According to Symantec Corp.'s recent ISTR 2016 Ransomware and Businesses , ransomware has emerged as one of the most dangerous threats in cyberspace, both for businesses and large organizations, as well as for consumers in general, with global losses now reaching hundreds of millions of dollars.
Over the past 12 months, ransomware has reached a new level of maturity and threat. Major ransomware “gangs” are able to funnel their malware to millions of computers. Users hit by ransomware find their valuable data locked away with strong and often impenetrable encryption.
The sophistication of the ransomware business model has created an avalanche mentality among attackers, as the amount of money they try to extort from their victims increases every day. The numbers are constantly on the rise, with the number of new ransomware families discovered in 2015 alone reaching 100 and the average ransom demanded by attackers being $679 USD!
Attacks against businesses are on the rise, with large-scale ransomware attacks remaining the most prevalent form of threat. As demonstrated by two case studies included in Symantec’s report, these attacks are characterized by a high level of sophistication, employing techniques more commonly seen in cyberespionage campaigns.
A successful attack on an organization can potentially infect thousands of computers, causing massive operational damage and serious damage to revenue and reputation. Once cybercrime gangs see some businesses succumb to these attacks and pay the ransom, more and more attackers follow in an attempt to grab their share of the potential profits.
Organizations should be fully aware of the threats posed by ransomware and prioritize their security. A multi-layered approach to security minimizes the likelihood of infection, while educating end users about ransomware is also vital, as dangerous cybercriminals are constantly improving their attack tactics.
In summary, the most important findings of the report are the following:
- While ransomware attacks have until now operated largely indiscriminately, they are now showing a growing interest in targeted attacks on businesses.
- A large number of ransomware groups have begun to use advanced attack techniques, displaying a level similar to cyberespionage attacks.
- The services sector is the most affected with a rate of 38%. Construction and the financial sector follow with 17%, while insurance, real estate and public administration also rank high with a rate of 10%.
- The average ransom demand has more than doubled to $679, from $294 at the end of 2015.
- The number of new ransomware families has been steadily increasing since 2011, with 2015 reaching a record high after 100 new families were discovered.
- The advent of ransomware-as-a-service (RaaS) means that a greater number of cybercriminals can acquire their own ransomware, even with low levels of technical expertise.
- The shift towards crypto-ransomware continues. New variants discovered so far in 2016 have reached 80%.
- Between January 2015 and April 2016, the US was the most affected by ransomware, accounting for 28% of the global ranking. It was followed by Canada, Australia, India, Japan, Italy, the UK, Germany, the Netherlands and Malaysia.
Tips for businesses and end users
- New ransomware variants appear on a regular basis, so you should always keep your security software up to date.
- Keep your operating system and other applications up to date, as updates include patches for ransomware security vulnerabilities that are discovered.
- Email is one of the main methods of attack. Delete any suspicious emails you receive, especially if they contain links and/or unknown attachments.
- Be extremely wary of any file attachment that arrives via Microsoft Office email and advises you to enable macros to view its contents.
- Back up important data to effectively combat ransomware attacks. Attackers gain leverage over their victims by encrypting their valuable files. If the victim has backups, they can restore their files once they realize and “clean up” the attack.
By adopting a multi-layered approach to security, the likelihood of infection is minimized. Symantec has a comprehensive strategy that protects against ransomware in three stages: Prevention, Containment, and Response.
- Prevention: Tools such as Symantec Email security, Intrusion Prevention, Download Insight, Browser Protection, and Proactive Exploit Protection (PEP) can comprehensively protect and prevent malicious ransomware attacks and more.
- Containment: In the event of an infection, a critical step is to contain the spread of the infection. Symantec’s file-based technologies ensure that any file a user downloads to their computer cannot be directly executed. Symantec has a 24/7 security team that is responsible for the continuous development and improvement of ransomware issues. The team continuously monitors ransomware families and their distribution chain to collect all new samples and ensure robust prevention and detection.
- Response: The Symantec Incident Response (IR) team is always there to help businesses respond and recover their data after a ransomware attack.
Symantec's full report on protecting businesses from ransomware, titled Ransomware and Businesses 2016: An ISTR special report, is available for download here!
