Ransomware Gang Enhances Capabilities with Custom Data-Theft Tool.

1 min read
Source: BleepingComputer
Ransomware Gang Enhances Capabilities with Custom Data-Theft Tool.
Photo: BleepingComputer
TL;DR Summary

Play ransomware group has developed two custom tools, Grixba and VSS Copying Tool, to improve the effectiveness of its cyberattacks. Grixba is a network-scanning and information-stealing tool used to enumerate users and computers in a domain, while VSS Copying Tool allows attackers to interact with the Volume Shadow Copy Service (VSS) via API calls using a bundled AlphaVSS .NET library. Both tools enable attackers to gather information about security, backup, and remote administration software, and easily copy files from VSS to bypass locked files. Symantec discovered and analyzed the new tools and shared their findings with BleepingComputer before publishing their report.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

1 min

vs 2 min read

Condensed

73%

381101 words

Want the full story? Read the original article

Read on BleepingComputer