Showing posts with label ransomware. Show all posts
Showing posts with label ransomware. Show all posts

Saturday, December 28, 2019

CyberScout shares key cybersecurity predictions for 2020; predicts persistent threats in areas of privacy and cybersecurity

As 2019 comes to an end, cybersecurity experts are preparing for a new year—and a new decade—and all the cyber scams, breaches, attacks and privacy concerns that threaten consumers and businesses. CyberScout continues to strengthen defenses against the constantly evolving cyber threats that will shape the 2020 security landscape, encouraging consumers and business owners to stay informed and aware. 


"While consumers and business leaders are more aware of cybersecurity and privacy than ever before, cybercriminals continue to innovate," said CyberScout founder and chairman Adam Levin. "As defenses improve, the attack vectors become more nuanced and technically impressive. You are your best guardian when it comes to your privacy and personal cybersecurity."  

Levin's has listed the following 20 cybersecurity predictions for 2020:
  1. Cybersecurity workforce shortages. There will be a shortage of experts, adding pressure on CISO's charged with tackling an increasing issue environment. With the demand for cybersecurity professionals far exceeding supply, the market will have to start filling openings with less qualified people. 

  1. The disinformation blob will grow. With the success of weaponized misinformation campaigns in the 2016 and 2018 U.S. elections, expect to see more of them in the private sector, with businesses adopting troll farm tricks to hurt the competition. 

  1. Ransomware will continue to thrive. Phishing attacks will continue to lead to ransomware infecting more and more networks. Businesses, municipalities and other organizations will continue to pay whatever they must in order to regain control of their data and systems, and will also see better backup practices that will help minimize or neutralize the threat of these attacks.  

  1. IoT botnets will make dystopian paranoia seem normal. IoT will continue to grow exponentially. In 2020, there will be somewhere around 20 billion IoT devices in use around the world. Unfortunately, many are not secure because they are protected by nothing more than manufacturer default passwords readily available online. They will be weaponized (like in years' past), but with increasing skill and computing power.


  1. The integrity of the U.S. elections will be questioned—for good reason. There are still voting machines in use that are far from secure and would not pass the simplest of audits. Some states continue to use machines that leave no paper trail. Look forward to questions regarding election security all year.  

  1. Cryptocurrency miners will continue to get rich off stolen electricity. Related to the botnet craze, we will see an increase in computing power theft used to mine cryptocurrency. With bots becoming exponentially more effective as the result of AI and cloud computing, a renaissance of Wild West behavior in the global blockchain digital ledger can be expected. 
  
  1. Zero-trust environments will be talked about. A few may exist. The assumption that one can trust the home team—people within one's organization—has been replaced with zero-trust policies. Zero-trust simply means that no one can be trusted, in or outside the organization. With this assumption foremost, new systems make breaches and compromises harder to happen. 

  1. More people will know what "protect surface" means. Protect surface is part of the zero-trust environment. An organization's attackable surface includes every error-prone human in its employ as well as the mistakes in configuration they may have committed along the way and any number of other issues. The protective surface is much smaller and must be kept out of harm's way. The more the subjects is spoken about, the stronger its cybersecurity is expected to be. 

  1. Cars will be frozen. Driverless cars are going to hit things as well as get hit by hackers. Cars that talk to satellites are toast. It's going to happen. (Or not. But it totally could.) 

  1.  5G will make the cyber smash grab a thing.  5G is going to make everything move fast, as will the new generation USB4 devices. With quicker speed, it will take much less time to transfer data. Coincidentally, criminals appreciate this as much as the rest of us.  

  1. Social media will no longer need to be private. Social media companies will probably become a bit more responsible when it comes to the way they gather, store, crunch, analyze and sell our data to marketing companies and small to medium sized businesses looking to connect directly with consumers. 


  1.  State-sponsored traffic jams will be a thing. Hackers are going to target operational systems with an array of tactics that include ransomware and more DDoS attacks that will snarl things up in ways we've not yet seen. The targets will be financial institutions, the power grid, elections, proprietary business information, city services and infrastructure like traffic lights and much more that can wreak havoc on our day to day lives.

  1.  You're going to have personal cyber insurance. Insurance companies will be writing more comprehensive cyber liability policies for businesses and offering innovative personal cyber coverage for consumers. 

