Get a Pentest and security assessment of your IT network.

Cyber Security

Sodinokibi ransomware can now encrypt open and locked files

The Sodinokibi (REvil) ransomware has added a new feature that allows it to encrypt more of a victim’s files, even those that are opened and locked by another process. Ransomware is now using the Windows Restart Manager API to shut down processes or shut down Windows services keeping a file open during encryption. The API was created by Microsoft to make it easier to install software updates without performing a restart to free files that the updates need to replace. Both SamsSam and LockerGoga use the API in their malware as well.

Source: https://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-can-now-encrypt-open-and-locked-files/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security