Vietnam.vn - Nền tảng quảng bá Việt Nam

LockBit attacks Windows Domain servers in Vietnam

Báo Thanh niênBáo Thanh niên07/03/2024


Security experts say the malware has made many more sophisticated improvements, both in its encryption script and in its spread, capable of bypassing conventional security solutions.

In the past 2 months, Bkav experts have continuously received requests for help from many businesses in Vietnam with the common situation that computers in the internal network were all encrypted at the same time, and the data could not be saved.

LockBit tấn công các máy chủ Windows Domain tại Việt Nam- Ảnh 1.

LockBit 3.0 is starting to 'explode' in Vietnam

Investigation and analysis results from many cases show that the culprit of data encryption is LockBit 3.0, also known as LockBit Black, a ransomware of a famous hacker group, recently destroyed by the International Police Alliance (including the UK's National Crime Agency - NCA, the US Federal Bureau of Investigation - FBI and the European Union Police Agency - Europol).

LockBit Black has more sophisticated improvements than previous variants. They are specifically designed to target Windows Domain management servers in the internal system. After infiltrating, the virus uses these servers to continue spreading to the entire system, disabling security solutions (disable anti-virus, firewall), copying and executing malicious code... In this way, the virus can encrypt all machines in the internal system at the same time without having to attack each machine as before.

Not only does LockBit Black change its method and target, it also has a more dangerous data encryption scenario. Instead of directly encrypting data upon launch, the virus escalates its privileges, then bypasses UAC, and finally reboots the victim's computer into Safe Mode (a mode where only the system and some applications are launched) and performs data encryption in this mode. In this way, the malware can bypass common security solutions.

To avoid being attacked by LockBit as well as other data encryption viruses, Bkav experts recommend that users and system administrators need to:

  • Backup important data regularly.
  • Do not open internal service ports to the internet when not necessary.
  • Evaluate the security of services before opening them to the internet.
  • Install strong enough antivirus software for constant protection.


Source link

Comment (0)

No data
No data
U23 Vietnam radiantly brought home the Southeast Asian U23 Championship trophy
Northern islands are like 'rough gems', cheap seafood, 10 minutes by boat from the mainland
The powerful formation of 5 SU-30MK2 fighters prepares for the A80 ceremony
S-300PMU1 missiles on combat duty to protect Hanoi's sky
Lotus blooming season attracts tourists to the majestic mountains and rivers of Ninh Binh
Cu Lao Mai Nha: Where wildness, majesty and peace blend together
Hanoi is strange before storm Wipha makes landfall
Lost in the wild world at the bird garden in Ninh Binh
Pu Luong terraced fields in the pouring water season are breathtakingly beautiful
Asphalt carpets 'sprint' on North-South highway through Gia Lai

Heritage

Figure

Business

No videos available

News

Political System

Local

Product