  1.  HR will save money by spending some. More employers will offer their employees identity protection products and services as part of their paid or voluntary benefits programs. An employee who has their identity stolen is not very productive and if, as part of that identity theft, their user ID or passwords are exposed, a thief might have what he or she needs to access an employer's network and sensitive databases. 

  1.  The cloud will leak. The parade of stories about misconfigured cloud clients and data stored without any password protection on cloud services will continue apace, perhaps in part because of the CISO and cybersecurity workforce shortage discussed in the first prediction.  

  1.  AI will gladly take one’s job. AI is here and it's willing to work. The CISO shortage as well as many of the innovations discussed in this list of predictions will be increasingly addressed and powered by Artificial Intelligence. 

"Disinformation efforts, election security and continued attacks on local governments and major metropolitan hubs are escalating concerns of how disruptive and dangerous cybercrimes are becoming," continued Levin. "2020 promises to be an interesting ride. Be smart and stay safe by staying informed and seeking cyber insurance protection for you, your family and your business."  

Saturday, December 21, 2019

Asigra’s latest program defends public/non-profit organizations against cyber-attacks targeting backup data

Asigra announced a new program focused on defending the backup repositories and data of Canadian public and non-profit organizations against cyber-attacks. The purpose of the program is to ensure the recovery of data that otherwise may have become compromised as a result of malicious malware or ransomware Attack-Loops that prevent the recovery of mission-critical data and often put large volumes of personally identifiable information (PII) at risk.

Cyber-attacks on public/non-profit organizations have put citizen data at risk like never before as new variants of ransomware and other attacks continue to infiltrate and expose sensitive data to unknown and possibly criminal entities.


In a recent attack covered by the Toronto Star, medical test provider LifeLabs agreed to pay the ransom of attackers in order to retrieve millions of customer records. In a statement, the organization said, “The personal information of over 15 million customers was compromised, mostly in British Columbia and Ontario, including name, address, email, login, passwords, date of birth, health card number and lab test results.”

Like many organizations dealing with a cyber-attack, the last resort for recovery relies on a functioning disaster recovery or backup solution in place. Unfortunately, hackers have now designed ransomware and other malware to seek out secondary storage systems (aka: disaster recovery and backup data) in order to compromise a clean retrieval of the information. 


As a result, these organizations no longer have a way to reinstate their data, and therefore are faced with either relinquishing or paying a ransom which can be exceptionally high for public and non-profit entities.

As a Canadian company, Asigra is planning to help protect these organizations by partially donating a large percentage of its cybersecurity-enabled backup technology to Canada’s extensive list of public and non-profit organizations. Those establishments in the country that can issue a tax-deductible receipt may contact Asigra to receive the company's complete anti-ransomware/backup software suite with the cost covered in large part by a donation-in-kind.

Asigra’s cloud-based data recovery platform is unique in the industry for converging data protection and cybersecurity for effective malware/ransomware detection and prevention that ensures safe, secure and reliable data recovery. 


The advanced software includes initial zero-day Attack-Loop preventative technology using bi-directional cyber-threat detection, zero-day exploit protection, variable repository naming, and multi-factor authentication (MFA) for a full defensive suite against aggressive ransomware and other cyber-threats targeting backup data. This is complemented by FIPS 140-2 certification and military-grade data encryption to ensure enterprise-grade data security, making user data unreadable without the proper encryption key.

“The majority of cybersecurity analysts today agree that cyber-attacks are evolving from the perspective of what they target, how they impact organizations and the changing methods of attack,” said David Farajun, CEO, Asigra. “For the past year, we have seen an increasing number of cyberthreats begin to target the number one method of data recovery – the backup repository. As a specialist in this area, we have developed a very effective solution to fight against this and now offer the technology to public and non-profit organizations we share our data with.”

Saturday, December 14, 2019

Kaspersky research finds 174 municipal institutions targeted with ransomware in 2019

According to Kaspersky security experts, 2019 has seen a significant spike of ransomware attacks on municipalities. This conclusion comes after the company’s researchers observed at least 174 municipal institutions with more than 3,000 subset organizations have been targeted by ransomware throughout the last year. This represents a 60 percent increase from the same figure in 2018.


