaborate to Trai ...

Moorfields Eye Hospital Dubai unveils 20% expansion, equipped with the latest te ...

Dubai Food Festival 2024: Get ready to feast your senses at Mall of the Emirates ...

RAKEZ achieves 61% increase in new company registrations in Q1 2024