Yatron Ransomware-as-a-Service
Yatron is a newly observed ransomware-as-a-service tool based on the well-known HiddenTear ransomware family.
Summary
Yatron is a newly observed ransomware-as-a-service tool based on the well-known HiddenTear ransomware family.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, Yatron is being distributed primarily via spam campaigns. However, once an initial device is affected Yatron has several methods for further propagation. It will copy itself to all removable drives, as well as folders used by several popular peer-to-peer (P2P) applications. Yatron will also attempt to propagate to other devices on the network using EternalBlue and DoublePulsar exploits; however, the code used to do this appears to be incomplete.
Once delivered, Yatron will attempt to bypass User Access Controls before encrypting all non-system files using an unknown algorithm. It will then display a dialogue window demanding payment, claiming the files will be deleted if the ransom is not paid within 72 hours.
Remediation steps
| Type | Step |
|---|---|
|
Yatron's ransom note is displayed from a running process. Users can terminate this process to prevent deletion of encrypted files. If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 14 February 2020 2:47 pm