A recent change to the REvil/Sodinokibi ransomware allows the threat actors to automate file encryption via Safe Mode after changing Windows passwords. At the time of our reporting, the ransomware required someone to manually login to Windows Safe Mode before the encryption would start. The new sample refines the new Safe Mode encryption method by changing the logged-on user’s password and configuring Windows to automatically login on reboot. At least two samples uploaded to VirusTotal in the past two days continue to use the ‘DTrump4ever’ password.
Source: https://www.bleepingcomputer.com/news/security/revil-ransomware-now-changes-password-to-auto-login-in-safe-mode/