Monday, January 30, 2023
News 21 AV
  • Home
  • Tech News
    Government launches AI-focused green innovation programme

    Government launches AI-focused green innovation programme

    CDEI publishes roadmap for UK AI assurance ecosystem

    Why robots will make work more human

    Genome lab puts Vast Data’s rapid I/O to work on patient data

    Genome lab puts Vast Data’s rapid I/O to work on patient data

    The rise of ethical hackers in 2021

    Bug Bounty Calculator helps organisations fine-tune their payouts

    Google commits to cloud and AI

    EDF UK deploys Riverbed’s Alluvio Aternity to tackle IT issues

    How the sector is preparing for the prospect of planned winter power cuts

    How the sector is preparing for the prospect of planned winter power cuts

    Building the UK’s future cyber ecosystem

    CyberPeace Institute helps NGOs improve their security resilience

    Virtually all vulnerable open source downloads are avoidable

    Pioneer behind IT systems design dies

    Post Office supported 1999 law change that eased prosecutions using computer evidence

    Post Office scandal inquiry’s expert IT witness ‘troubled’ by his findings

  • Virtual reality
    StretchSense built an actually comfortable hand-motion capture glove

    StretchSense built an actually comfortable hand-motion capture glove

    VR gaming startup ForeVR Games raises $10M to grow its library of Wii Sports-like titles

    VR gaming startup ForeVR Games raises $10M to grow its library of Wii Sports-like titles

    Meta will release a new consumer-grade VR headset next year

    Meta will release a new consumer-grade VR headset next year

    Meta files to dismiss FTC complaint over acquisition of VR fitness company Within

    Meta files to dismiss FTC complaint over acquisition of VR fitness company Within

    Microsoft Teams avatars

    Here’s what you missed at Meta Connect 2022

    read more about Meta Connect 2022 on TechCrunch

    Meta partners with NBCUniversal to bring you into ‘The Office’

    Meta Quest 2 gets exclusive VR series ‘Scream Park’ from entertainment studio BlackBox TV

    Meta Quest 2 gets exclusive VR series ‘Scream Park’ from entertainment studio BlackBox TV

    Google’s GV backs SideQuest, an unofficial Meta Quest app store

    Google’s GV backs SideQuest, an unofficial Meta Quest app store

    VRAI wants to tackle the energy crisis by bringing VR simulation training to offshore wind sector

    VRAI wants to tackle the energy crisis by bringing VR simulation training to offshore wind sector

  • Lifestyle
    Cancer

    6 Most Common Cancers and Their Symptoms

    business clothing

    How can astrology help in business

    Business astrology

    Learn About Your Business Indications by Your Zodiac Sign

    NFT (Non-Fungible Token) Futuristic Background

    How NFTs Are Breaking Ground in the World of Watchmaking

    woman reading

    How to Stay Productive All Day: Tips for Internal Motivation

    in laws family

    5 signs that show your in-laws are too interfering

    Booty Shorts

    7 Ways to Look Sexy at Your Next Rave Party

    Happy life

    Feeling stuck? How to clear your mind and plan ahead

    CBD Beauty

    7 Health Benefits of CBD

  • Beauty
    Water Flosser

    This Bestselling Waterpik Is On Sale Right Now

    Proud To Be Pink Bobbi Brown Gloss Duo

    Proud To Be Pink Bobbi Brown Gloss Duo

    ColourPop x Snitchery Collection Swatches (Eyes & Cheeks)

    ColourPop x Snitchery Collection Swatches (Eyes & Cheeks)

    Image may contain Clothing Apparel Human Person Lingerie and Underwear

    Period Care Ads Are Woefully Lacking in Disability Representation

    mileys new years eve party

    Who Is Maxx Morando? – All About Miley Cyrus’s New Boyfriend

    Dior Cosmic Eyes (359) Eyeshadow Palette

    Dior Holiday 2022 Collection Swatches

    preview for How Emma Stone Became an Oscar-Winning Actress

    Who Is Dave McCary? Meet Emma Stone’s Husband and Baby Girl’s Dad

    Coloured Raine Sunset Chic Eyeshadow Palette Review & Swatches

    Coloured Raine Sunset Chic Eyeshadow Palette Review & Swatches

    Mila Kunis Criticizes Celebs Who Gave Will Smith a Standing Ovation at the Oscars After The Slap

