Ransomware Now Disguises Itself


A new strain of ransomware now disguises itself as ‘quarantined’ to help avoid detection.–PC Pitstop

Ransomware Now Disguises Itself

By Stu Sjouwerman, for KnowBe4.com Security Awareness Training

A new ransomware strain dubbed CRYPVAULT by Trend Micro is being spread as an email attachment. It’s currently focusing on Eastern Europe and is making its way to Europe and America.

It’s a novel approach. In an attempt to bypass any and all endpoint protection, the user is social engineered to open an attached Javascript file. The phishing attack does not have an executable as a payload. Next, it uses the command box to run a batch file that encrypts the files.

According to a post by Michael Marcos, threat response engineer with Trend Micro, CRYPVAULT encrypts the files and then makes them appear to the end-user as if they were quarantined, by giving them the .vault extension.

According to a Monday post by Michael Marcos, threat response engineer with Trend Micro, CRYPVAULT encrypts the files and then makes them appear to the end-user as if they were quarantined, by giving them the .vault extension.

Article Continued Here

Stop Responding to Threats.
Prevent Them.

Want to get monthly tips & tricks?

Subscribe to our newsletter to get cybersecurity tips & tricks and stay up to date with the constantly evolving world of cybersecurity.

Related Articles