Update to REvil ransomware changes Windows passwords to automate file encryption via Safe Mode
Summary
The hackers behind the REvil ransomware have released an updated version of the malware that allows them to change Windows passwords and automate file encryption through Safe Mode, according to a recent report from Bleeping Computer. "REvil has been evolving its tactics since February 2020, adding DDoS attacks to its arsenal, cold calling victims, and now rebooting machines in Safe Mode. Data shows that there has been a 72% rise in ransomware attacks over the past year which can be directly correlated to the increased use of home computers to perform remote work due to the COVID19 pandemic." Jerome Becquart, COO at Axiad, echoed those remarks highlighting that no matter how strong your users passwords are, having any password-based authentication can leave you open to ransomware attacks. By encrypting victims files and requesting financial payment, ransomware like REvil has one of the highest direct returns of investment," said Niamh Muldoon, global data protection officer at OneLogin.