Symantec has found evidence that an increasing number of ransomware attackers are using virtual machines (VMs) in order to run their ransomware payloads on compromised computers. The motivation behind the tactic is stealth. In order to avoid raising suspicions or triggering antivirus software, the payload will hide within a VM while encrypting files on the host computer. The tactic is a recent development, having been documented by Sophos in connection with RagnarLocker last year. In that case, ransomware was run from inside an Oracle VirtualBox Windows XP VM.”]
Source: https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ransomware-virtual-machines

