A new strain of ransomware now disguises itself as ‘quarantined’ to help avoid detection.–PC Pitstop
Ransomware Now Disguises Itself
By Stu Sjouwerman, for KnowBe4.com Security Awareness Training
A new ransomware strain dubbed CRYPVAULT by Trend Micro is being spread as an email attachment. It’s currently focusing on Eastern Europe and is making its way to Europe and America.
It’s a novel approach. In an attempt to bypass any and all endpoint protection, the user is social engineered to open an attached Javascript file. The phishing attack does not have an executable as a payload. Next, it uses the command box to run a batch file that encrypts the files.
According to a post by Michael Marcos, threat response engineer with Trend Micro, CRYPVAULT encrypts the files and then makes them appear to the end-user as if they were quarantined, by giving them the .vault extension.
According to a Monday post by Michael Marcos, threat response engineer with Trend Micro, CRYPVAULT encrypts the files and then makes them appear to the end-user as if they were quarantined, by giving them the .vault extension.