Back to Resources

SentinelOne VS Zeon Ransomware – Detection, Response and Remediation

Zeon ransomware is a Python-based malware that was first reported in January 2022. The ransomware is packaged using PyInstaller and obfuscated using PyArmor, and is a predecessor to the Royal ransomware operation. Zeon’s operators threaten victims with the public exposure of their internal data in ransom notes, stating that they will publish the data on their news website if the victim does not comply.

On execution, Zeon ransomware payloads attempt to stop any services or processes that could inhibit the encryption process, including backup processes, utilities, and security products from McAfee, Sophos, and Kaspersky. The ransomware uses both taskkill.exe and net.exe to terminate these processes.

To achieve persistence, Zeon generates and executes a scheduled task via cmd.exe. SentinelOne Singularity XDR protects against Zeon ransomware attacks.

#Zeon #ransomware

지금 읽기

세계에서 가장 앞선 사이버 보안 플랫폼 경험하기

지능적인 자율형 사이버 보안 플랫폼이 현재와 미래의 조직을 어떻게 보호할 수 있는지 알아보세요.