03:36 PM
Connect Directly

New Free Tool Stops Petya Ransomware & Rootkits

Meanwhile, Locky puts ransomware on the Check Point Top Three Global Malware List for the first time ever.

Although Check Point reported today that ransomware operators have reached a new benchmark in their malicious spree, security researchers at Cisco Talos Labs have unveiled a new way to fight back. 

For the first time ever, reports Check Point, a ransomware strain has hit its Top Three Global Malware List -- specifically the Locky ransomware, which accounted for 6% of all attacks recognized globally during September.

Meanwhile, Cisco Talos has released a new free, open-source tool -- called MBRFilter -- to fight the insidious Petya ransomware and similar malware.

F-Secure first issued an alert about Petya in April. Most ransomware works by simply encrypting files; Petya uses a much different tactic, behaving more like a rootkit. Petya overwrites the system's Master Boot Record, which forces the system to reboot. On reboot, the malware encrypts the Master File Table of the infected system's hard drive.

The process happens more quickly than other ransomware's usual file-by-file grind. It leaves little time to notice there's a problem, much less call for help. 

MBRFilter defeats Petya in a rather simple, clever way. MBRFilter is a driver that simply places the MBR into read-only mode. Therefore, ransomware like Petya cannot overwrite the MBR or otherwise modify its contents. 

"Our vulnerability research team is constantly looking for new ways to exploit devices and identify ways to better protect them," says Craig Williams, senior technical leader and global outreach manager of Talos. "This project is a natural result." 

Although MBRFilter will not help organizations solve their problems with Locky, it has wide use beyond ransomware.

"This should be effective at stopping all rootkits which require MBR modification," says Williams. 

MBRFilter is a simple disk filter based on Microsoft's diskperf and classpnp example drivers. Cisco Talos Labs researchers caution security operations teams to test MBRFilter thoroughly before deploying it to production environments, because it was deliberately designed to be difficult to remove.

Related Content:



Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Joe Stanganelli
Joe Stanganelli,
User Rank: Ninja
10/21/2016 | 11:14:50 AM
Cut out the middle man
I suppose this proliferation only makes sense.  The bad guys are finding out that they can make more money and keep 100% of the cut by taking money directly out of their victims' pockets as opposed to fighting for scraps in the decimated spam market.
Who Does What in Cybersecurity at the C-Level
Steve Zurier, Freelance Writer,  3/16/2018
(ISC)2 Report: Glaring Disparity in Diversity for US Cybersecurity
Kelly Jackson Higgins, Executive Editor at Dark Reading,  3/15/2018
Voice-Operated Devices, Enterprise Security & the 'Big Truck' Attack
Menny Barzilay, Co-founder & CEO, FortyTwo Global,  3/15/2018
Register for Dark Reading Newsletters
White Papers
Current Issue
How to Cope with the IT Security Skills Shortage
Most enterprises don't have all the in-house skills they need to meet the rising threat from online attackers. Here are some tips on ways to beat the shortage.
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.