Thursday June 26, 2025
Advertisement
Edit
The Current Bite The Current Bite
  • most recent news
  • trending news
  • most read
  • All Video
  • Image gallery
  • more
Technology

Introducing Windows 11

August 21, 2021
Technology

Launching Mi 5X Series

August 26, 2021
Mobile

Infinix Hot 11S India

August 27, 2021
News

Xiaomi to invest $10bn

September 1, 2021
News

FBI Alerts About Hive

September 1, 2021
Mobile

OnePlus Buds Pro Matte

September 2, 2021
  • Accessibility
  • Help
  • Contact
  • About qoxag
The Current Bite The Current Bite

Breaking News

EXCLUSIVE: Rani Mukerji reunites with Shah Rukh Khan on King;

ThalapathyVijay’s #GOAT is a cinematic masterpiece!

Border 2 Gets Even Stronger! Diljit Dosanjh Joins the Squad

Fans Demand Mr. India 2 After Viral BTS Pic

Rajkummar Rao Shares Unseen BTS Pic from Stree 2: “Deleted

AMMA Leadership Resigns Amid Sexual Misconduct Allegations

“Stree 2 Success Party: New Photos of Shraddha Kapoor, Kriti

“Explained: The Arshad Warsi-Prabhas Controversy—’Joker’ Comment and Reactions from Nani

“‘Stree 2’ Global Box Office Update on Day 7: Shraddha

IC 814: The Kandahar Hijack | Official Trailer | Vijay

The Current Bite The Current Bite
  • Home
  • News
  • Technology
  • Entertainment
  • Sports
  • Gadgets
  • Finance
  • TCB-How to
  1. Home
  2. News
  3. Hackers use AnyDesk in safe mode to launch attacks – Sophos
 Hackers use AnyDesk in safe mode to launch attacks – Sophos
News Technology

Hackers use AnyDesk in safe mode to launch attacks – Sophos

by VICKY December 30, 2021 0 Comment

Avos Locker remotely accesses boxes, even running in Safe Mode

Infections involving this relatively new ransomware-as-a-service spiked in November and December
Written by   Andrew Brandt
Over the past few weeks, an up-and-coming ransomware family that calls itself Avos Locker has been ramping up attacks while making significant effort to disable endpoint security products on the systems they target

Guidance and detection

Working in Safe Mode makes the job of protecting computers all the more difficult, because Microsoft does not permit endpoint security tools to run in Safe Mode. That said, Sophos products behaviorally detect the use of various Run and RunOnce Registry keys to do things like reboot into Safe Mode or execute files after a reboot. We have been refining these detections to reduce false positives, as there are many completely legitimate tools and software which use these Registry keys for normal operations.

Ransomware, especially when it has been hand-delivered (as has been the case in these Avos Locker instances), is a tricky problem to solve because one needs to deal not only with the ransomware itself, but with any mechanisms the threat actors have set up as a back door into the targeted network. No alert should be treated as “low priority” in these circumstances, no matter how benign it might seem. The key message for IT security teams facing such an attack is that even if the ransomware fails to run, until every trace of the attackers’ AnyDesk deployment is gone from every impacted machine, the targets will remain vulnerable to repeated attempts. In these cases, where the Avos Locker attackers set up access to their organization’s network using AnyDesk, the attackers can lock out the defenders or run additional attacks at any time as long as the attackers’ remote access tools remain installed and functional.

Various activities by the threat actors were detected (and blocked) by the behavioral detection rules Exec_6a and Exec_15a. Intercept X telemetry showed that the CryptoGuard protection mechanism was invoked when the ransomware attackers tried to run their executable. Sophos products will also detect the presence of Chisel (PUA), PSExec (PUA), and PSKill (PUA), but may not automatically block these files, depending on the local policies set up by the Sophos admin.

Share This:

  • 0
    Facebook
Tags: #anydesk #anydeskhack #hacking #sophos #tcb #technology #virus
Previous post
Next post

VICKY

administrator

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Categories

  • Entertainment
  • Finance
  • Gaming
  • Mobile
  • Movies Trailers
  • News
  • Sports
  • TCB-How to
  • Technology
  • Uncategorized
Most Recent
Entertainment

EXCLUSIVE: Rani Mukerji reunites with Shah Rukh

May 16, 2025
Entertainment

ThalapathyVijay’s #GOAT is a cinematic masterpiece!

September 6, 2024
Entertainment

Border 2 Gets Even Stronger! Diljit Dosanjh

September 6, 2024
Entertainment

Fans Demand Mr. India 2 After Viral

August 28, 2024
Social Profile

Daily Newsletter

Get all the top stories from Qoxag to keep track.

RELATED Stories for you
Entertainment

Citadel: Honey Bunny Teaser | Raj &

by VICKY August 1, 2024

The upcoming series, Citadel: Honey Bunny, directed by the dynamic duo Raj & DK,

News Technology

Dangerous new malware dances past more than

by VICKY July 9, 2022

Specialists have found a new malware test fit for stowing away from more than

Mobile Technology

Tips for how transfer whatsapp chat from

by VICKY June 21, 2022

The year before, WhatsApp announced a new feature that lets users transfer their chat

Copyright © 2025 Teqtive Solutions. All Right Reserved.