HomeSecurityInfostealer malware is a precursor to ransomware attacks

Infostealer malware is a precursor to ransomware attacks

Infostealer Malware is a Precursor to Ransomware Attacks! SpyCloud, the leader in Cybercrime, today released the  2023 Ransomware Defense Report, an annual analysis of how security leaders and professionals view the ransomware threat and their organizations’ cyber effectiveness.

Infostealer

SpyCloud researchers conducted a detailed analysis using ransomware event data from ecrime.ch and its own database of recovered records from the criminal underground, and it was consistently observed that organizations infected with information-stealing malware (infostealers) were more likely to be attacked by ransomware.

Infostealer infections preceded over a fifth (22%) of ransomware incidents for North American and European ransomware victims in 2023 – with common infostealers such as Raccoon, Vidar , and Redline further increasing the likelihood. SpyCloud’s analysis shows that 76% of infections preceding these ransomware incidents involved Raccoon infostealer malware.

Additionally, SpyCloud surveyed over 300 people who play an active role in cybersecurity at organizations in the US, UK and Canada with at least 500 employees. However, it found that despite changing priorities for addressing ransomware attacks, organizations are ignoring infostealer malware – the precursor to ransomware attacks.

Organizations perceive risk and adapt

SpyCloud found that over 98% of respondents worldwide agree that better visibility and automated remediation of data leaked through malware would improve their ability to combat ransomware. Organizations have shifted their approach over the past year, moving away from user awareness and education and toward technological measures: automating the remediation of exposed passwords and session cookies, implementing multi-factor authentication (MFA), and leveraging password removal tools such as passkeys.

Respondents across the board ranked the importance of multi-factor authentication (MFA) much higher than in previous years, although data backup remained the most important response organizations identified for addressing extortion. Additionally, organizations cited email scams (phishing) and social engineering (common methods of malware delivery) as the most dangerous entry points.

Current efforts at defense are not yielding the expected results.

According to SpyCloud, 81% of organizations surveyed were affected at least once in the past year. The affected organizations include companies that used any business resources to combat ransomware, whether through security solutions or ransom payments.

Information source: businesswire.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS