0 Записи
We found results matching "0" in 0 ms

Antivirus vendors push fixes for EFS ransomware attack method

Jan. 23, 2020

Researchers have discovered how an EFS attack triggered by ransomware makes systems based on signature-based antivirus solutions vulnerable.


Amit Klein, vice president of security research at Safebreach Labs, announced an investigation into how ransomware can exploit the Windows encryption file system, a type of malware that encrypts systems and should be detected.


A laboratory investigation conducted by EFS, developed by Microsoft as an NTFS alternative to fully encrypt the BitLocker disk to encrypt individual files or directories, found that important antivirus solutions may not protect the system.


In a blog post, Safebreach Labs said that after trying three key anti-ransomware solutions offered by cybersecurity providers, all three attacks could not be blocked.


The security solutions tested were ESET Internet Security 12.1.34.0, Kaspersky Anti Ransomware 4.0.0.861 and Microsoft Windows 10 Controlled Folder Access on Windows 10 64 bit version 1809 using a Windows 10 virtual machine loaded with a variety of different contents and types of files.


Safebreach Labs tested whether EFS could be exploited by creating its own ransomware variant, which uses tactics such as generating keys and certificates. To start the attack chain, the ransomware created both and added the certificate to the personal certificate store, with the new key assigned as the current EFS key and requested the deletion of files or folders.


If possible, the malware removes the loose parts of the hard drive and then encrypts the data in the key file with a public key connected to the ransomware. At this point, it is also possible to send stolen information to an attacker's command and control center.


According to the researchers, EFS-based ransomware encryption activities take place in the kernel and, as the NTFS driver is involved, they can also go unnoticed for file system filtering drivers. No human interaction or administrative rights are required.


However, the lock icons appear when the files are encrypted, which can give victims an indication that everything is wrong, and when the Data Recovery Agent is activated, recovery can be "trivial," the equipment.


Safebreach Labs developed a proof of concept code and provided it to 17 cybersecurity providers. As a result, the team discovered that more products were affected than expected.


One possible solution is for administrators to modify registry keys to disable EFS and use Group Policy in company settings. However, if EFS is used actively and legally, disabling the configuration may affect the required file protection.


Bzfuture shares software news and advice on big data software and platforms. Don't forget to keep an eye on our weekly newsletter for more information.Get all the software products you need from the bzfuture online retail store. Connect with our customer service online.

Последние новости: Protect Your Data with AOMEI Backupper

Следующая новость: Kaspersky Anti-Virus Review

ЗакрытьДобро пожаловать в Bzfuture Вход.

Еще не зарегистрировались ?   Sign Up Now

Войти с помощью сторонней учетной записи:

Open the bzfuture APP

Scan The code to login

ЗакрытьДобро пожаловать в w8games регистрацию

  • Адрес электронной почты*

    Please enter a valid Email.

  • Mobile Phone*

    Please enter a valid mobile phone.

  • Verification Code*

    Get Verification Code

    The code will be invalid in 5 minutes

  • Пароль*

    5 to 16 letters, numbers, and special characters.

  • Подтвердить пароль*

  • Имя* Фамилия*

  • Я прочитал и согласен с  
    Подписаться на Bzfuture Предложения, конкурсы и новости

Уже зарегистрированны в Bzfuture ?   Войти сейчас

Войти с помощью сторонней учетной записи

ЗакрытьЗабыли пароль

Закрыть

Prompt T698563:

The programe has been successfully submitted to the system

Закрыть

Prompt T698563:

The programe has been successfully submitted to the system

Закрыть

Prompt T698563:

The programe has been This is a warning ?

ЗакрытьSuccessful Registration

Click here to set up your User Center

CloseПроверка безопасности