417. Ransomware Gangs Abuse Microsoft Windows Recovery Agent

Hello everyone!

Today, we’ll take another look at the Inhibit System Recovery (T1490) technique, this time focusing on how threat actors use the Microsoft Windows Recovery Agent.

As you already know, attackers do not always limit themselves to deleting shadow copies. They may also disable other operating system recovery capabilities. In this case, the attackers also disabled the Windows Recovery Environment (WinRE). To do so, the Settra ransomware executed the following command:

reagentc /disable

Of course, this activity can be legitimate. Nevertheless, it is quite suitable for proactive threat hunting:

event_type: "processcreatewin"

AND

proc_file_path: "reagentc.exe"

AND

cmdline: "disable"

Once again, it is worth noting that although this was part of the ransomware’s functionality in this particular case, the same technique can also be used by attackers as part of their preparations for encrypting an IT environment.

See you soon!

Comments

Popular posts from this blog

343. Ransomware Gangs Abuse SystemSettingsAdminFlows to Evade Defenses

391. Hunting for TeamPCP's Stealer

388. Ransomware Gang Abuses FTK Imager for Defense Evasion