Re-Thinking The Threat Of Ransomware

In the last year there has been an endemic use of ransomware on a large scale and at a global level.  To put this into context, a recent report from Druva estimated that 4,000 ransomware attacks occur each day, while a report from Verizon ranked ransomware as the number one piece of crime-ware used by cyber-criminals in 2017.

The National Cyber Security Centre has also identified ransomware as the most common cyber extortion method used by cyber-criminals to target UK businesses.

Ransomware is a type of malware that restricts access to a computer or its data and demands money for it to be released. The threat is typically spread via phishing emails, spam campaigns, drive-bys or programs downloaded to a computer by an unwitting user visiting an infected website. 

In May last year, WannaCry, one of the world’s most publicised ransomware variants caused global panic when it hit the NHS and left hospitals unable to access patient data. So, where did ransomware come from, is it a new threat, how is it evolving and, most importantly, what steps can organisations take to protect against it?

History of Ransomware 
Ransomware is not new and has been around since 1989 with the first ever documented case being the AIDS Trojan (or PC Cyborg ransomware) created by Joseph Popp, who distributed 20,000 infected floppy disk drives to the participants of the World Health Organisations AIDS Conference.

Since then, ransomware has appeared more frequently due to the amount of money that can be made using the technique.  
In 2017 the same report from Druva estimated that the ransomware industry has quadrupled over the past year, reaching an estimated $1 billion. As a result of the huge financial return on ransomware, cyber-criminals are constantly developing new variants in a bid in ensnare more victims and bypass security defenses.

The latest ransomware variants have deployed new strategies for the delivery of the malware. Whilst most ransomware typically requires some sort of user interaction, recent research has demonstrated how hackers have infected systems with WannaCry by exploiting a remote code execution (RCE) vulnerability, which allowed them to infect unpatched systems without user’s interaction. This is something that is usually associated with a worm rather than ransomware.

To Pay or Not to Pay
One of the key dilemmas an organisation faces when infected with ransomware is whether or not to pay the fine. This is particularly true for organisations that do not have a comprehensive back-up strategy in place and risk losing access to their files entirely if they do not pay. Whilst many law enforcement agencies and security practitioners often advise against paying ransoms for this criminal activity, reports suggest that severe disruption to services and the lack of backups sometimes leads to organisations giving in and paying the criminals for the release of their data.

However, as has been demonstrated in many recent attacks, even when organisations do pay the fine, there is no guarantee they will receive their files back. Additionally, in some cases when an organisation opts to the pay the ransom, they only receive part of their data back in return. 

This ultimately means organisations need to assess if paying the fine is worth it at all, when there is absolutely no way to know if the cybercriminals will ever return their files. 

Some businesses also believe that paying the fine makes sense because they believe their data is worth more than the ransom. However, the danger of paying is that they are essentially funding the ransomware industry, which will ultimately make it more profitable for cyber-criminals and lead to more attacks. So, what are the best ways to mitigate a ransomware attack without having to pay the fine? 

Protecting Against Ransomware
To protect against the tidal wave of ransomware attacks, organisations need to improve their software patching processes. Many organisations, for example the UK NHS, were caught out because they did not update their systems with the relevant patches in time.

Another lesson that can be learned from these events is that vulnerability disclosure practices within the industry need to improve as no single organisation can defend against these threats on its own. 

For any organisation that does fall victim to a ransomware attack, it is very important to carry out a post incident analysis. This will allow them to analyse how they contained the event and if there are any changes that could be made to improve their response, should a future attack occur.

Infosecurity- Magazine

You Might Also Read:

British IT Bosses Fear Sophisticated Cyber Threats:

FBI: Don’t Pay Bitcoin Ransomware:

 

 

« Australia's Largest Bank Lost The Personal Financial Histories Of 12m Customers
Hacker Group Targets Healthcare Providers »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

ThreatHunter.ai

ThreatHunter.ai

ThreatHunter.ai (formerly Milton Security) is a business that tracks down and mitigates attacks in real time using our ARGOS Platform and our Elite Threat Hunters.

Data Resolve Technologies

Data Resolve Technologies

Data Resolve offer a mechanism through which customers can detect and tackle various kinds of sensitive activities pertaining to data loss and data theft.

Institute for Cyber Security Innovation - Royal Holloway

Institute for Cyber Security Innovation - Royal Holloway

The Institute for Cyber Security Innovation aims to bring together Academia, Industry and Government to be a catalyst for applied research and innovation in cyber security policy and solutions.

Intelligent Waves

Intelligent Waves

Intelligent Waves holds and manages contracts to provide an array of intelligence, operational, communications and IT support to the USG in austere, forward-deployed, hazardous duty environments.

iHLS Startups Accelerator

iHLS Startups Accelerator

iHLS Accelerator is the first startup accelerator in the world in the security and homeland security field.

Orca Security

Orca Security

Orca Security delivers full stack visibility including prioritized alerts to vulnerabilities, compromises, misconfigurations, and more across your entire inventory on all your cloud accounts.

Collins Aerospace

Collins Aerospace

Collins Aerospace provides cybersecurity services and systems to protect critical infrastructure facilities and railroad operations.

NexGenT

NexGenT

NexGenT have combined military-style training with decades of network engineering and cyber security experience into an immersive program to get people into cyber security fast and effectively.

Stealth-ISS Group

Stealth-ISS Group

Stealth–ISS Group is your extended IT, cyber security, risk and compliance team, providing strategic guidance, engineering and audit services, along with technical remediation and security operations.

NightDragon

NightDragon

NightDragon is a venture capital firm investing in innovative growth and late stage companies within the cybersecurity, safety, security, and privacy industry.

Diligent

Diligent

Diligent's SaaS GRC platform gives leaders a connected view of governance, risk, compliance and ESG across their organization.

PKI Solutions

PKI Solutions

PKI Solutions offers Public Key Infrastructure (PKI) products, services, and training to help ensure the security of organizations now and in the future.

BuddoBot

BuddoBot

BuddoBot has been a pioneering force in cybersecurity and information technology since 2008.

Dispel

Dispel

Dispel makes the fastest secure remote access for industrial networks. Built by operators for operators: a zero trust engine for your entire OT, IoT, and xIoT stack.

Jitterbit

Jitterbit

Jitterbit integrates critical business processes and enables application development to deliver the experiences and insights needed by enterprises of all sizes to accelerate their digital journey.

Merkle Science

Merkle Science

Merkle Science provides next generation risk mitigation, compliance and forensics for crypto-native businesses, DeFi participants, financial institutions & government agencies.