New Free Tool Stops Petya Ransomware & Rootkits

  /     /     /  
Publicated : 22/11/2024   Category : security


New Free Tool Stops Petya Ransomware & Rootkits


Meanwhile, Locky puts ransomware on the Check Point Top Three Global Malware List for the first time ever.



Although Check Point reported today that ransomware operators have reached a new benchmark in their malicious spree, security researchers at Cisco Talos Labs have unveiled a new way to fight back. 
For the first time ever, reports Check Point, a ransomware strain has hit its Top Three Global Malware List -- specifically the
Locky
ransomware, which accounted for 6% of all attacks recognized globally during September.
Meanwhile, Cisco Talos has released a new free, open-source tool -- called MBRFilter -- to fight the insidious Petya ransomware and similar malware.
F-Secure first
issued an alert
about Petya in April. Most ransomware works by simply encrypting files; Petya uses a much different tactic, behaving more like a rootkit. Petya overwrites the systems Master Boot Record, which forces the system to reboot. On reboot, the malware encrypts the Master File Table of the infected systems hard drive.
The process happens more quickly than other ransomwares usual file-by-file grind. It leaves little time to notice theres a problem, much less call for help. 
MBRFilter
defeats Petya in a rather simple, clever way. MBRFilter is a driver that simply places the MBR into read-only mode. Therefore, ransomware like Petya cannot overwrite the MBR or otherwise modify its contents. 
Our vulnerability research team is constantly looking for new ways to exploit devices and identify ways to better protect them, says Craig Williams, senior technical leader and global outreach manager of Talos. This project is a natural result. 
Although MBRFilter will
not 
help organizations solve their problems with Locky, it has wide use beyond ransomware.
This should be effective at stopping all rootkits which require MBR modification, says Williams. 
MBRFilter is a simple disk filter based on Microsofts diskperf and classpnp example drivers. Cisco Talos Labs researchers caution security operations teams to test MBRFilter thoroughly before deploying it to production environments, because it was deliberately designed to be difficult to remove.
Related Content:
Ransomware Authors Break New Ground With Petya
Ransomware Spikes, Tries New Tricks
 

Last News

▸ Researchers create BlackForest to gather, link threat data. ◂
Discovered: 23/12/2024
Category: security

▸ Travel agency fined £150,000 for breaking Data Protection Act. ◂
Discovered: 23/12/2024
Category: security

▸ 7 arrested, 3 more charged in StubHub cyber fraud ring. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
New Free Tool Stops Petya Ransomware & Rootkits