"Maze Ransomware Adopts Ragnar Locker Virtual-Machine Approach"

The operators of Maze ransomware have started distributing ransomware payloads via virtual machines (VM).  Researchers at Sophos Managed Threat Response believe that the adversaries distribute the ransomware using virtual machines because it should help the ransomware get around endpoint defenses.  The maze malware is being distributed in the form of a VirtualBox virtual disk image (a VDI file).

Threatpost reports: "Maze Ransomware Adopts Ragnar Locker Virtual-Machine Approach"

Submitted by Anonymous on