Showing posts with label cyber criminals. Show all posts
Showing posts with label cyber criminals. Show all posts

Monday, June 22, 2020

Demystifying Ransomware - The Cyber Pandemic Spreads Wings


By Sharda Tickoo, Director – Technical, Trend Micro India

With an evolving digital landscape and the rapid proliferation of sophisticated cyberattacks, security can no longer be relegated as an afterthought by organizations. The world continues to witness numerous cyberattacks – from Wannacry to the latest Maze attack, with each attack being more unique and complex than the preceding one, and making businesses succumb to huge losses. What’s common between these attacks, you may ask – they are all ‘ransomware'. This ‘cyber pandemic’, as we would like to call it due to its inherent nature of spreading far and wide, has spread its wings across countries leading to concerns around security of data. Its enormity can be gauged from the fact that almost 62% of organizations globally have experienced a ransomware attack in the past one year, as reported by an industry survey by CyberEdge. And, which will likely continue to do so in the foreseeable future, with newer and stealthier attacks underway.

A case in point is the recent Maze ransomware, which created headlines the world over. What’s unique about this ransomware is that it not only encrypts the data but steals it, and with the threat actors threatening to publish the data, which makes it exponentially more devastating. On why organizations should look at ransomware as the proverbial ‘elephant in the room’ and not just shelve the topic aside, let’s delve a bit in into demystifying few of the aspects, which include - ransomware transmission; whether it’s ever a good idea to pay up a ransom, and if ‘prevention’ might be the best ‘vaccine’ in dealing with it.

Infectious modes of transmission

How lethal is ransomware, and why do many of the cyber experts still consider it to be the numero-uno cyber threat even today? All the findings and the industry data validate this fact, with one such finding by Cybersecurity Ventures, a global cybersecurity research firm predicting that – ‘globally, businesses in 2021 will fall victim to a ransomware attack every 11 seconds, down from every 14 seconds in 2019.’ Its proliferation has further been accentuated because of the COVID-19 outbreak, as more and more employees continue to work remotely, and there is less protection due to remote access. It is likely that the users are more susceptible to falling prey to COVID-19 themed malicious emails.

What’s the modus operandi of a ransomware attack and its transmission? Phishing emails are the most common way through which ransomware penetrate an organization – as attachments masquerading as a file which victims tend to trust. However, there are several other vectors through which ransomware can also permeate, which includes endpoints, cloud workloads, networks, web gateways, files, mobile phones and even instances seen across Linux servers.

Typically, ransomware encrypts data using different file formats or extensions with different Advanced Encryption Standard (AES) keys, and hence decryption becomes almost impossible.

‘Ransom’ in ransomware - not a good thing

This is a perennial question, whether to comply to the demands of the ransomware actor or not. It’s important for an organization which has been breached to understand the attackers’ unseen motive, which in many cases is to get a quick return on investment. According to a joint study by PwC India and Data Security Council of India (DSCI), the data breach cost in India has gone up by 8% in 2 years, which is alarming. We notice that many-a-times organizations are ready to pay a ransom to speed up the recovery of their data and systems. However, it’s important to note that paying it does not guarantee that the users will get the decryption key or unlock tool required to regain access to the infected system or hostage files and may only further encourage threat actors to attack organizations. As long as the ransom scheme, or the ‘cyber heist' as we like to call it, continues to be profitable, cybercriminals will continue to leverage it on vulnerable targets.

Prevention and Remediation – Keys to defend

In the current parlance, to deal with ransomware an occasional intake of medicine won’t suffice, and a ‘vaccine’ is the order of the day. This is where ‘prevention’ could be the panacea or much needed vaccine that organizations should prescribe to rather than looking at knee-jerk reactive approach to ransomware attacks, which is the current practice.

Despite the prevalent ideals of digital transformation, lack of basic security hygiene, legacy systems with outdated operating systems and unpatched vulnerabilities are still a reality. As per Gartner’s analysis of clients’ ransomware preparedness, globally over 90% of ransomware attacks are preventable. There is no silver bullet when it comes to stopping ransomware. As part of a layered defense strategy against ransomware, organizations should have multiple security controls in place across email, endpoints, networks, and servers. Since these are correlated, a centralized security visibility across all these layers from a single console helps to reduce IT complexity and to stay on top of the ransomware threat.