Ransomware is notorious in the corporate sector for financial devastation and has affected businesses around the world for several years. This year has seen rapid development of an earlier trend where malware distributors have targeted municipal organizations. 

Researchers note that while these targets might be less capable of paying a large ransom, they are more likely to agree to cybercriminals’ demands. Blocking any municipal services directly affects the welfare of citizens in financial losses as well as other significant and sensitive consequences.

When considering publicly available information, ransom amounts have varied greatly with highs reaching up to $5,300,000 and $1,032,460 on average. Researchers note that these figures do not accurately represent the final costs of an attack, as the long-term consequences are far more devastating.

The malware that was most often observed were varied, yet three families were named as the most notorious by Kaspersky researchers: Ryuk, Purga and Stop. Ryuk appeared on the threat landscape more than a year ago and has since been active all over the world in public and in the private sector. Its distribution model usually involves delivery via backdoor malware which spreads by the means of phishing with a malicious attachment disguised as a financial document. 


Purga malware has been recognized since 2016, yet only recently municipalities have been discovered to fall victims to this Trojan having various attack vectors from phishing to brute force attacks. Stop cryptor is relatively new as it is only a year old. It propagates by hiding inside software installers. This malware continues to be prevalent, ranking at number seven in the top 10 most popular cryptors ranking of the third quarter this year.

“One must always keep in mind that paying extortionists is a short-term solution which only encourages criminals and keeps them funded to quite possibly repeat the same acts,” said Fedor Sinitsyn, a security researcher at Kaspersky. “In addition, once a city has been attacked, the whole infrastructure is compromised and requires an incident investigation and a thorough audit. This inevitably results in costs that are in addition to the ransom requested. Based on our observations, cities might be inclined to pay because they usually cover the cyber risks with help of insurance and allocating budgets for incident response. The better approach would be to invest in proactive measures like proven security and backup solutions as well as regular security audit. While the trend of attacks on municipalities is only growing, it can be stifled by adjusting the approach to cybersecurity and what is more important by the refusal to pay ransoms and broadcasting this decision as an official statement.”

Friday, December 13, 2019

Trend Micro warns against sighting of ransomware bugs, Snatch and Zeppelin

Two ransomware families – Snatch and Zeppelin – with noteworthy features were spotted this week. Snatch ransomware is capable of forcing Windows machines to reboot into Safe Mode. Zeppelin ransomware, on the other hand, was responsible for infecting healthcare and IT organizations across Europe and the U.S.

Snatch reboots infected machines into Safe Mode to bypass security software and encrypt files without being detected. It was designed to do this because security software often do not run in Windows Safe Mode, since it’s meant for debugging and recovering a corrupt operating system (OS).


Researchers at SophosLabs found that the ransomware operators use a Windows registry key to schedule a Windows service called SuperBackupMan, which can run in Safe Mode and cannot be stopped or paused. The malware even goes further by deleting all volume shadow copies on the system, thus preventing the forensic recovery of encrypted files.

Snatch ransomware, first discovered back in 2018, does not target home users or use mass distribution methods such as spam campaigns or browser-based exploits. Instead, the malware operators go after a small list of targets that include companies and government organizations. The operators were also found recruiting hackers on hacking forums and stealing information from target organizations.


Zeppelin, which is a new variant of the VegaLocker/Buran ransomware, was spotted (with compilation timestamps no earlier than November 6, 2019) infecting companies located in Europe and the U.S. through targeted installs. Reported by BlackBerry Cylance, the Zeppelin ransomware, also a ransomware-as-a-service (RaaS) family, was found being used to infect certain healthcare and IT companies.

Zeppelin ransomware appears to be highly configurable and can be deployed as a .dll or .exe file, or wrapped in a PowerShell loader. Aside from encrypting files, it also terminates various processes, including those associated with backup, database, and mail servers. Zeppelin executables were found wrapped in three layers of obfuscation. Its ransom notes range from generic messages to elaborate notes tailored to specific organizations. Notably, it appears Zeppelin ransomware is not being widely distributed — or at least not yet.

The researchers believe that Zeppelin, similar to Sodinokibi ransomware, is being spread through managed service providers (MSPs) to further affect customers. Moreover, the ransomware can also be distributed through malvertising operations and watering hole attacks.


