New SNAKE Ransomware is an Attack Mix of Obfuscation, Encryption, and Corporate Disruption

Stu Sjouwerman | Jan 14, 2020

Snake_Malware_Not_Detected_By_Antivirus_for_8_YearsBeware! This new targeted attack variant of ransomware is smart, sophisticated, and does a lot more than just encrypt files.

It’s inevitable that every attack vector – including ransomware – is going to evolve. In this latest iteration of the ongoing saga of bad guys encrypting your data for ransom comes SNAKE. According to MalwareHunterTeam (who first identified the variant), SNAKE ransomware has a higher level of obfuscation that normally found with ransomware – this helps to ensure the ransomware can make it past security solutions and result in a higher probability of infection.

It also works to delete Windows’ Shadow Volume copies (to eliminate the ability to easily recover), as well as kills a number of different types of processes related to security solutions, industrial control systems, remote and network management tools, and more. This can bring operations and IT support to a halt.

And, as if that wasn’t enough, SNAKE encrypts all non-OS critical files and leaves the victim with a ransom note found within a txt file:

ransom-note

Source: Bleeping Computer

This new ransomware should come as no surprise; the bad guys are constantly watching what the good guys (read: security vendors) are doing and are taking steps to make their malware as disruptive as is humanly possible – the more disruptive, the higher and more likely the payout.

Today, ransomware usually only finds entry in one of two ways: RDP connections or email. Locking down externally-facing RDP services fixes the former, and putting users through Security Awareness Training fixes the latter. The ransomware’s focus on obfuscation as part of the attack should be a warning that simply relying on security solutions is not going to be a surefire way to protect your environment; it’s only through educating your users to spot potentially malicious emails and to not engage with them that you can avoid newer, smarter, and more deadly strains of ransomware.

Ransomware Simulator

Free downloadable software tool

Threat actors are constantly coming out with new strains to evade detection. Is your network effective in blocking all of them when employees fall for social engineering attacks?

RanSim gives you a quick look at the effectiveness of your existing network protection. RanSim will test 24 ransomware infection scenarios and 1 cryptomining infection scenario and show you if a workstation is vulnerable.

RansIm-Monitor3Here's how it works:

  • 100% harmless simulation of real ransomware and cryptomining infections
  • Does not use any of your own files
  • Tests 25 types of infection scenarios
  • Just download the installer and run it
  • Results in a few minutes!

Get RanSim!

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.