New strain of REvil ransomware on the prowl
Hackers have reportedly come up with a new variant of REvil ransomware and are particularly targeting Windows 10 PCs.
The new ransomware is capable of taking over the computer and initiate rebooting process. It restarts the PC into Safe Mode to perform the encryption of files, reported Bleeping Computer citing an independent security researcher, who goes by the moniker R3MRUM.
By rebooting the device in Safe Mode, the new REvil ransomware can bypass the security of the PC and also stop all backup software, database servers, and mail servers to complete the encryption.
It also changes the login password and would return control only after the user pays up the ransom.