    Mila Kunis Criticizes Celebs Who Gave Will Smith a Standing Ovation at the Oscars After The Slap

  • Health & Fitness
    Shop Around to Save on Drug Prices

    Shop Around to Save on Drug Prices

    Ukrainian Powerlifter Daria Rusanenko (84KG) Squats a World Record 275.5 Kilograms (607.4 Pounds)

    Ukrainian Powerlifter Daria Rusanenko (84KG) Squats a World Record 275.5 Kilograms (607.4 Pounds)

    Logo for WebMD

    Gene and Cell Therapies Used in Treatment

    Watch Ivan Makarov Lift a Milestone 190-Kilogram (418.9-Pound) Overhead Press

    Watch Ivan Makarov Lift a Milestone 190-Kilogram (418.9-Pound) Overhead Press

    Treating MS Pain With Virtual Reality

    Treating MS Pain With Virtual Reality

    Žydrūnas Savickas Wins the 2022 Masters World's Strongest Man Title

    Žydrūnas Savickas Wins the 2022 Masters World’s Strongest Man Title

    MS Questionnaire Helps Measure Symptoms and Spot Early Disease Changes

    MS Questionnaire Helps Measure Symptoms and Spot Early Disease Changes

    Shaun Clarida Will Stick with the 212 Division at the 2022 Mr. Olympia

    Shaun Clarida Will Stick with the 212 Division at the 2022 Mr. Olympia

    How to Focus on Your Mental Health With Relapsing-Remitting MS

    How to Focus on Your Mental Health With Relapsing-Remitting MS

  • Equipment
  • Login
No Result
View All Result
News 21 AV
Home Tech News

Latest LockBit ransomware versions have wormable capabilities

News 21 AV by News 21 AV
December 2, 2022
in Tech News
0
Latest LockBit ransomware versions have wormable capabilities
0
SHARES
0
VIEWS
FacebookTwitter


The LockBit ransomware cartel behind the recent Advanced Software – NHS attack continues to evolve and upgrade its locker malware, incorporating new wormable functionality that allows it to self-spread, making it easier to use, and obfuscation capabilities that enable it to mimic the activity of legitimate penetration testers.

Related posts

Ban predictive policing systems in EU AI Act, says civil society

Insights on Nordic artificial intelligence strategies

January 14, 2023
Unionised contract workers who train Google’s AI win pay rise

Unionised contract workers who train Google’s AI win pay rise

January 14, 2023

Operatives at Sophos’s Managed Detection and Response (MDR) unit pored over evidence from leaks and a series of attacks and found evidence that LockBit’s creators have been experimenting with scripting that allows it to self-propagate using Windows Group Policy Objects (GPOs) or the PSExec tool, which they say makes it easier for the ransomware to move laterally and infect other computers.

Critically, said the MDR team, this would substantially reduce the technical legwork required for LockBit affiliates to infect their victims, speeding up the time to ransomware execution. It also runs with permissions that mean an affiliate does not necessarily need administrator-level access to their victim in order to cause damage.

Reverse-engineering of LockBit 3.0, which launched earlier this year, also revealed that the ransomware has adopted new behaviours that make it harder for researchers to analyse properly. For example, affiliates must now enter a 32-character password in the ransomware binary’s command line when they launch it, or it won’t run.

Sophos also posited a stronger-than-ever link to the BlackMatter group, noting multiple similarities that suggest LockBit is reusing BlackMatter code, notably an anti-debugging trick that conceals internal functions calls from researchers, similar means of string obfuscation, thread hiding, enumerating DNS hostnames, OS checking and configuration. They also both send ransom notes to any available printers they may find.

Sophos principal researcher Andrew Brandt wrote: “Some researchers have speculated that the close relationship between the LockBit and BlackMatter code indicates possible recruitment of BlackMatter members by LockBit, a purchase of the BlackMatter code base, or a collaboration between developers. As we noted in our whitepaper on multiple attackers earlier this year, it’s not uncommon for ransomware groups to interact, either inadvertently or deliberately.

