Locky ransomware continues to bypass security

XORed JavaScript used to evade detection

Hackers looking to plant Locky ransomware on victim's systems are using XOR obfuscation and reversing the bytes on the payloads to evade detection by network security tools.

According to investigations by security firm Proofpoint, the use of malware loaders such as RockLoader paired with the usage of malicious Javascript files has allowed Locky to remain a top threat among email distributed ransomware.

Researchers at the firm recently observed a Locky distributor embarking on further efforts to make their ransomware more elusive and effective.

"These campaigns continue to demonstrate the trend of threat actors shifting delivery mechanisms and adding new layers of obfuscation and evasion to bypass security defences. In the example above, the initial payload was actually the RockLoader malware loader which then attempted to install Locky from a sophisticated command and control (C&C) architecture," researchers at Proofpoint said in a blog post.

Advertisement
Advertisement - Article continues below

XOR obfuscation disguises the code of the malicious ransomware as something that makes looks like it was part of the original binary code.

"Last week, though, we observed one Locky actor (affiliate ID 1) begin using XOR obfuscation and reversing the bytes on the payloads to evade detection by network security tools," said the researchers.

This technique has been proven to be fast and effective, which has made it a popular choice among threat actors.

"While this type of obfuscation can be particularly effective against network security products that primarily scan executables entering the network, they can also be used for sandbox evasion," they said.

The researchers recommended that users have layered forms of security to counteract the techniques of Locky, especially since it is harder than ever to be detected.

Featured Resources

Application security fallacies and realities

Web application attacks are the most common vulnerability, so what is the truth about application security?

Download now

Your first step researching Managed File Transfer

Advice and expertise on researching the right MFT solution for your business

Download now

The KPIs you should be measuring

How MSPs can measure performance and evaluate their relationships with clients

Download now

Life in the digital workspace

A guide to technology and the changing concept of workspace

Download now
Advertisement

Recommended

Visit/cloud-security/34458/what-is-cloud-security
cloud security

What is cloud security?

20 Sep 2019

Most Popular

Visit/strategy/28115/the-pros-and-cons-of-net-neutrality
Business strategy

The pros and cons of net neutrality

4 Nov 2019
Visit/security/ransomware/354171/microsoft-issues-statement-debunking-teams-ransomware-rumours
ransomware

Microsoft issues statement debunking Teams ransomware rumours

21 Nov 2019
Visit/public-cloud/34850/salesforce-takes-aws-relationship-to-the-next-level
News

Salesforce takes AWS relationship to the next level

19 Nov 2019
Visit/mobile/5g/354161/tests-show-uks-5g-network-is-450-faster-than-4g
5G

Tests show UK's 5G network is 450% faster than 4G

20 Nov 2019