Understanding Ransomware Attacks
Ransomware is malware that encrypts files, halts operations and demands payment to regain access. It is a profitable business model for cyber mafias, with annual ransomware-induced costs expected to reach $265 billion by 2031. New strains and variants are constantly evolving to get past traditional defenses. Examples include WannaCry, GandCrab, and Cerber.
During the attack phase, ransomware first gains a foothold on the target computer or network. Some types of ransomware also disable system restore features or encrypt backups on the host device to increase pressure for payment. Other types of ransomware exfiltrate sensitive data (login credentials, customer information, intellectual property) and threaten to publish it online as additional extortion.
The attack phase ends when the attacker understands local systems and domains that they can currently access. Attackers then focus on gaining access to additional systems and domains, a process known as lateral movement. The final attack stage focuses on identifying and encrypting the most valuable data and files.
Ransomware attacks have significant financial and reputational impacts, including lost productivity, downtime and legal fees. To mitigate these risks, organizations can apply a combination of controls, including performing regular vulnerability scanning on internet-facing devices, maintaining offline, encrypted backups and regularly testing them, and educating employees about how to identify phishing emails, suspicious external links and questionable file attachments. Organizations can also implement security policies and procedures to prevent ransomware infections, including quarantining machines that have been infected.