2020-05-22
Ransomware Deploys Virtual Machine to Evade Detection
Editor's Note
The targets chosen are more likely to be running VirtualBox, so its presence alone is not necessarily a red flag. This attack installs an unsigned SunxVM VirtualBox MSI from 2009, which should trigger endpoint defenses. Unplanned disabling of backup and remote management utilities also merits follow-up. As this group is also known for exfiltrating data, expect threats of data disclosure to accompany ransom demands.

Lee Neely
Read more in
The Register: Forget BYOD, this is BYOVM: Ransomware tries to evade antivirus by hiding in a virtual machine on infected system
SC Magazine: Attackers' use of virtual machine to hide ransomware is a first, say researchers
ZDNet: Ransomware deploys virtual machines to hide itself from antivirus software
Bleeping Computer: Ransomware encrypts from virtual machines to evade antivirus
Sophos: Ragnar Locker ransomware deploys virtual machine to dodge security