Categories: MalwareRansomware

REvil Ransomware 2.2 Released – Now Encrypts Open and Locked Files

REvil Ransomware also known as Sodinokibi observed wild at the end of April 2019. The REvil ransomware is a part of Ransomware-as-a-Service (RaaS) where a set of people maintain the source code and other affiliate groups distribute the ransomware.

Researchers believe that REvil and GandCrab ransomware are similar, since the emergence of REvil, GandCrab activity declined and codes are shared.

REvil Ransomware 2.2

The new version of the ransomware uses Windows Restart Manager API to terminate processes that open the file targeted for encryption.

This is because if the file is opened by a specific process then another process on the same file will be terminated by the Windows system.

Intel471, researchers have spotted that Sodinokibi is now implemented this technique using the Windows Restart Manager also used by other ransomware such as SamSam and LockerGoga.

“REvil ransomware opens files for encryption with no sharing (dwShareMode equals 0). As a result, the Restart Manager is invoked whenever a sharing violation occurs when opening an already opened file.”

Also, the attackers included a command-line option -silent that skips blacklisted processes, services, and shadow copy deletion.

The popular analyst Vitali Kremez noted that REvil Decryptor v2.2 also leverages Windows Restart Manager API to shut down any process that files being decrypted.

With the newly added capabilities now the REvil Ransomware can encrypt some highly critical files.

You can also read the “Ransomware Attack Response and Mitigation Checklist” to prevent yourself from the ransomware attack.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Microsoft Strengthens Trust Boundary for VBS Enclaves

Microsoft has introduced a series of technical recommendations to bolster the security of Virtualization-Based Security…

12 minutes ago

Hackers Exploiting Business Relationships to Attack Arab Emirates Aviation Sector

A sophisticated cyber espionage campaign targeting the aviation and satellite communications sectors in the United…

14 minutes ago

Microsoft Removing DES Encryption from Windows 11 24H2 and Windows Server 2025″

Microsoft has announced the removal of the Data Encryption Standard (DES) encryption algorithm from Kerberos…

18 minutes ago

Researchers Unveil APT28’s Advanced HTA Trojan Obfuscation Tactics

Security researchers have uncovered sophisticated obfuscation techniques employed by APT28, a Russian-linked advanced persistent threat…

20 minutes ago

GrassCall Malware Targets Job Seekers to Steal Login Credentials

A newly identified cyberattack campaign, dubbed GrassCall, is targeting job seekers in the cryptocurrency and…

22 minutes ago

Bypassing AV Detection & Anti-Malware Scans with Red Team Tool SpecterInsight

In an era where antivirus (AV) solutions and anti-malware scan interfaces (AMSI) are becoming increasingly…

24 minutes ago