Aside from maintaining an up-to-date operating system to address exploitable vulnerabilities, users should adopt the standard best practice of backing up data via the 3-2-1 rule. Users can also consider deploying comprehensive, multilayered security solutions that will protect against ransomware attacks coming from different entry points. 

Trend Micro advises users and organizations to secure ports and services that are exposed on the internet; enable multi-factor authentication to protect admin accounts from potential brute-force attacks; secure remote access tools as they can be used as entry points; employ the principle of least privilege and regularly monitor the network for threats; and perform regular password audits for stronger access control to help prevent ransomware attacks.

Trend Micro solutions such as the Smart Protection Suites and Worry-Free Business Security solutions, which have behavior monitoring capabilities, can protect users and businesses from these types of threats by detecting malicious files, scripts, and messages as well as blocking all related malicious URLs. 

Trend Micro XGen security provides a cross-generational blend of threat defense techniques against a full range of threats for data centers, cloud environments, networks, and endpoints. It infuses high-fidelity machine learning with other detection technologies and global threat intelligence for comprehensive protection against advanced malware.

Wednesday, December 11, 2019

Trend Micro reveals that bug in Ryuk ransomware’s decryptor can lead to data loss in certain files

Ryuk’s decryptor tool — provided by the threat actors behind the ransomware to victims who have paid ransom demands — could actually cause data loss instead of reinstating file access to users. According to a blog post from Emsisoft, a bug with how the tool decrypts files could lead to incomplete recoveries, contrary to what the decryptor is actually meant to achieve.

While Ryuk has gained most of its notoriety due to who it targets and how much it tries to extort, the ransomware variant has actually seen a number of evolutions to its capabilities, which includes a revised encryption process. 


To make encryption faster and more efficient, Ryuk will only partially encrypt files that are larger than 57,000,000 bytes (approximately 54.4 megabytes) in 1,000,000 byte blocks — using a formula to compute how many of these blocks it will encrypt.

Traditionally, a file infected by Ryuk will contain a marker that shows whether it has already been previously encrypted with the Hermes ransomware, an earlier malware variant on which Ryuk was based. However, in addition to the Hermes marker, these partially encrypted files will also show a number beside the marker indicating how many of the 1,000,000 byte blocks were encrypted.


Due to a bug in how this number is calculated, the latest versions of Ryuk might accidentally truncate some files, removing a single byte of data from the file it was supposed to restore.

While a single byte might seem like a miniscule amount to get worried about (in most cases, the last byte is actually unused) — some types of files, such as those used in Oracle databases, store information in the last byte. This means that the removal of this single byte can actually result in an incomplete recovery, depending on the file type that was encrypted.

According to Trend Micro’s 2019 midyear security roundup, ransomware detections in the first half of the year increased by 77 percent compared to the second half of operations as threat actors seek to evolve their tools and methods. Ryuk is perhaps the most prevalent of the current ransomware families: It has earned the threat actors behind it millions of dollars from victims — typically, major organizations in both public and private sectors.

Given how widespread ransomware still is, it will benefit both organizations and individual users to regularly practice these recommendations to minimize the chances of a successful ransomware attack.


The simplest and perhaps most effective method to keep important files and data safe is to maintain regular backups — preferably using the 3-2-1 method of keeping three backup copies in at least two separate formats, with one copy offsite. IT administrators should ensure that systems, networks, servers, and applications are consistently updated and patched to prevent threat actors from taking advantage of vulnerable software and systems to deliver ransomware.

Organizations should cover all possible attack surfaces by implementing the principle of least privilege, where employees can only access parts of the system they need. Ransomware victims should also refrain from paying ransomware demands, as this encourages threat actors to continue with their campaigns. Furthermore, paying the ransom doesn’t even guarantee that the encrypted data will be restored, as seen in this scenario.


Organizations without dedicated security teams that want to bolster their security strategy can also look into taking advantage of services such as Trend Micro Managed XDR, which offers a wide scope of visibility and expert security analytics by integrating detection and response functions across networks, endpoints, emails, servers, and cloud workloads. 

The Managed XDR team is no stranger to Ryuk, and has extensive real-world experience investigating and analyzing the ransomware variant — as well as offering remediation advice — to customers.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...