{"id":36315,"date":"2019-12-16T08:26:01","date_gmt":"2019-12-16T08:26:01","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/?p=36315"},"modified":"2019-12-17T08:29:13","modified_gmt":"2019-12-17T08:29:13","slug":"sophos-uncovers-new-version-of-snatch-ransomware","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2019\/12\/16\/sophos-uncovers-new-version-of-snatch-ransomware\/","title":{"rendered":"Sophos uncovers new version of Snatch ransomware"},"content":{"rendered":"\n<p>Sophos, a global leader in next-generation cybersecurity, &nbsp;has published an investigative report,&nbsp;<em>Snatch Ransomware Reboots PCs into Safe Mode to Bypass Protection<\/em>, by&nbsp;SophosLabs&nbsp;and&nbsp;Sophos Managed Threat Response. <\/p>\n\n\n\n<p>The report details the changing attack methods of Snatch ransomware, first seen in December 2018, including rebooting PCs into safe mode mid-attack in an attempt to bypass behavioural protections that detect ransomware activity. Sophos believes this is a new attack technique adopted by cybercriminals for defence evasion.<\/p>\n\n\n\n<p>Continuing a trend noted in&nbsp;SophosLabs\u2019 <em>2020 Threat Report<\/em>, the Snatch cybercriminals are now also exfiltrating data before the ransomware attack begins. This behaviour has been used by other ransomware groups, including Bitpaymer. Sophos expects this sequence of exfiltrating data before ransomware encryption to continue. Businesses needing to comply with GDPR, the upcoming California Consumer Privacy Act and other regulatory laws may need to notify data protection regulators if they are victims of Snatch.<\/p>\n\n\n\n<p>Snatch is an example of an automated, active attack, also outlined in&nbsp;<a href=\"https:\/\/www.sophos.com\/en-us\/labs\/security-threat-report.aspx\">SophosLabs\u2019 <em>2020 Threat Repor<\/em>t<\/a>. Once attackers gain access by abusing remote access services, they use hand-to-keyboard hacking to move laterally and do damage. As explained in the Snatch report, attackers are gaining entry through insecure IT remote access services, such as (but not limited to) Remote Desktop Protocol (RDP). <\/p>\n\n\n\n<p>The report shows examples of Snatch attackers recruiting potential collaborators who are skilled in compromising remote access services in Dark Web forums. <\/p>\n\n\n\n<p>Advice for defenders:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Be proactive about threat hunting: use an expert      internal or external security operations team to monitor for threats      around the clock&nbsp;<\/li><li>Enable machine\/Deep Learning, active adversary      mitigations and behavioural detection in endpoint security<\/li><li>Where possible, identify and shutdown remote      access services exposed to the public Internet<\/li><li>If remote access is required, use a VPN with      industry best practice multi-factor authentication, password audits and      precise access control, in addition to actively monitoring remote access<\/li><li>Any servers with remote access open to the public      Internet need to be up-to-date on patches and protected by preventative      controls (such as endpoint protection software) and actively monitored      for anomalous login and other abnormal behaviour<\/li><li>Users logged into remote access services should      have limited privileges for the rest of the corporate network<\/li><li>Administrators should adopt multi-factor      authentication and use a separate administrative account from their normal      user account<\/li><li>Actively monitor for open RDP ports in public IP      space<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Sophos, a global leader in next-generation cybersecurity, &nbsp;has published an investigative report,&nbsp;Snatch Ransomware Reboots PCs into Safe Mode to Bypass Protection, by&nbsp;SophosLabs&nbsp;and&nbsp;Sophos Managed Threat Response. The report details the changing attack methods of Snatch ransomware, first seen in December 2018, including rebooting PCs into safe mode mid-attack in an attempt to bypass behavioural protections that [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":36414,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,6617,93],"tags":[1255,564,1847,14076],"class_list":["post-36315","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-research","category-top-stories","tag-cybercrime","tag-cybersecurity","tag-sophos","tag-sophos-managed-threat-response"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/36315","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=36315"}],"version-history":[{"count":2,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/36315\/revisions"}],"predecessor-version":[{"id":36408,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/36315\/revisions\/36408"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/36414"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=36315"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=36315"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=36315"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}