Live Breaking News & Updates on Volume Shadow Copies

Stay updated with breaking news from Volume shadow copies. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.

Ryuk Ransomware: Now with Worming Self-Propagation


The Ryuk scourge has a new trick in its arsenal: Self-replication via SMB shares and port scanning.
A new version of the Ryuk ransomware is capable of worm-like self-propagation within a local network, researchers have found.
The variant first emerged in Windows-focused campaigns earlier in 2021, according to the French National Agency for the Security of Information Systems (ANSSI). The agency said that it achieves self-replication by scanning for network shares, and then copying a unique version of the ransomware executable (with the file name rep.exe or lan.exe) to each of them as they’re found.
“Ryuk looks for network shares on the victim IT infrastructure. To do so, some private IP ranges are scanned: 10.0.0.0/8; 172.16.0.0/16; and 192.168.0.0/16,” according to a recent ANSSI report. “Once launched, it will thus spread itself on every reachable machine on which Windows Remote Procedure Call accesses are possible.” ....

Key Distribution Center , French National Agency , Information Systems , Windows Remote Procedure Call , Address Resolution Protocol , Server Message Block , Volume Shadow Copies , Ryuk Worm Infection , Mutual Exclusion Objects , Active Directory , Web Security , Mobile Security , விசை விநியோகம் மையம் , தகவல் அமைப்புகள் , ஜன்னல்கள் தொலைநிலை ப்ரொஸீஜர் அழைப்பு , சேவையகம் செய்தி தொகுதி , தொகுதி நிழல் பிரதிகள் , பரஸ்பர விலக்கு பொருள்கள் , செயலில் அடைவு , வலை பாதுகாப்பு , கைபேசி பாதுகாப்பு ,