RobbinHood ransomware tricks Windows into deleting defences

General News

Summary

Sophos has published research into a novel type of ransomware attack in which cyber criminals are deploying legitimate, digitally signed hardware drivers to delete security products from their target systems before encrypting user data. The RobbinHood ransomware works by exploiting an old vulnerability, CVE-2018-19320, that exists in a now-deprecated driver produced by Taiwanese firm Gigabyte, which still has a valid and unrevoked Verisign Authenticode signature and is still in use by many despite being discontinued. Mark Loman, director of engineering at Sophos, said the firm’s analysis of RobbinHood showed how rapidly and dangerously the ransomware threat is evolving. “This is the first time we have seen ransomware bring its own legitimately signed, albeit vulnerable, third-party driver to take control of a device and use that to disable the installed security software, bypassing the features specially designed to prevent such tampering. Sophos found a number of indicators to suggest that the authors of the malicious driver are the same group behind RobbinHood, a strain of ransomware that caused chaos for many victims in 2019, notably the city of Baltimore in Maryland, where local government employees were locked out of their systems for over two weeks.

Classifications

industries
No industries detected
applications
Security

AskAI Classifications

Labels
No AI classifications detected

Linked Companies