BotNet News

Your source for Online Security News

The COVID-19 crisis has prompted a global response that has changed many aspects of our lives. However, some groups are using this humanitarian crisis as a cover to pursue illicit goals. One of those groups are cyber criminals who use ransomware to extort money.

Ransomware is malware that encrypts data and holds it hostage until a ransom is paid. The payment is often in a cryptocurrency such as Bitcoin. This makes it difficult to trace the perpetrators. In addition, ransomware has become increasingly targeted and sophisticated. For example, Ryuk is a popular variant that is targeted at specific high-value targets and demands a ransom in the millions of dollars. It gains access to systems by using phishing emails and exploit kits that target vulnerabilities in Microsoft Windows.

Once an enterprise system is infected with ransomware, the attackers typically present a notification on a computer screen that asks for a ransom to be paid to decrypt files. The cybercriminals behind these attacks typically wait months to infiltrate an organization before launching an attack. They may even infiltrate a network multiple times, resetting the passwords of compromised users.

While paying a ransom is not the preferred solution, it can be an option if other measures have been exhausted. A well-defined incident response plan based on the National Institute of Standards and Technology’s incident response lifecycle will help ensure an effective recovery that limits downtime and eliminates the need to pay ransoms. An additional option is to create backups of digital data that are separate from the centralized network.