Get a Pentest and security assessment of your IT network.

News

RobbinHood Kills Security Processes Before Dropping Ransomware

In a newly detected attack campaign, the attackers behind RobbinHood use legitimate, digitally signed hardware drivers to delete security tools on target machines before encrypting files. These attacks exploit known vulnerability CVE-2019-19320, report Sophos researchers who investigated two attacks employing this technique. The flaw exists in a signed driver that is part of a now-deprecated software package published by Taiwanese motherboard manufacturer Gigabyte. The company later rescinded its statement that its products weren’t affected by the flaws.”]

Source: https://www.darkreading.com/attacks-breaches/robbinhood-kills-security-processes-before-dropping-ransomware

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2