{"id":487,"date":"2019-10-29T16:59:31","date_gmt":"2019-10-29T16:59:31","guid":{"rendered":"https:\/\/codesmartinc.com\/?p=487"},"modified":"2019-11-25T17:46:34","modified_gmt":"2019-11-25T17:46:34","slug":"its-about-time-you-make-your-organization-ransomware-proof-2","status":"publish","type":"post","link":"https:\/\/codesmartwebapp.azurewebsites.net\/?p=487","title":{"rendered":"Ransomware is spreading like a wildfire!"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Ransomware is a relatively\nnewfound constituent of overall malware (malicious software) or virus that bog\ndown computer networks around the globe. Its modus operandi is as such \u2013 it\ndisables access of users from devices, portals, applications, files etc. and\ndemands a ransom in order to restore the access. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ransomware\nusually encrypts files, applications, portals and requires victims to pay\nransom, commonly in the cryptocurrency form (read Bitcoin). So, the users or\norganizations are expected to pay attackers a ransom in order to decrypt the\nencrypted files to have their access restored. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Like any other malware, Ransomware too, is plainly technology in bad hands \u2013 a mistake, too pricey at that usually. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Types of Ransomware<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Over time, Cybersecurity experts have categorized ransomware essentially into two types:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Crypto Ransomware<\/strong><br>This type of ransomware encrypts key files\/folders\/applications on a user\u2019s\/organization\u2019s computer\/network and the hackers demand a ransom to decrypt the encryption so that users regain access to the files\/folders\/application.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Locker Ransomware<\/strong><br>Locker Ransomware is the second kind which completely locks a user out of his\/her device, thereby completely barring him\/her from access. Then the usual ransom demand ensues. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We are listing downstairs the most dominant\ntypes of ransomware that have been identified so far:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Locky<\/strong> \u2013 traced for the first time in 2016, with an ability to encrypt more than 150 file types via malicious\/fishy email attachments sent to targeted users\/user groups<\/li><li><strong>WannaCry \u00ad<\/strong>\u2013 the most infamous ransomware that ran its course first in 2017 by exploiting an MS Windows bug\/vulnerability and made its effects felt in more than 150 countries; came with a ransom demand of $120m dollars and created a damage of $4b in total<\/li><li><strong>Bad Rabbit <\/strong>\u2013 a sly &nbsp;maneuver of the hackers by guising malware as legit browser requests\/prompts known as \u2018malware droppers.\u2019 This one saw light in 2017<\/li><li><strong>Ryuk <\/strong>\u2013 Targeted the victims by disabling the Windows System Restore feature in August 2018 before expanding the encryption to network drives as well. Many organizations suffered from Ryuk and the ransom ran into the plus side of $600k<\/li><li>&nbsp;<strong>Troldesh <\/strong>\u2013 Hackers behind Troldesh took it a step further by negotiating with victims on the ransom amounts by directly communicating with them via emails<\/li><li><strong>Jigsaw <\/strong>\u2013 Impatient cybercriminals behind Jigsaw in 2016 went on deleting increasing number of files every hour that the demanded ransom wasn\u2019t paid<\/li><li><strong>CryptoLocker <\/strong>\u2013 Did a massive damage of crippling more than 500,000 computers in 2007; first of its kind. However, this marked the inception of a portal backed by govt. officials in the U.S. where victims could find keys to decrypt the encrypted files without paying the ransoms <\/li><li><strong>Petya \u00ad<\/strong>\u2013 So (in)famous that the MS Word recognized the word as we typed it in for the first time! Known to encrypt the entire hard drives of victims by exploiting the Master File Table (MFT) component (Petya came back for the second time in 2017 under the name &#8211; GoldenEye)<\/li><li><strong>GandCrab <\/strong>\u2013 By threatening to make victims\u2019 porn-watching preferences public, GandCrab found a way into victims\u2019 webcams, only to demand ransoms individually from victims citing public humiliation as collateral<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Recent Ransomware Attacks<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The State of Texas deserves a special reckoning with regards to recent ransomware attacks. Many local govt. organizations running under the umbrella of the State of Texas were recently hit by ransomware attacks \u2013 of various types, ransom amounts of wide range and damages \u2013 menacing. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As many as 23\norganizations were under the malware attacks and officials have remarked that\nthese attacks were well planned and well timed \u2013 to have happened over the 2<sup>nd<\/sup>\nweekend of August \u201919. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Apart from\nTexas, the states of New York, Maryland and Florida have also had\ngovernment-run organizations that fell prey to ransomware attacks in the recent\npast. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s take a\nlook at recent noteworthy ransomware attacks and the compromises they have\ninduced into the organizations\u2019 networks:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Baltimore:<\/strong> In May 2019, Baltimore\u2019s state-run organizations were hit by a debilitating ransomware attack that handicapped computers of numbers running into 5 digits. Specifically, email accounts and online payments were compromised largely, barring access and processing for weeks on end. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Officials refused\nto honor the ransom demand and instead went down the tedious path of manual\nprocessing of all transactions. To deny the cybercriminals the last laugh of\ntriumph, Baltimore chose to endure a painful loss of $18m against the ransom\ndemand of $100,000 worth of Bitcoins.