Home > Cyber News > Security Researcher Discovers Vulnerabilities in Popular Ransomware Families
CYBER NEWS

Security Researcher Discovers Vulnerabilities in Popular Ransomware Families

Security Researcher Discovers Vulnerabilities in Popular Ransomware Families

A security researcher known by the moniker h3perlinx discovered vulnerabilities in some of the most common ransomware families, including Conti, REvil, LockBit, AvosLocker, and the recently discovered Black Basta.

Security Researcher Discovers Weaknesses in Popular Malware

The discovered weaknesses could be leveraged to prevent file encryption from happening. The researcher analyzed numerous malware strains from the mentioned ransomware groups, and found out that they were all prone to DLL hijacking. Ironically, this method is often used by hackers to inject malicious code into legitimate applications.




If an attacker can get hold of a file on a targeted system (achievable via phishing and remote control), that file can be later executed when the user runs an application vulnerable to DLL hijacking. The technique works specifically on Windows systems by leveraging the way apps search for and load in memory their corresponding DLL files.

Furthermore, a program with insufficient checks can load DLLs from a path outside its directory, thus achieving elevated privileges or executing malicious code. In the case of the vulnerable samples of Conti, REvil, LockBit, LockiLocker, AvosLocker, and Black Basta, h3perlinx said that they exploit could allow code execution to control and terminate the malware in the pre-encryption phase. The exploit code the researcher created should be compiled into a DLL with a specific name to make it possible for the malicious code to recognize it as its own and load it to initiation file encryption.

The researcher provided reports for each analyzed malware piece and discovered weakness, including the sample’s hash, a proof-of-concept code, and a demo video. He has been tracking vulnerable malware in his malvuln project.

Milena Dimitrova

An inspired writer and content manager who has been with SensorsTechForum since the project started. A professional with 10+ years of experience in creating engaging content. Focused on user privacy and malware development, she strongly believes in a world where cybersecurity plays a central role. If common sense makes no sense, she will be there to take notes. Those notes may later turn into articles! Follow Milena @Milenyim

More Posts

Follow Me:
Twitter

Leave a Comment

Your email address will not be published.

Share on Facebook Share
Loading...
Share on Twitter Tweet
Loading...
Share on Google Plus Share
Loading...
Share on Linkedin Share
Loading...
Share on Digg Share
Share on Reddit Share
Loading...
Share on Stumbleupon Share
Loading...