RSS
Логотип
Баннер в шапке 1
Баннер в шапке 2
2020/11/06 13:42:33

RegretLocker (virus racketeer)

Content

2020: Appearance of the RegretLocker virus racketeer attacking Windows virtual machines

At the beginning of November, 2020 it became known of appearance of a new virus racketeer which developers used advanced methods for enciphering of virtual machines. Systems for Windows are subject to the attacks.

The RegretLocker virus racketeer which was for the first time detected in October, 2020 uses interesting technology of assembling of the file of a virtual disk, it allows to cipher each file individually. For this RegretLocker uses the Windows Virtual Storage API OpenVirtualDisk, AttachVirtualDisk and GetVirtualDiskPhysicalPath functions for assembling of virtual disks. Such approach allows to reduce enciphering speed significantly. In addition to use of API of virtual storage, RegretLocker also uses the API manager of restart Windows for completion of processes or Windows services which save the file opened during enciphering.

File:Dqrv5iuWkAEBiV.jpg
The RegretLocker virus racketeer attacking Windows virtual machines is detected

Though the technical aspect impresses with the complexity and capability to work with files, the rest of RegretLocker is quite standard. The victims receive a note about the redemption in which they are offered to contact hackers via e-mail if they want to recover the ciphered files. Hackers use the Icelandic, anonymous service of e-mail CTemplar.

File:Aquote1.png
Recently detected RegretLocker program racketeer is one more example of that how sophisticated became creators of malware and as they continue to develop the capabilities, - Saryyu Nayar, the chief executive officer of Gurucul Solutions noted. - New opportunities of this program racketeer pose a threat, especially if it is widely adopted. Nevertheless, tools of behavioural analytics are capable to identify quickly attacks of this sort in the same way as in a case with other programs racketeers.[1]
File:Aquote2.png

See Also





Notes