“Either way, these findings are further evidence that the ransomware ecosystem is complex and fluid. Groups reuse, borrow or steal each other’s ideas, code and tactics as it suits them. And, as the LockBit 3.0 leak site – containing, among other things, a bug bounty and a reward for ‘brilliant ideas’ – suggests that gang in particular is not averse to paying for innovation.”

Interestingly, Brandt and the MDR team also found that it is increasingly difficult to distinguish LockBit 3.0 activity from the work of legitimate penetration testers.

They found evidence that LockBit 3.0 is using a package from GitHub known as Backstab, the function of which is to sabotage security operation centre tooling – in addition to the now practically standard use of red teaming framework Cobalt Strike and password sniffer Mimikatz.

It has also been observed using GMER, a rootkit detector and remover, ESET’s AV Remover tool, and a number of PowerShell scripts that seek to remove Sophos’s own products from systems.

“It is safe to assume that experienced threat actors are at least as familiar with Sophos Central and other console tools as the legitimate users of those consoles, and they know exactly where to go to weaken or disable the endpoint protection software,” said Brandt.

“In fact, in at least one incident involving a LockBit threat actor, we observed them downloading files which, from their names, appeared to be intended to remove Sophos protection.”



Source link

Tags: capabilitiesLatestLockBitransomwareversionswormable
Previous Post

I Love My Best Friend; We Hook Up, But He Doesn’t Love Me Back

Next Post

No, the Robots Are Not Taking Over

Next Post
First They Get Long COVID, Then They Lose Their Health Care

No, the Robots Are Not Taking Over

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED NEWS

Chanel Vital Beige (3) No. 1 de Chanel Lip & Cheek Balm

Chanel Vital Beige No. 1 Lip & Cheek Balm Review & Swatches

1 year ago
Lidar-powered lawn care solves big problem for utilities

Lidar-powered lawn care solves big problem for utilities

1 year ago
Luxury Home With Infinity Pool in Mallorca, Spain [Video]

Luxury Home With Infinity Pool in Mallorca, Spain [Video]

4 months ago
51 Living Room Chandeliers for Effective Illumination with Unforgettable Style

51 Living Room Chandeliers for Effective Illumination with Unforgettable Style

10 months ago

BROWSE BY CATEGORIES

  • Beauty
  • Equipment
  • Health & Fitness
  • Lifestyle
  • Tech News
  • Virtual reality

BROWSE BY TOPICS

Beauty Equipment Health & Fitness Lifestyle Tech News Virtual reality

POPULAR NEWS

  • The 20 Best Leg Exercises for Size and Strength

    The 20 Best Leg Exercises for Size and Strength

    0 shares
    Share 0 Tweet 0
  • Who Is Dalton Gomez – Meet Ariana Grande’s Husband

    0 shares
    Share 0 Tweet 0
  • 14 Best Sanitary Napkins To Provide Comfort During Periods

    0 shares
    Share 0 Tweet 0
  • 10 Best CD Players in 2021

    0 shares
    Share 0 Tweet 0
  • Why Power Dressing is Important at Workplace For Women

    0 shares
    Share 0 Tweet 0
News 21 AV

We bring you the best of latest news articles with an emphasis. We offers an original take on the latest in Lifestyle, fashion, high tech and health & fitness informations and guides.

Follow us on social media:

Recent News

  • A Home Of Muted Colors And Soft Curves
  • 2023 Britain’s Strongest Man Results — Adam Bishop Takes The Crown
  • Kids’ COVID More Dangerous When Co-Infected With RSV, Colds

Category

  • Beauty
  • Equipment
  • Health & Fitness
  • Lifestyle
  • Tech News
  • Virtual reality

Recent News

Cancer

6 Most Common Cancers and Their Symptoms

November 22, 2022
Government launches AI-focused green innovation programme

Government launches AI-focused green innovation programme

November 22, 2022
  • Blog
  • Privacy Policy
  • Disclaimer
  • Terms and Conditions
  • Contact us

© 2021 News.21av - Popular News & magazine powred by Get solutions.

No Result
View All Result
  • Home
  • Tech News
  • Virtual reality
  • Lifestyle
  • Beauty
  • Health & Fitness
  • Equipment

© 2021 News.21av - Popular News & magazine powred by Get solutions.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In