Ransomware Deploys Virtual Machines to Hide Itself from Antivirus Software

enovise.com
Published On 22 May 2020
Enovise
Summary
The operators of the RagnarLocker ransomware are installing Oracle VirtualBox on computers they infect and running their ransomware inside a Windows XP virtual machine — hiding malicious file encryption from local antivirus software in what Sophos confirmed as the first documented case of ransomware gangs abusing virtual machines operationally.
The operators of the RagnarLocker ransomware are running Oracle VirtualBox to hide their presence on infected computers inside a Windows XP virtual machine. The operators install the VirtualBox app and run virtual machines on computers they infect in order to execute their ransomware in a "safe" environment, outside the reach of local antivirus software. This technique was detailed by UK cyber-security firm Sophos and demonstrates the creativity and great lengths some ransomware gangs will go to avoid detection while attacking a victim.
What Is RagnarLocker?
Avoiding detection is crucial because RagnarLocker is not a typical ransomware gang. They carefully select targets, avoiding home consumers, and go after corporate networks and government organisations only. Sophos reports the group has targeted victims by abusing internet-exposed RDP endpoints and has compromised MSP (managed service provider) tools to breach companies and gain access to their internal networks.
On these networks, the RagnarLocker group deploys a version of their ransomware — customised per victim — and then demands an astronomical decryption fee in the range of tens and hundreds of thousands of US dollars. Because each carefully planned intrusion represents a chance to earn large amounts of money, the group has put a premium on stealth.
The Virtual Machine Trick
Instead of running the ransomware directly on the target computer, the RagnarLocker gang downloads and installs Oracle VirtualBox — software that allows virtual machines to run inside a host system.
The group then configures the virtual machine to give it full access to all local and shared drives, allowing the virtual machine to interact with files stored outside its own storage. The virtual machine runs a stripped-down version of the Windows XP SP3 operating system called MicroXP v0.82. The ransomware is then loaded and executed inside the VM.
Because the ransomware runs inside the VM, antivirus software on the host machine cannot detect the malicious process. From the antivirus software's point of view, files on the local system and shared drives are suddenly replaced with encrypted versions — and all file modifications appear to originate from a legitimate process: the VirtualBox application itself.
Mark Loman, director of engineering and threat mitigation at Sophos, confirmed this is the first time a ransomware gang has been observed abusing virtual machines during an attack: "In the last few months, we've seen ransomware evolve in several ways. But the Ragnar Locker adversaries are taking ransomware to a new level and thinking outside of the box."
Source: ZDNet / Sophos Research
You May Also Like
View Blogs
Kenya Threat Landscape Report 2024
The Kenya Threat Landscape Report, prepared by SOCRadar and Enovise, highlights various aspects of the cyber threat environment around Kenya — where public administration, information, and finance sectors collectively account for over 43% of observed incidents.

Enovise Group and SOCRadar Partnership
Enovise has partnered with SOCRadar to deliver advanced, proactive cybersecurity solutions for organisations across Africa, integrating SOCRadar's Extended Threat Intelligence platform with Enovise's Managed Detection and Response services.

Garmin South Africa Hack
Customer data for purchases made through the Garmin South Africa shop has been stolen — including payment card numbers, CVV codes, names, physical addresses, phone numbers, and email addresses — containing all the information required to make fraudulent purchases.

Hackers Stole and Encrypted Data of 5 US Law Firms
Hackers compromised five United States law firms and demanded two 100 Bitcoin ransoms from each firm — one to restore access to the data, one to delete their copy instead of selling it. The Maze group published part of the stolen data, threatening to release increasingly sensitive material unless paid.