BotNet News

Your source for Online Security News

Ransomware holds victims hostage by encrypting their data and demanding payment for a decryption key. It’s a lucrative attack that has grown in frequency and severity, driven by the ease of access for attackers to tools and vulnerabilities, and the high return on investment. The actor rationale is straightforward: ransomware commoditizes victim data and reduces the risk of detection by leveraging a known weakness in computing systems.

Ransom attacks often target low-hanging fruit, including small and midsize businesses (SMBs) with insufficient security. They also focus on companies that have valuable data and must keep operations running, such as those using database or marketing applications. Cyber criminals may even threaten to release stolen data unless they receive the ransom.

Some ransomware variants can also steal credentials to access critical systems and devices. These attacks, referred to as double extortion, can include the threat of a regulatory leak or partner disruptions to pressure victims into paying the demanded ransom.

The most recent major ransomware families, such as CryptoLocker and Ryuk, rely on a new tactic called “cryptoworming,” which is the simultaneous exploitation of multiple vulnerabilities across a network. These attacks can bypass antivirus software, disable backup files, and corrupt system restore features to amplify the attack’s impact.

While some attackers have successfully negotiated ransom payments from their targets, many others have simply refused to pay and have had their systems permanently destroyed by the malware. To avoid being held hostage by ransomware, it’s important to understand how to identify an infection and quickly disconnect systems from the Internet by disabling networking or powering them down. It’s also critical to understand that under certain circumstances, paying a ransom can violate U.S. Office of Foreign Assets Control regulations, and violators can face fines or criminal charges.