Source |
The Hacker News |
Identifiant |
1493874 |
Date de publication |
2019-12-10 01:28:44 (vue: 2019-12-17 22:01:48) |
Titre |
Snatch Ransomware Reboots Windows in Safe Mode to Bypass Antivirus |
Texte |
Cybersecurity researchers have spotted a new variant of the Snatch ransomware that first reboots infected Windows computers into Safe Mode and only then encrypts victims' files to avoid antivirus detection.
Unlike traditional malware, the new Snatch ransomware chooses to run in Safe Mode because in the diagnostic mode Windows operating system starts with a minimal set of drivers and services |
Notes |
|
Envoyé |
Oui |
Condensat |
antivirus avoid because bypass chooses computers cybersecurity detection diagnostic drivers encrypts files first have infected malware minimal mode new only operating ransomware reboots researchers run safe services set snatch spotted starts system then traditional unlike variant victims windows |
Tags |
Ransomware
|
Stories |
|
Move |
|