HomeYoutubeRansomware: What you need to know about this major threat!

Ransomware: What you need to know about this major threat!

Ransomware is a type of malware that cybercriminals use to lock down and encrypt victims' systems and data. The attackers then demand money, or a ransom, from the victims in order to decrypt the systems. That's why this malware is called ransomware , which comes from the English word "ransom," which means ransom.

See also: FBI and CISA issued alert about DarkSide ransomware

Ransomware

Ransomware has been around since 1989, when the “AIDS trojan” was used to blackmail victims and demand money. In 1996, researchers from Columbia University presented another ransomware at a conference, demonstrating the progress, power, and creation of modern cryptographic tools.

Since then, cybercriminals have greatly advanced their methods and knowledge, creating ransomware that can cause significant damage to victims while allowing criminals to make money while maintaining their anonymity. This type of attack exploits system, network and software vulnerabilities, as well as human error.

The target device can be a computer, printer, smartphone, wearable, POS and more, but ransomware can also spread to an entire network.

Ransomware attacks have become very common in recent years. Large companies in the United States and Europe have fallen victim to such attacks.

Cybercriminals can target individual users, but they usually choose companies and organizations, as the chances of receiving the ransom are higher.

Hackers usually set a deadline for the ransom to be paid. Until then, the data remains encrypted and inaccessible.

If the deadline expires and the victims have not given the money, the criminals can permanently delete the data or, as is becoming more common lately, they can publish data that they have stolen before encrypting the systems.

See also: Another American city victim of ransomware attack

The ransoms demanded by hackers can range from a few thousand to hundreds of thousands of dollars, and in most cases, hackers demand it in the form of cryptocurrency.

Several security experts and government agencies, including the FBI, advise users not to pay criminals.

How does ransomware work?

As we said before, ransomware is a type of malware designed to encrypt important data and blackmail victims.

What are the stages of a typical ransomware attack?

  • Ransomware attacks on companies typically begin with a phishing emailcontaining a malicious attachment or link. The unsuspecting user opens the attachment or clicks on the malicious URL. This installs the ransomware agent, which begins scanning the system for important files.
  • The ransomware then begins encrypting the files on the victim's computer.
  • In many cases, malware steals data before encrypting it.
  • After encryption, the ransomware displays a message on the infected device. The message explains what has happened and provides other important information, such as the ransom amount, payment deadline, and payment method.
  • If the ransom is paid, the hackers will send a decryption key.

However, users should keep in mind that ransomware is not only installed through phishing emails and malicious attachments.

Users could infect their systems by clicking on malicious links on social media, such as Facebook and Twitter, entering malicious advertisements, downloading untrustworthy programs and applications, entering unsafe sites , etc.

See also: FBI/ACSC: Avaddon ransomware attacks are increasing at an alarming rate

Finally, ransomware gangs can exploit vulnerabilities in unpatched systems to deploy their malware.

Examples of ransomware

Ransomware: What you need to know about this major threat!

WannaCry

WannaCry is one of the most popular and destructive ransomware. In 2017, it spread to 150 countries, targeting 230,000 computers and causing an estimated $4 billion in damage. The ransomware exploited a Windows vulnerability and had a mechanism that allowed it to spread and infect other devices.

Ransomware

Cerberus

Cerber is a ransomware-as-a-service (RaaS) ransomware that is available to various cybercriminals. Cerber encrypts files and attempts to prevent security and antivirus functions from running, preventing users from restoring their systems.

Ransomware: What you need to know about this major threat!

Locky

Locky can encrypt 160 file types. It was first released in 2016 and is mainly distributed through exploit kits or phishing. Hackers send an email with a malicious Word or Excel document or a ZIP file that installs the malware.

Ransomware

NotPetya and Petya

Petya ransomware infects a machine and encrypts the entire hard drive, going to the Master File Table (MFT). This makes the entire drive inaccessible, although the actual files are not encrypted.

Petya first appeared in 2016 and only affects Windows computers.

Ransomware: What you need to know about this major threat!

The original Petya was not particularly successful, but a new variant, dubbed NotPetya, has proven to be more dangerous. NotPetya can spread to systems without human intervention. NotPetya was initially spread using a backdoor and later exploited the EternalBlue and EternalRomance vulnerabilities in the Windows SMB protocol. In fact, it is said that when it encrypts data, it destroys it so that it cannot be recovered. Users who pay the ransom cannot get their data back.

Ransomware

Ryuk

Ryuk infects victims' devices via phishing emails or drive-by downloads. It uses a dropper, which extracts a trojan onto the victim's machine. Attackers can install additional tools, such as keyloggers and other malware. In a Ryuk-based attack, ransomware is the final stage of the attack, after the attackers have already done the damage and stolen the files they need.

Goals

As for the targets of ransomware attacks, as we said above, they can be both ordinary users and businesses.

Where hackers will target depends on many factors.

Others are trying to target organizations they believe do not implement many layers of protection.

Others target organizations they believe are more likely to pay the ransom.

These include healthcare organizations and government agencies that hold critical information.

Protection measures

  • Use of reliable and advanced antivirus software
  • Create backups, especially for essential files
  • Regularly update systems, applications and antivirus programs
  • Training employees to recognize suspicious emails
  • Using filters to automatically block suspicious emails 
  • Use of firewalls and VPNs
  • Network segmentation

The above security practices can protect users and businesses to a certain extent from various cyber attacks.

However, if someone falls victim to a ransomware attack, the key thing to do is not to pay the ransom and to contact the authorities. The attackers are not people you can trust.

Even if the ransom is paid, it is not guaranteed that the criminals will not leak the stolen data or that they will give the victim the decryption key.

Ransomware attacks are very popular precisely because they offer large sums of money to criminals. If victims stop paying the ransom, then only we can hope for a decrease in these attacks!

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS