New Microsoft file system technique can make ransomware ‘invisible’

Discussion in 'other security issues & news' started by guest, Nov 21, 2019.

  1. guest

    guest Guest

    New Microsoft file system technique can make ransomware ‘invisible’
    November 21, 2019
    https://www.siliconrepublic.com/enterprise/nyotron-ransomware-microsoft-file-system-invisible
    Nyotron Discovers Technique That Renders Ransomware Invisible to Security Software
    RIPlace Report (PDF - 753 KB): https://www.nyotron.com/collateral/RIPlace-report_compressed-3.pdf

    Nytron blog entry: Nyotron Discovers Potentially Unstoppable Ransomware Evasion Technique: “RIPlace”
     
  2. guest

    guest Guest

    New RIPlace Bypass Evades Windows 10, AV Ransomware Protection
    November 21, 2019
    https://www.bleepingcomputer.com/ne...s-evades-windows-10-av-ransomware-protection/
     
  3. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,296
    In the interests of testing, I ended up sacrificing a file on my desktop:
     

    Attached Files:

  4. B-boy/StyLe/

    B-boy/StyLe/ Registered Member

    Joined:
    Sep 19, 2012
    Posts:
    518
    Location:
    Bulgaria
  5. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,561
    Location:
    The Netherlands
    Interesting, has anyone tested this against tools like HMPA and AppCheck?
     
  6. guest

    guest Guest

    Thanos Ransomware Evading Anti-ransomware Protection With RIPlace Tactic
    November 18, 2020
    https://www.seqrite.com/blog/thanos...ti-ransomware-protection-with-riplace-tactic/
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.