Antivirus

Why does ransomware keep evading your defenses?

About the authorNir Gaist, Founder and CTO of Nyotron, has worked with some of the largest Israeli organizations, written the cybersecurity curriculum for the Israel Ministry of Education, and holds patents for Behavior Pattern Mapping. Ransomware has long been a menace for organizations and consumers. Global damage cost estimates reach about 10 billion USD per year.…


About the author

Nir Gaist, Founder and CTO of Nyotron, has worked with some of the largest Israeli organizations, written the cybersecurity curriculum for the Israel Ministry of Education, and holds patents for Behavior Pattern Mapping. 

Ransomware has long been a menace for organizations and consumers. Global damage cost estimates reach about 10 billion USD per year. After all these years, why does ransomware continue to be so good at being so bad? The answer is a combination of the security industry’s history of largely ineffective responses to ransomware and how ransomware developers use psychology to trick users into thinking they’re responding to requests from a colleague or even donating Bitcoins to a children’s charity.

Ransomware is hardly new and unknown since it has been around since 1989. Yet it remains one of the most common and successful attack types. According to reports, there were over 180 million ransomware attacks in the first six months of 2018 alone. The adoption of cryptocurrencies and Tor have served to amplify the prevalence of ransomware dramatically.

minimising the ransomware threat

  • How to test anti-ransomware: This is how we do it
  • More than half of working adults don’t know what ransomware is
  • Every 14 seconds, an organization somewhere in the world falls prey to a ransomware attack. But the bad actors are not narrow in their focus and typically target many organizations and users at once. For example, think back to the global WannaCry attack that resulted in losses of almost $4 billion.  

    Ransomware

    Image credit: Pixabay

    How ransomware works

    The details of how one attack gets inside a system or an organization, i.e., its “attack vector” are irrelevant. It can be phishing, exposed RDP or any other avenue that ransomware developers leverage to get in.  

    Instead, let’s take a look at what happens when ransomware actually interacts with your file system and encrypts data. First, ransomware process(es) locates the files it wants to encrypt. These are most often based on file extensions and target your most valuable assets such as Microsoft Office documents or photos, while leaving operating system files intact to ensure that system will still boot. Then the malware encrypts that data in memory and destroys the original file. 

    One route ransomware takes is to save encrypted data into a new file and then delete the original. 

    Another option, and probably the most devious one, is to write that encrypted data into the original file itself. In this case, the original file name is left intact, complicating the recovery by making it difficult to distinguish between encrypted files and those that haven’t been encrypted. 

    A third method is for ransomware to create a new file like in the first option, but then instead of the delete operation use rename to replace the original file.

    After completing the encryption process, the infamous ransomware note is displayed. We know that part of the story quite well from the news coverage.

    Image credit: Pixabay

    Image credit: Pixabay

    (Image: © Image Credit: Geralt / Pi

    Read More

    Be the first to write a comment.

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    Antivirus

    Microsoft Defender briefly decided Google Search was malware

    You can pay every month for Office 365’s productivity tools, but you still can’t escape Microsoft Defender’s habit of turning everyday links into fake security alerts. On September 2, Office 365 subscribers ran into an unusual incident: Redmond’s endpoint antivirus engine began flagging Google Search results as potentially malicious URLs.Read Entire Article…

    You can pay every month for Office 365’s productivity tools, but you still can’t escape Microsoft Defender’s habit of turning everyday links into fake security alerts. On September 2, Office 365 subscribers ran into an unusual incident: Redmond’s endpoint antivirus engine began flagging Google Search results as potentially malicious URLs.Read Entire Article…
    Read More

    Continue Reading
    Antivirus

    5 Windows Security Settings You Should Never Skip Over

    Windows has a range of authentication methods for accessing your device, a firewall, an antivirus, a way to encrypt your drives and more…

    Windows has a range of authentication methods for accessing your device, a firewall, an antivirus, a way to encrypt your drives and more…
    Read More

    Continue Reading
    Antivirus

    Watch out for this fake Face ID Apple Pay pop-up scam

    Macworld The security, antivirus, and VPN company Malwarebytes has an interesting post on its Malwarebytes Labs blog detailing a new and sophisticated scam. The web-based trick is meant to make users think that they just made a big payment with Apple Pay, with the goal being to trick them into calling a fake “Apple Support”

    Macworld

    The security, antivirus, and VPN company Malwarebytes has an interesting post on its Malwarebytes Labs blog detailing a new and sophisticated scam.

    The web-based trick is meant to make users think that they just made a big payment with Apple Pay, with the goal being to trick them into calling a fake “Apple Support” number…
    Read More

    Continue Reading
    Antivirus

    This simple antivirus tool is the easiest way to scan your Linux PC for threats – for free

    Worried about Linux vulnerabilities or sharing files with Windows users? This ClamAV GUI makes it easy to ensure they’re clean…

    Worried about Linux vulnerabilities or sharing files with Windows users? This ClamAV GUI makes it easy to ensure they’re clean…
    Read More

    Continue Reading