HomeSecurityRansomware: They usually execute 3 days after the breach - You can avoid them!

Ransomware: Usually executed 3 days after the breach - You can avoid them!

FireEye security researchers analyzed a massive number of ransomware attacks that took place between 2017 and 2019, and found that most ransomware is installed and executed on networks ' victims three days after the initial breach. 

In 75% of ransomware attacks , attackers delay the encryption of their victims ' systems as they attempt to steal Domain Admin credentials, which they can later use to distribute ransomware payloads throughout the compromised environment.

Recently, a new technique has emerged. The hackers behind ransomware steal data victims' victims, threatening to make the data public if they don't receive the ransom.

Many of the incidents analyzed by the researchers showed that malicious activity was widespread and could last for weeks. However, the gangs behind the GandCrab and GlobeImposter ransomware acted almost immediately after the initial breach.

In 75% of ransomware attacks, there is time for companies to defend themselves

As mentioned above, hackers install ransomware at least three days after the initial breach (in 75% of cases). This means that organizations have plenty of time to defend themselvesif they take the appropriate measures and make the right moves.

The researchers said in their report that if organizations detect initial breaches early and act promptly, they can avoid the significant damage and costs associated with a ransomware attack.

Both FireEye and Mandiant have managed to prevent many ransomware attacks.

Subsequent investigations showed that in many cases the ransomware payloads had already been installed but had not yet had time to execute on the systems .

Ransomware: Usually executed 3 days after the breach - You can avoid them!
Computer security and hacking concept. Ransomware virus has encrypted data in laptop. Hacker is offering key to unlock encrypted data for money.

Ransomware: Usually executed 3 days after the breach - You can avoid them!

Ransomware gangs use many ways to infiltrate victims' networks : RDP (LockerGoga), phishing emails with malicious links or attachments (Ryuk), and malware downloads (Bitpaymer and DoppelPaymer).

Also, the FireEye research team found that in most cases ransomware attacks occur after hours or during the weekend.

Attackers use this tactic to avoid immediate detection by the organizations' security teams.

To prevent ransomware attacks, FireEye recommends that organizations use authentication - factor, conduct regular system scans , and use security solutions and email systems that can detect malware, such as Trickbot, Emotet, and Dridex, that help install ransomware.

Implementing security best practices, such as regularly training staff on how to recognize phishing emails, network segmentation, backups , and using unique passwords for each service, can help mitigate the impact of a ransomware attack.

FireEye concludes that there is a positive side. This delay (at least three days) in the installation and execution of the ransomware gives companies time to react and avoid the worst.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS