Cybercriminals created fake forum posts on compromised websites to distribute samples of the Sodinokibi ransomware family.
In this infection, the ransomware payload used a PowerShell command to delete the victim’s Shadow Volume Copies before encrypting their data. It then displayed a ransom note that directed the victim to visit a portal hosted on Tor, which contained instructions to submit payment in exchange for a decryption tool.
A Look Back at Sodinokibi’s History
This is just the latest episode in Sodinokibi’s evolving history. Cisco Talos first discovered the ransomware back in April 2019. At that time, researchers observed the threat abusing CVE-2019-2725.
Just a few months later, Cybereason spotted several instances in which the ransomware went after South Korean security vendor Ahnlab to inject its malicious payloads into the trusted antivirus provider. In late August, Bleeping Computer reported on an attack in which Sodinokibi affected a remote data backup service used by hundreds of dental practices in the U.S.
Help Protect Against Sodinokibi Ransomware
To help protect against Sodinokibi ransomware, security leaders should consider investing in a single solution that can streamline their implementation of encryption, access controls, key monitoring and other anti-ransomware security controls. Organizations should build upon this solution using a multilayered defensive strategy that includes anti-malware tools, security awareness training and robust data backups.