Threat Profiles
What is Ransomware?
Ransomware is a type of malicious software (malware) that attempts to extort money from victims by restricting access to a computer system or files. The most prevalent form of this profit-motivated malware is crypto-ransomware, which encrypts files into encoded messages that can only be decrypted (decoded) with a key held by the malicious user or group.
Ransomware: An Enduring Risk to Organizations and Individuals
REAL assesses with high confidence that many businesses, schools, government agencies, and home users will remain at high risk of ransomware infections because hackers will continue to innovate and expand the targeting scope of their extortion campaigns. The most prevalent form of this malware is known as crypto-ransomware, referring to the use of encryption to render files locked until a ransom is paid for the decryption key.
- The tactics used to distribute ransomware often involve cunning social engineering tactics, such as carefully crafted phishing emails. Other infection vectors include exploit kits, drive-by downloads, malvertising, and botnets.
- Ransomware developers obscure their identities and reduce attribution risk using various tactics, often relying on the Tor anonymity network for command and control and using Bitcoin for anonymous ransom payments. Newer variants attempt to eliminate data recovery options by encrypting connected drives and deleting system restoration points.
- The Cyber Threat Alliance reported that CryptoWall 3.0 infected hundreds of thousands of victims and netted criminals $325 million. In 2015, Microsoft removed ransomware infections from 24,000 computers.
- An expanding marketplace for customizable ransomware tools and affiliate programs allows users with little technical ability to distribute malware. For example, the Tox ransomware kit enabled anyone to distribute ransomware.
For many organizations, ransomware may not be entirely preventable; however, a robust data backup process can greatly reduce the impact of a successful infection. Regular training and awareness exercises with all employees will enhance safe Internet-browsing techniques and improve phishing email recognition.
Ransomware Mitigation Strategies
Although ransomware infections may not be entirely preventable, the most effective strategy to mitigate their impact is having a comprehensive data backup protocol.
Data Protection:
- Schedule backups frequently, keeping them offline and secure, ideally in multiple locations for redundancy.
- Contact online backup services immediately if a ransomware infection is suspected.
System Management:
- Keep anti-virus software updated and schedule regular scans.
- Enable automated patches for all software and systems.
- Follow the Principle of Least Privilege for user accounts, and enable User Access Control (UAC).
- Disable macros in Microsoft Office.
- Use ad-blocking extensions to prevent drive-by infections from malicious ads.
Network Management:
- Keep the firewall active and properly configured.
- Close unused ports and block known malicious IP addresses.
Mobile Device Management:
- For Android, disable unknown sources and install apps only from official stores.
- For iOS, back up data and enable two-factor authentication.
Post-Infection Remediation:
- Alert security personnel if suspicious activity is detected, and disconnect infected devices from networks immediately.
Ransomware Decryption and Removal
COMING SOON
Known Ransomware
Known Ransomware (AS OF 11/9/2016)
- 777
- 7ev3n
- 8lock8
- Alfa
- Alma Locker
- Alpha Crypt
- AnonPop
- Apocalypse
- AutoLocky
- BadBlock
- Bart
- BitStak
- Cerber
- Chimera
- CoinVault
- Coverton
- CryptoBit
- CryptoJoker
- CryptoWall
- CryptXXX
- Crysis
- CTB-Locker
- RAA
- Ransom32
- TeslaCrypt
- ZCryptor
What is a Botnet?
A botnet is a group of internet-connected computers and devices infected by malware that allows a malicious actor to control them remotely for purposes like sending spam, stealing data, conducting DDoS attacks, and more.
How is a Botnet Created?
Botnets are created by compromising devices through known vulnerabilities. Once access is gained, malware is installed to facilitate remote access and communication with a command-and-control server.
Prevention Strategies for Network Administrators
- Establish network activity baselines.
- Disable UPnP on routers.
- Block suspicious outbound connections.
Known BOTNETS
Known BOTNETS (AS OF 11/9/2016)
- Aidra
- Bashlite
- Hajime Botnet
- Mirai Botnet
What are Exploit Kits?
Exploit Kits are toolkits that automate the exploitation of vulnerabilities in software applications to deliver malicious payloads.
How Do Exploit kits work?
- Contact
- Redirect
- Exploit
- Infect
Known Exploit Kits
Known Exploit Kits (AS OF 11/11/2016)
- Angler
- Blackhole
- Fiesta
- Neutrino
- RIG
What is Mobile Malware?
Mobile malware is software designed to exploit mobile operating systems, capable of remote control, tracking users, and stealing personal information.
Recommendations to mitigate Mobile Malware threats
- Apply patches and updates immediately.
- Avoid third-party apps.
- Use anti-malware apps like Malwarebytes or Kaspersky.
Known Mobile Malware Variants
Known Mobile Malware (AS OF 11/15/2016)
- Acecard
- AndroRAT
- Bankosy
- HummingBad
What is PoS Malware?
PoS malware is designed to steal credit and debit card data from payment processing systems.
Known PoS Malware Variants
Known PoS Malware (AS OF 11/16/2016)
- AbaddonPOS
- BlackPOS
- Dexter
What is a Trojan?
A Trojan is a type of malware that disguises itself as legitimate software to trick users into installation.
Known Trojan Variants
Known Trojan Variants (AS OF 11/15/2016)
- Adwind
- BlackEnergy
- Dridex
- Gozi
2018 © All Rights Reserved.