Updated Ransomware Plays Hide and Seek
Craig Petronella
PetronellaTech.com?, ComplianceArmor.com?, BlockchainSecurity.com???CMMC Certified RP?#1 Amazon Best Selling Author, Blockchain, AI, Crypto, CMMC, FTC, NIST 800-171, 800-172, DFARS, CUI, HIPAA, PCI, GDPR, ADA, SOC, ISO
Cerber is one of the more popular variations of ransomware. A new version has been detected, and it has a few new tricks up its sleeve.
The latest version of Cerber extracts itself from a hacker-owned Dropbox account. The self-extraction makes it look safe to machine-learning tools, which is one way it avoids detection. It also checks to see if it's installing itself onto a virtual machine, which cybersecurity companies use to detect and study malware. If Cerber sees that it is being installed on a virtual machine, it stops the installation, making it harder for the good guys to fight it.