Security News > 2021 > April > REvil ransomware now changes password to auto-login in Safe Mode

REvil ransomware now changes password to auto-login in Safe Mode
2021-04-07 20:06

A recent change to the REvil ransomware allows the threat actors to automate file encryption via Safe Mode after changing Windows passwords.

In March, we reported on a new Windows Safe Mode encryption mode added to the REvil/Sodinokibi ransomware.

At the time of our reporting, the ransomware required someone to manually login to Windows Safe mode before the encryption would start, which could raise red flags.

At the end of March, a new sample of the REvil ransomware was discovered by security researcher R3MRUM that refines the new Safe Mode encryption method by changing the logged-on user's password and configuring Windows to automatically login on reboot.

The ransomware then configures the following Registry values so that Windows will automatically login with the new account information.

These changes illustrate how ransomware gangs continuously evolve their tactics to successfully encrypt victims' devices and force a ransom payment.


News URL

https://www.bleepingcomputer.com/news/security/revil-ransomware-now-changes-password-to-auto-login-in-safe-mode/