New Ransomware Found Exploiting Former Windows Zero-Day Flaw

The Windows vulnerability was last seen being used in a small number of targeted attacks.

Advertisement
By Indo-Asian News Service | Updated: 6 July 2019 16:53 IST

Geographic spread of Sodin ransomware from April to June 2019

Photo Credit: Kaspersky

Researchers at cybersecurity firm Kaspersky have uncovered new encryption ransomware named Sodin (Sodinokibi or REvil) that exploits a recently discovered Windows vulnerability to get elevated privileges in an infected system. The ransomware takes advantage of the architecture of the central processing unit (CPU) to avoid detection - functionality that is not often seen in ransomware.

"Ransomware is a very popular type of malware, yet it's not often that we see such an elaborate and sophisticated version: using the CPU architecture to fly under the radar is not a common practice for encryptors," said Fedor Sinitsyn, a security researcher at Kaspersky.

"We expect a rise in the number of attacks involving the Sodin encryptor, since the amount of resources that are required to build such malware is significant. Those who invested in the malware's development definitely expect if to pay off handsomely," Sinitsyn added.

Advertisement

The researchers found that most targets of Sodin ransomware were found in the Asian region: 17.6 percent of attacks have been detected in Taiwan, 9.8 percent in Hong Kong and 8.8 percent in the Republic of Korea.

Advertisement

However, attacks have also been observed in Europe, North America and Latin America, Kaspersky said, adding that the ransomware note left on infected PCs demands $2500 worth of Bitcoin from each victim.

The vulnerability CVE-2018-8453 that the ransomware uses was earlier found to be exploited by the FruityArmor hacking group. The vulnerability was patched on October 10, 2018, Kaspersky said.

Advertisement

To avoid falling victim to Sodin threats, make sure that the software used in your company is regularly updated to the most recent versions, said Kaspersky researchers.

Security products with vulnerability assessment and patch management capabilities may help to automate these processes, they added.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Apple's iOS 26.1 May Launch on This Date, Followed By iOS 26.2 Beta Rollout
  2. Realme GT 8 Pro Aston Martin F1 Limited Edition Launch Date Revealed
  3. OnePlus 15 to Get New OP Gaming Core Tech for Smoother Gameplay
  4. Samsung Galaxy S26 Series Could Launch on This Date
  5. Vivo Y19s 5G Launched in India With 6,000mAh Battery: See Price
  6. You Might See New Product Displays at Apple Retail Stores On This Date
  7. Lenovo AI Glasses V1 Debuts With Real-Time Translation, Micro LED Displays
  1. Oppo Reno 15 Series India Launch Timeline Leaked; Reno 15 Mini Also Expected to Debut
  2. India Is Shaping a Global Framework for Ethical and Human-Centric AI: PM Modi
  3. Sotta Sotta Nanaiyuthu Streaming Now on OTT: Know Where to Watch This Tamil Comedy Drama Movie Online
  4. Robin Hood Season 1 Now Streaming on Prime Video: Everything You Need to Know
  5. Bitcoin Price Drops Below $107,500 Amidst Weakening Spot Demand, Macro Uncertainty
  6. Realme GT 8 Pro Aston Martin F1 Limited Edition Launch Date, Design Revealed
  7. Vivo Y19s 5G Launched in India With 6,000mAh Battery, Dimensity 6300 SoC: Price, Specifications
  8. ChatGPT Atlas, Perplexity’s Comet and Other AI Browsers Can Bypass Paywalls: Report
  9. Silent Hill 2 Remake's Xbox Series S/X Version Listed on ESRB Website, Suggesting Upcoming Launch
  10. Vivo S50, Vivo S50 Pro Mini Reportedly Clear Radio Certification Before Launch in China
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.