Ransomware And Its Criminal Use

Ransomware is a type of malicious software cyber criminals use to block you from accessing your own data. The digital extortionists encrypt the files on your system and add extensions to the attacked data and hold them ‘hostage’ until the demanded ransom is paid. After the initial infection, the ransomware may attempt to spread throughout your network to shared drives, servers, attached computers, and other accessible systems. 

If the ransom demands are not met within the cyber criminals' timeframe, the system or encrypted data remains unavailable, or your data may be deleted by the software and the decryption key obliterated. 

How Ransomware Works

There are a number of vectors ransomware can take to access a computer. One of the most common delivery systems is phishing email, this is an attachment that come to the victim in an email, masquerading as a file they should trust. Once they're downloaded and opened, they can take over the victim's computer.

Ransomware enters your network in a variety of ways, the most popular is a download via a spam email attachment. The download then launches the ransomware program that attacks your system. 

Other forms of entry include social engineering, downloads of the malicious software from the web that can be direct from a site or by clicking on “malvertising,” fake ads that unleash the ransomware. The malware can also be spread through chat messages or even removable USB drives.

Typically, the software gets introduced to your network by an executable file that may have been in a zip folder or disguised as a fax or other viable attachment. The download file then encrypts your data, adds an extension to your files and makes them inaccessible. 

More sophisticated versions of the software are propagating themselves and can work without any human action. Known as “drive-by” attacks, this form of ransomware infects your system though vulnerabilities in various browser plugins.
Without ponying up the money for the key, it is very difficult to decrypt files after an attack. Of course, good backup eliminates the need to succumb to ransomware demands.

Ransomware attackers are honing their distribution plans to hit those organizations that are more likely to pay the ransom demand ,such as healthcare, government, education and small businesses.

How To Defend Against Ransomware

Whether you need to know how defend against CryptoLocker or any of the other 4,000 daily attacks, the first component of the solution is to warn co-workers against downloading suspicious file attachments. They won’t prevent all attacks, but it will help. It is also critical to ensure that your servers are being patched regularly, as many security gaps that ransomware hackers take advantage of are often protected in the latest Microsoft patches.  

Failing to stay up to date can cause major issues down the line.  No matter what, you have to prepare to be hit.  So it’s critical you not only have backups, but secure, tested backups and a well-documented, secure disaster recovery plan if the attack is pervasive enough.  On the data protection side of things, keep these 5 components in mind:

Backup & Protect 

Experts have suggested a number of ways private individuals and organisations can protect their computer systems against cyber-attacks. Blocking suspicious Internet and email accounts and avoiding downloading programs that are not secure are some of the cheap and effective ways of protecting against ransomware, but will not block all forms of the software.

Organisations are warned to back up data on separate networks or on a cloud-based system to ensure continuity of business, should a successful attack be carried out. 

Follow the 3-2-1- rule. Three copies of your data, 2 different types of media and 1 version stored off-site. If you do get hit by ransomware you’ll have an easy escape.  You can even consider keeping a backup offline (on tape or rotational media), but recovery times are longer from offline backups, and offline backups are more difficult to test.

Secure

Ransomware predominantly targets Windows OS. As backup systems can require many role-based instances for centralised management, data movement, reporting, search and analytics, securing all those machines can be complex. Consider locking them down to do only what they are required, and nothing more. Newer solutions based on integrated backup appliances typically remove that complexity and come hardened out of the factory.So security can be far simpler in those newer architectures.

Test

Test the viability of your backup and disaster recovery strategy regularly. A lot of factors can impact recovery, including backups of machines that already contain ransomware.  Test automation is becoming a trend in the data management and data protection industry. It is important those features are used more as security threats become more impactful to IT.

Detect

Early ransomware detection means faster recovery. More backup vendors are starting to use predictive analytics and machine learning to recognize possible attacks and alert administrators of abnormal fluctuations of data as backups are ingested.

Recovery

If you’ve effectively backed up your data and tested its recoverability you will be ready to roll back your network to a safe restore point and avoid downtime, data failure and revenue loss.

Ransomware attackers are ferocious. If you haven’t been attacked yet, it’s not a matter of if, but when…be prepared.

Forbes:       Unitrends:       CSO Online:           Irish Examiner:         Washington Post

You Might Also Read:

Will Governments Ban Ransom Payments To Hackers?:

 

« Get The Best Cyber Security Audits & Training
Denmark Helped NSA Spy On European Union »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Montash

Montash

Montash is an award winning, global technology recruitment business, specialising in the acquisitions of high-performing talent across a number of core disciplines including Information Security.

Ripjar

Ripjar

Ripjar is a global company of talented technologists, data scientists and analysts designing products that will change the way criminal activities are detected and prevented.

Quality Professionals (Q-Pros)

Quality Professionals (Q-Pros)

QPros are a recognized leader in providing full-cycle software quality assurance and application testing services.

Egerie

Egerie

EGERIE's RiskManager solution provides a Global, Centralized, and Updated view of risk maps and security measures for your company.

Siscon

Siscon

Siscon delivers tailor-made compliance solutions that are based on the customer's specific wishes and reality and then supplement with many years of experience in the field.

Red Balloon Security (RBS)

Red Balloon Security (RBS)

Red Balloon Security is a leading embedded device security company, delivering deep host-based defense for all devices.

Garrison Technology

Garrison Technology

Garrison SAVI® is a unique technology for secure remote browsing that can dramatically change the risk profile for enterprise cyber security.

C11 Cyber Security & Digital Innovation Centre

C11 Cyber Security & Digital Innovation Centre

C11 is working with local and national partners to develop talent and bring brilliant minds and brilliant businesses together.

Zeusmark

Zeusmark

Zeusmark are a digital brand security company. We enable companies to successfully defend their brands, revenue and consumers online.

Envelop Risk

Envelop Risk

Envelop Risk is a global specialty cyber insurance firm, combining decades of insurance industry expertise with sophisticated cyber and artificial intelligence-based analytics.

OnDefend

OnDefend

OnDefend delivers information security solutions that improve overall security posture, reduce risks and defend against continually evolving and persistent cyber adversaries.

comforte AG

comforte AG

comforte AG is a leading provider of data-centric security technology. Organizations worldwide rely on our tokenization and format-preserving encryption capabilities to secure personal, sensitive data

Axellio

Axellio

Axellio provides economic, end-to-end cyber security solutions designed for your team, environment, and security objectives, providing packet level visibility across your network.

KATIM

KATIM

KATIM is a leader in the development of innovative secure communication products and solutions for governments and businesses.

Mogwai Labs

Mogwai Labs

Mogwai Labs deliver cutting-edge penetration tests, security assessments and trainings, to safeguard your applications, networks and cloud environments from cyber threats.

Chorus

Chorus

Chorus are a leading Managed Security Service Provider (MSSP), and member of the Microsoft Intelligent Security Association (MISA), with three Microsoft Advanced Specialisations in security.