Ransomware against businesses: Kaspersky Lab researchers have discovered an emerging and worrying trend: more and more cybercriminals are shifting their focus from attacks on individuals to ransomware attacks targeting businesses.
At least eight cybercriminal groups involved in the development and distribution of encrypted ransomware have been identified. The attacks have primarily targeted financial institutions worldwide. Kaspersky Lab experts have documented cases where the monetary claims are estimated at more than half a million dollars.
The eight identified groups include the creators of PetrWrap, which has attacked financial institutions worldwide, the notorious Mamba group, and six other groups with unknown names, which mainly target corporate users. It is worth noting that these six groups were previously involved in attacks that primarily targeted individuals and used identical programs. Now they have refocused their efforts on corporate networks. According to Kaspersky Lab researchers, the reason for this trend is clear – criminals believe that ransomware attacks against businesses have greater profit potential than mass attacks against individuals. A successful ransomware attack against a company can easily stop the smooth operation of the business for hours or even days, making the owners of the attacked companies more likely candidates to pay the ransom.
In general, the tactics, techniques and procedures used by these groups have several common elements. They “infect” the targeted organization with malware via vulnerable servers or by spreading phishing emails. They then persistently install it on the victims’ network and identify vulnerable corporate resources to encrypt them. In return, they demand a ransom for decryption. In addition to their similarities, some of the groups also have their own characteristics and traits.
For example, the Mamba group uses its own encryption malware, based on the open source DiskCryptor software. Once the attackers gain access to the network, they install the encryptor on it using a legitimate remote control utility for Windows. This approach makes the actions less suspicious for the security personnel of the targeted organization. Kaspersky Lab researchers have encountered cases where the ransom has reached a value of up to one bitcoin (about $1,000 as of the end of March 2017) per decryption endpoint.
Another unique example of tools used in targeted ransomware attacks is PetrWrap. This group mainly targets large companies with a large number of network nodes. The criminals carefully selected targets for each attack that persisted for a certain period of time: PetrWrap has been persistent on a network for up to 6 months.
“We all need to be aware that the threat of targeted ransomware attacks on businesses is growing, bringing tangible financial losses. The trend is worrying, as ransomware actors have begun their crusade for new and more profitable victims. There are many more potential ransomware targets out there, with attacks bringing even more devastating consequences,” said Anton Ivanov, Senior Security Researcher, Anti-Ransom at Kaspersky Lab.
To protect organizations from such attacks, Kaspersky Lab security experts advise:
- Create appropriate and timely backups of your data so that they can be used to restore the original files after a data loss incident.
- Use a security solution with behavioral-based detection technologies. These technologies can “catch” malware, including ransomware, by observing how it operates during the attack on the system and make it possible to detect new and yet unknown ransomware samples.
- Visit the No More Ransom, a joint initiative aimed at helping ransomware victims recover their encrypted data without having to pay the criminals.
- Check the installed software, not only on endpoints, but also on all nodes and servers in the network and keep it up to date.
- Conduct a security assessment of the control network (i.e., a security audit, penetration testing, gap analysis) to identify and eliminate any security gaps. Review external providers and third-party security policies if they have direct access to the control network.
- Seek external intelligence: information from trusted providers helps organizations predict future attacks against the company.
- Train your employees, with particular emphasis on operational and technical staff and raising their awareness of recent threats and attacks.
- Providing protection inside and outside the perimeter. A sound security strategy must allocate significant resources to attack detection and response in order to prevent an attack before it reaches critical assets.
For more information about targeted Ransomware attacks, you can read the blogpost on the dedicated website Securelist.com.