Let’s observe some of the best practices that organizations and users can adopt to strengthen their defenses against ransomware and mitigate risks:

Back up important files using the 3-2-1 rule—create 3 backup copies on 2 different media with 1 backup in a separate location.
Enable virtual patching, especially for operating systems that are no longer supported by the vendor.
Ensure emails are safeguarded with sandboxing technology and anti-spam solution, and there is an advance scanning & detection technology in place for mail endpoint & network traffic.
Implement multi-factor authentication and least privilege access policies to prevent abuse of tools that can be accessed via admin credentials, like RDP, PowerShell and developer tools.
Regularly update software, programs, and applications to protect against the latest vulnerabilities.
Increase awareness of how ransomware spreads, i.e., through spammed emails and attachments.
Avoid opening unverified emails or clicking links embedded in them.

The hard question that CISOs, CTOs, CIOs and all the security and IT managers should ask themselves is that, in the eventuality of a newer ransomware threat, are they really prepared well enough to deal with it. 

Thursday, October 1, 2009

Banks, social networks new target for computer viruses

Cyber criminals are increasingly focusing their attacks on the hundreds of millions of users of social networks and on loopholes in bank security systems, security software vendors said on Wednesday. At the same time, spam e-mail messages rose sharply in the third quarter, Symantec Corp said.

And as Facebook reached 300 million accounts in September, social networks and social media continued to attract criminals, smaller research firm F-Secure said in its quarterly virus report. "As Twitter has grown in popularity, it has been increasingly targeted by worms, spam and account hijacking," F-Secure said.

Cyber criminals choose targets that are widely used, allowing them to go after the largest number of potential victims. "Cyber criminals continue to follow the money," said Yuval Ben-Itzhak, technology chief at a small security software vendor Finjan, who on Wednesday revealed a new method criminals use to steal money from bank accounts and hide their tracks.

Finjan said it expects a growing trend of using new software that forges on-screen bank statements, concealing the true transaction amount to dupe account holders and their banks, and then sends the stolen money to money mules accounts.

"With the combination of using sophisticated Trojans for the theft and money mules to transfer stolen money to their accounts, they minimize their chances of being detected," Ben-Itzhak said.

The amount of spam in all e-mail traffic rose to 88.1 percent in the third quarter from 81 percent a year ago, said Symantec's MessageLabs in its quarterly report. MessageLabs said botnets are now responsible for sending 87.9 percent of all spam. Hackers take advantage of the PC vulnerability by booby- trapping websites with a malicious code that loads onto computers.

Infected PCs are commandeered into a botnet, a network of hijacked computers. They are used for identity theft, spamming and other cyber crimes. "Over the past year, we have seen a number of ISP's (Internet service providers) taken offline for hosting botnet activity resulting in a case of sink or swim and an ensuing shift in botnet power," MessageLabs analyst Paul Wood said in a statement.

"However, this won't always be the case as botnet technology has also evolved since the end of 2008 and the most recent ISP closures now have less of an impact on resulting activity as downtime now only lasts a few hours rather than weeks or months as before," Wood said.

Agencies

Wednesday, September 30, 2009

Free computer security software from Microsoft released

Microsoft has released free software that people can use to protect computers against viruses, spyware and other malicious codes in arsenals of cyber criminals.

Microsoft Security Essentials is available for download at microsoft.com/security_essentials and is built on technology that the global software giant uses in computer security programs it designs for businesses.

"With Microsoft Security Essentials, consumers can get high-quality protection that is easy to get and easy to use, and it won't get in their way," said Amy Barzdukas, general manager for consumer security at Microsoft.

"Consumers have told us that they want the protection of real-time security software but we know that too many are either unwilling or unable to pay for it, and so end up unprotected."

Microsoft hopes that the free software will be broadly adopted, particularly by those who have not been vigilant about protecting computers from hackers, and thereby "increase security across the entire Windows ecosystem."

More than 90 percent of the computers worldwide run on Windows operating systems made by the US technology firm.

"Microsoft is helping to reduce some of the barriers that constrain consumers from running (anti-virus software)," said IDC security analyst Jon Crotty. "Microsoft is focused on the challenges that prevent consumers from running up-to-date anti-virus software today, particularly in emerging markets where there is a growing prevalence of malware."

Security Essentials is designed to run behind the scenes, defending machines against infection by malicious computer codes.

The real-time nature of the software means it is automatically kept up-to-date regarding viruses.

Computer security specialty firm Symantec downplayed the Microsoft offering, saying it is lightweight and isn't tuned for new forms of attack being used by hackers.

Symantec referred to Security Essentials as a stripped-down version of an old Microsoft OneCare product that got poor ratings.

"From a security perspective, this Microsoft tool offers reduced defenses at a critical point in the battle against cyber crime," Symantec said of the free offering that competes with Norton products sold by the firm.

"Unique malware and social engineering tricks fly under the radar of traditional signature-based technology alone -- which is what is employed by free security tools such as Microsoft's," it said.

Agencies

Total Pageviews