Snatch: Virus Rebooting Your PC in Safe Mode to Bypass Antivirus
Snatch

Keeping your software up to date, having a basic security suite, and being careful with clicks and downloads are the usual recommendations (and the most frequent ones) for protecting your devices—but we know they're not perfect. Malware adapts, and its developers grow cleverer. Snatch is a striking example. Instead of wasting time and resources trying to bypass antivirus software, this ransomware escapes it by running in Windows Safe Mode, completely unopposed.

Malware has managed to hide in almost every format imaginable: emails, documents, Excel templates, games. It has infected specific extensions, boot sectors, and even firmware. In recent times, the concept of ransomware has gained ground aggressively, with campaigns harming companies, government agencies, and public health systems. Naturally, the major security solutions responded to the threat, but the story is far from over.

The problem (if you can call it that) is that most of these solutions run in a conventional Windows environment with all its components loaded. If you enter Safe Mode (a.k.a. "fail-safe" mode), they don't activate. In other words, Safe Mode creates a completely unprotected space—and that's what Snatch exploits.

https://vimeo.com/378363798

The folks at Sophos (who have been investigating a ransomware campaign over the past few weeks) shared an excellent demonstration of Snatch in action. The first step is to force the computer to reboot into Safe Mode using the "shutdown" command, and then it reloads in that mode as if it were a Windows service (courtesy of a Registry chain). User files are effectively encrypted during the reboot, and then it's just the classic ransom demand.

https://old.neoteo.com/the-malware-museum-ejemplos-historicos-de-malware-a-tu-alcance/

Of course, everything depends on how Snatch's payload gets onto the machine, but once it does and manages to execute... game over. The people behind this ransomware decided not to fish for small fry; they prefer to hunt sharks, meaning they concentrate their efforts on large companies and government agencies. However, that doesn't stop other malicious developers from borrowing the Safe Mode trick and applying it to their creations.

Now, the masterminds behind Snatch don't limit themselves to data encryption. The Sophos team discovered a marked interest in recruiting new members with privileged access to corporate networks, stores, and other companies. In essence, they have no problem paying to get into an already-hacked network, or joining forces with other actors.

At the same time, Sophos has evidence of stolen data from this group. A company targeted by Snatch not only risks ending up with encrypted and hijacked files; there's also the chance they'll be sold on the black market.

Source: Sophos

https://old.neoteo.com/programas-de-seguridad-para-android