Neo23x0 / Raccine

A Simple Ransomware Vaccine
The Unlicense
942 stars 123 forks source link

Prometheus / Thanos Ransomware kills Raccine process #126

Closed certrik closed 3 years ago

certrik commented 3 years ago

In an article from Unit42 it is described that at least Prometheus / Thanos Ransomware actively tries killing Raccine processes in order to operate.

It seems that Raccine will be needing advanced evasion techniques starting now in order to still be effective.

Neo23x0 commented 3 years ago

This shouldn't be a problem anymore. Newer versions of Raccine also intercept calls to taskkill.exe and kill the process that try to kill Raccine.