Thursday, February 27, 2020

Ransomware uses Gigabyte driver to disable antivirus



Extortionists demand a ransom from their victims, which increases by $ 10 thousand every day.

Sophos experts warned of new cyber attacks using RobbinHood ransomware. Criminals use the vulnerable Gigabyte driver to hack into a Windows system and disable running antivirus software.

During the attack, attackers exploit the uncorrected vulnerability (CVE-2018-19320), discovered in 2018 in the Gigabyte driver. The exploitation of the vulnerability allows you to access the device and install a second driver, with which criminals disable antivirus programs.

The Steel.exe executable file is used to exploit the vulnerability in the gdrv.sys driver and extracts a file with the name ROBNR.EXE in a temporary Windows folder. ROBNR.EXE, in turn, extracts two different drivers - one of which was developed by Gigabyte and contains a vulnerability, and the other is needed to disable antivirus software on a compromised device. After exploiting the vulnerability, the forced use of the Windows driver signature is disabled, which allows the malicious driver to be launched.

For access to encrypted files, ransomware requires a ransom from their victims, which increases by $ 10 thousand every day.


2 comments:

  1. Directly looking into it says "8MB to spare game". I have known about Fallout 3, Digital Marketing Company a comparative bethesda game, taking up to 1gb. in any case, that is in the event that you complete everything and possibly drop things all over the place. in the event that your not happy with the measure of memory you hav I propose simply purchasing a little blaze drive(4gb) and putting everything on there.

    ReplyDelete
  2. At times, freelance web developers uae I don't generally concur with capital punishment, yet in the event that somebody kills somebody without a second thought, at that point yes I figure he ought to likewise be killed. for what reason is it reasonable that he end an actual existence and live when the honest individual had no real option except to be killed. Why give the homicide a decision? He didn't give the blameless a decision. Nonetheless.

    ReplyDelete