Skip to main content
JS
Jacob Santos

Jacob Santos

Threat Hunter, Researcher and Builder

Sr. Threat Researcher | Trend AI
17
Articles
14
Threads
10+
Tools
10+
Talks
Multistage RA World Ransomware Uses Anti-AV Tactics, Exploits GPO
Trend AI Research Blog Mar 2024

Multistage RA World Ransomware Uses Anti-AV Tactics, Exploits GPO

RansomwareGPO AbuseSafe Mode

RA World ransomware employs a sophisticated multistage attack chain that abuses legitimate Windows infrastructure for maximum impact. The operators distribute their payloads through Group Policy Objects (GPO), ensuring enterprise-wide deployment across Active Directory environments. A key evasion technique involves rebooting infected machines into Safe Mode, where most security products don't load, before executing the encryption routine. The ransomware itself is derived from Babuk source code with modifications to the encryption implementation. This article traces the full kill chain from initial domain compromise through GPO abuse to encryption, with detailed analysis of each stage.