Jump to content

Recommended Posts

Posted

We look after businesses as well as schools.  One of our clients got hacked by Dragon Force - the scumbags behind Jaguar Landrover and M&S hacks - which we intercepted just in time and in the process managed to get their payload and encryptor tools out of quarantine (Avast Cloudcare) - all of which have been handed to the police.

 

Out of interest I just did a virustotal on the payload exe file.  62 out of 72 engines detect ransomware, Microsoft Defender and Malwarebytes detect Dragon Force ransomware.  Sophos gives the file a big green tick!  Yep its one of the 10 that is totally oblivious to what is now becoming the most prolific ransomware.

 

If you are relying on Sophos to protect endpoints alone get something like Threatdown installed as well asap.  

  • Like 1
Posted

We had a bad experience with Sophos a few years back, after it failed to detect a virus that changed PDF files to executables, and spread like wildfire across the server. To add insult to injury, their support was poor. We switched to ESET, so out of interest did their product detect it? (if they're on virustotal)

  • 3 weeks later...
Posted

Hi JTCOOP's

 

Thanks for posting, would it be possible to share the file / SHA-256 please?

 

VirusTotal is a very useful platform for performing static file scan test comparisons to allow threat hunters to get a quick feel for the "industry's view" of the suspiciousness file or URL. Any files uploaded to VT are shared with the 70+ vendors who partner with them. In this case, there could be a number of reasons why Sophos didn’t identify it as malicious when you checked. For example, it could be a delayed update synchronisation, or that we use other scanning techniques not currently used by VT to determine if the file is malicious or not, which is skewing the result in this case - access to the SHA-256 / file would mean we can investigate further why this sample isnt generating a detection.

 

Also many commercial entities or environments within an educational setting need to constantly remember that for a cyber attack to succeed then the threat actors in addition to attacking the endpoint / server, typically have to defeat email protection, web URL/Download scanning and firewall solutions / VPN / RDP portals - which are often not monitored or not fully patched to protect against latest vulnerabilites being actively exploited by gangs such as Dragon Force.

 

In 2026 Cyber Security must be treated with a holistic approach rather than as a number separate of point products. Which is why partnering with experts - be it MSSP or Vendor is critical for organisations risk mitigation steps against cyber attacks and provision of additional advisory services relating to areas such as Internal / External / Wifi Pen Tests, Tabletop Exercises or IR plans to help organisations mature their posture and policies. 

 

More as background information on typical attacks from Dragon Force, Sophos have a very good track record protecting customers against Dragon Force and have a number of press releases over the last few years discussing their RaaS system, tools and techniques etc. they use. For example https://www.infosecurity-magazine.com/news/dragonforce-ransomware-msp-attack/ where DragonForce threat actors compromised an MSP's SimpleHelp remote monitoring and management (RMM) software to push malicious installers over the MSP’s client networks. In this specific incident, a client of the MSP luckily was protected by Sophos Extended Detection and Response (XDR) and enrolled in the MDR service, which successfully thwarted the ransomware and data theft attempts due to effective behavioural detection and swift incident response actions. Other clients of the MSP not using Sophos MDR were significantly affected.

 

Sophos's Counter Threat Unit continuously monitors and analyzes groups like Dragon Force, providing real-time threat intelligence and guidance to organizations on how to implement robust cybersecurity strategies, such as patching vulnerabilities immediately, implementing multi-factor authentication (MFA) for RMM tools, and using advanced detection tools like XDR. 

 

Sophos Endpoint Protection includes a module called CryptoGuard which is designed for Anti-Ransomware and MBR protection. CryptoGuard is completely signatureless, and operates off the behaviour of the file encryption process (either local or increasingly used remote encryption process) and will protect the device and roll back encrypted files automatically. This is a highly-tuned protection system, and is capable of distinguishing between real-world encryption via malicious processes and what are simple encryption tests and does not respond to those tests to avoid exposing it’s behaviour and techniques to attackers. If you'd like to know more then please have a read of https://www.sophos.com/en-us/blog/cryptoguard-an-asymmetric-approach-to-the-ransomware-battle where we will delve into the different approaches made by many vendors and why some work and some dont (Microsoft's 2025 Digital Defences report https://www.microsoft.com/en-us/corporate-responsibility/dmc/en-us/corporate-responsibility/cybersecurity/microsoft-digital-defense-report-2025/ is also a good read for their view on Remote Encrypting Ransomware from unmanaged or unprotected devices).

 

Going back to your original point, if you can let me have the SHA-256 we can investigate.

 

Best Wishes

Roger Neal

Sophos

 

  • Like 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...