BotNet News

Your source for Online Security News

Ransomware is malware that encrypts data and demands payment in an untraceable method (usually cryptocurrency) for decryption. The victims receive a notice that outlines how to pay the ransom, and once payment is received, the files are restored to normal. However, it is not uncommon for the encryption process to corrupt some or all of the affected data beyond recovery even after paying the ransom.

Infection vectors for ransomware vary, but most variants are delivered by phishing email. The phishing email may contain a malicious link or attachment that initiates a download of the ransomware. Once the ransomware has been downloaded, it can then search for files to encrypt and spread to more machines.

Attackers will typically use unauthorized lateral movement and tools like Remote Desktop or Windows Management Instrumentation (WMI) to gain access to as many systems and devices as possible in a targeted environment. Once attackers have gained a foothold, they can focus on gaining access to other systems and domains using privilege escalation and exploitation of vulnerabilities like WannaCry’s EternalBlue exploit.

As the threat of ransomware continues to grow, it is important that organizations have a playbook ready. This should include a plan to identify the best way to respond to ransomware attacks, including how to recover from them. It is also important to have relationships with law enforcement as they will have resources and capabilities that are unavailable to most organizations.

In addition to having a plan in place, it is essential that all organizations keep backups of their data stored on systems that are not connected to the centralized network. Ransomware will often look for data backups and encrypt or delete them. It is also a good idea to regularly test the ability to restore backup data in case of an infection.