Did You Know That Ransomware Can Stop SQL So It Can Encrypt The Database?

Stu Sjouwerman | Oct 9, 2016
Cerber RansomwareI have been knee deep into Ransomware since September 2013 when the granddaddy of modern ransomware CryptoLocker made well over 20 million bucks in a few months. But sometimes I learn something new that even surprises me.

This week, Larry Abrams reported that the latest version of Cerber ransomware switches to random extensions (almost wrote "ransom extensions") and ends database processes so that it can access the sql datastore itself and encrypt that:

"This update also includes the addition of new database processes that are closed by the close_process directive in Cerber's configuration. This directive tells Cerber to terminate certain processes before encryption begins."

These are things like msftesql.exe, sqlagent.exe, sqlservr.exe and many more. Larry commented: "This is not something particular new, and other ransomware have been doing it for some time." Yikes. Here is the whole article:
http://www.bleepingcomputer.com/news/security/cerber-ransomware-switches-to-a-random-extension-and-ends-database-processes/

Topics: Ransomware

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.