When ransomware gains access to someone's data and steals important information, the victim is in a very difficult position as they are forced to give in to the hacker's demands in order to get their data back. Essentially, Ransomware is malicious software that uses data as a hostage in order to demand ransom. This type of malware has been used quite a lot in recent years.
Ransomware is delivered by powerful botnets, which send millions of malicious emails to victims. They aim to extort relatively small amounts of money (usually £300 – £500) from many victims. Recently, it has become common for them to ask for more money. In particular, based on some data from the UK, ransomware attacks are increasingly targeting “high-value” victims. They mainly target businesses that are able to pay very large amounts of money (£ 1.000.000).
Targeted ransomware attacks on companies in the UK have increased significantly over the past two years. Hackers look for vulnerable computers and servers and use various techniques to gain access. Brute-force attacks are usually used on systems that allow remote administration of the computer.
Access allows the hacker to "infect" other machines on the same network and collect information about the company and potential vulnerabilities. The next step is to download the ransomware. The malicious software steals valuable data and sends the company a message demanding a ransom. The amount of money requested is based on the attacker's assessment of the financial capacity of the company in question. This assessment is based on information such as the company's size, profits, and more. Usually, ransoms are requested in cryptocurrency and range between 35 and 100 bitcoins.
Other common attack methods include “spear phishing” and “big game hunting.” These types of attacks target people who are involved in a company’s finances. Specifically, they send emails to these people, pretending to be colleagues. These emails urge recipients to open an attached file, usually Word or Excel, with malicious code inside. The attackers are usually motivated by profit. However, some attacks aim to disrupt the business. These are very organized and methodical hacking, very skilled at extracting money. Usually, ransomware attacks send a threatening email, in which a specific amount of money is requested. Many times there is a countdown to pressure the situation. Usually, a file is also sent that proves that the hacker has control of the data. Information is also given on how to contact them and how the payment will be made. Attackers target businesses that rely heavily on electronic data. However, they prefer businesses that are not very large, as larger companies usually have more advanced security systems.
How to protect yourself from these attacks
The main reason why these attacks are developing is the vulnerable security systems of organizations. To address this situation, there must be better protection of remote access. How can this be done? Some ways are to turn off the system when not in use, use strong passwords and two-factor authentication. Another way is to switch to VPN, which connects machines over the internet as if they were on a private network.
According to Bob McArdle, a researcher at Trend Micro, email filters and anti-virus software that provide special protection for ransomware are essential. It is also recommended that companies and businesses create backup copies of their data. This is important in case someone steals the original documents. However, creating copies is not enough if the company does not take care of checking and storing them in a place that is fully protected from ransomware. Proper and regular checking is necessary because ransomware attacks are not easily detected. Therefore, we will not be quiet from ransomware attacks anytime soon. Attackers are constantly finding new methods, so businesses should be on the alert.
