What is Ransomware and How Does it Affect Business and Consumers?
A growing and ominous problem, ransomware is malware that infects a computer and encrypts data, preventing users from accessing their files until they pay a specified amount of money. Ransomware has become a lucrative criminal enterprise for cybercriminals who target businesses and consumers alike. The attack is disruptive, expensive and can damage a company’s reputation and cause indirect financial loss through lost productivity.
The first ransomware attack was launched in 1989 by Harvard-trained evolutionary biologist Joseph L. Popp, who sent infected floppy disks to participants at a World Health Organization AIDS conference. The disks contained a virus code, known as the AIDS Trojan, that hid file directories and instructed victims to mail $189 to Panama for a decryption key.
Today, cybercriminals use multiple methods to gain initial access to systems and encrypt files. The most common method is through phishing attacks or exploit kits that include a remote administration tool (RAT) and a backdoor for command-and-control (C2) and to steal credentials. The attackers then leverage this stolen data for more sophisticated attacks.
For example, the Ryuk ransomware attack gained entry to networks by using a combination of phishing and exploit kits to gain access. Once inside, the attackers used RSA and AES encryption to lock the files and demanded a high ransom payment in cryptocurrency.
As ransomware continues to evolve, it could soon be weaponized against critical infrastructures like power plants and transportation hubs. This could sabotage the operations of whole communities and even nations if cybercriminals manage to gain access to control systems.