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Riviera Beach<\/strong>: Riviera Beach City in Florida had voted to pay a ransom worth $600,000 Bitcoins to hackers in June \u201919 to have their city\u2019s entire computer network released from their paralyzing clutches.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Lake City<\/strong>: Following Riviera Beach City\u2019s incident, officials of Lake City in Florida paid a ransom worth $500,000 Bitcoins to hackers to see themselves freed from a compromised computer network. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>How to Prevent a Ransomware Attack?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cybercriminals\nwith expertise in deploying ransomware attacks keenly follow large\norganizations, for their volume of data is bigger \u2013 which means it\u2019s relatively\neasier to target large volumes of key data in one shot. Also, the financial\nmuscle of large organizations implies a bigger possibility of extracting large\namounts of money as ransom. However, this is only one line of thought. There\u2019s\nno certain way to point out the organizations that cybercriminals may target. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, it is\nimperative that organizations, big and small, take adequate measures to prevent\nthemselves from falling prey to ransomware attacks. We list here appropriate\nmeasures identified across the industry that help prevent ransomware attacks. <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Imparting appropriate, relevant\neducation pertinent to data and device security in users across an organization<\/li><li>Ensuring antivirus\/anti-malware\napplications are updated and running round the clock on a firm\u2019s network (all\ndevices)<\/li><li>Educating employees on all\nsorts of phishing possibilities so that they stay abreast of all contemporary\nphishing traps hackers cast<\/li><li>Keeping the Operating System\nand other OS-related software up to date<\/li><li>Enabling file history mechanism\nfor Windows 8.1 and 10; System Protection feature for Windows Vista and 7<\/li><li>Enabling advanced threat\nprotection solutions<\/li><li>Enabling SharePoint Online and\nOne Drive for Business to facilitate file restoration as a protection mechanism\nagainst ransomware<\/li><li>Putting in place an SLA for\ncomprehensive, automatic system and server scans to ensure full protection<\/li><li>Performing timely scans and\nhealth checks of the file system<\/li><li>Configuring file scanning on a\nreal-time basis as and when they are downloaded\/opened\/executed<\/li><li>Defining\/identifying signature\nupdates from antivirus\/anti-malware protection solution provider and enabling\nautomatic updating<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Now that we\u2019ve seen preventive measures for a ransomware attack, let\nus tell you another quick tip on the same lines: <em>Always set up a complex password for your devices so that you can\nprevent a DDOS attack<\/em>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em><strong>Fyrsoft Aids Your Cybersecurity Measures to Battle Ransomware Attacks<\/strong><\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Being experts on Microsoft security practices and products like Intelligent Security Graph, Fyrsoft performs a 360<sup>0 <\/sup>assessment of your organization\u2019s current cybersecurity posture to help tighten your network\u2019s security measures in the wake of spreading ransomware attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Reach out to us <a href=\"mailto:info@fyrsoft.com\">info@fyrsoft.com<\/a>\nknow more on how Fyrsoft can help you position yourself in the fight against\nransomware.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>About Author:<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Jonathan Cowan (also known as JC) is a Senior Security Engineer for FyrSoft LLC. JC is passionate about many technologies, however his primary focus is within Hybrid Cloud Solutions. He is an Industry Proven Technologist with a demonstrated history of experience in the Information Technology and Services industry. JC is a specialized professional in Cybersecurity Threat Response, Modern Workplace, Intelligent Cloud Hybridization, and Digital Transformation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With over 20 years of computing experience, JC is frequently selected to share his knowledge various technologies as well as the underlying platforms through blogging and speaking at various industry events, webinars and conferences.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can connect with him on&nbsp;<a href=\"https:\/\/www.linkedin.com\/in\/jonathan-cowan\/\">LinkedIn<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>So, it is important that organizations, big and small, adopt measures to avoid falling prey to ransomware attacks.<\/p>\n","protected":false},"author":1,"featured_media":760,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[3],"tags":[],"class_list":["post-487","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blogs","has-thumb"],"acf":[],"_links":{"self":[{"href":"https:\/\/codesmartwebapp.azurewebsites.net\/index.php?rest_route=\/wp\/v2\/posts\/487","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/codesmartwebapp.azurewebsites.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/codesmartwebapp.azurewebsites.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/codesmartwebapp.azurewebsites.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/codesmartwebapp.azurewebsites.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=487"}],"version-history":[{"count":20,"href":"https:\/\/codesmartwebapp.azurewebsites.net\/index.php?rest_route=\/wp\/v2\/posts\/487\/revisions"}],"predecessor-version":[{"id":979,"href":"https:\/\/codesmartwebapp.azurewebsites.net\/index.php?rest_route=\/wp\/v2\/posts\/487\/revisions\/979"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/codesmartwebapp.azurewebsites.net\/index.php?rest_route=\/wp\/v2\/media\/760"}],"wp:attachment":[{"href":"https:\/\/codesmartwebapp.azurewebsites.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=487"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/codesmartwebapp.azurewebsites.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=487"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/codesmartwebapp.azurewebsites.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=487"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}