What to do in the face of growing ransomware attacks

Issue 8 2022 Information Security, Security Services & Risk Management


Doros Hadjizenonos.

FortiGuard Labs research found, last year, that the explosive growth in ransomware is mainly attributable to Ransomware-as-a-Service (RaaS) becoming increasingly popular on the dark web. This allows cyber criminals to purchase plug-and-play ransomware to achieve a quick payday.

This means that every organisation is at risk. Cyber criminals demanding a ransom to unlock key data and systems are targeting, no matter how big or small, or what sector they operate in, organisations around the world. In many cases, even when ransoms are paid, organisations are unable to recover all their data, leading to costly downtime and reputational damage.

Know your enemy

FortiGuard Labs explains that there are five primary ransomware attacks by types:

• Crypto ransomware or encryptors: Probably one of the most well known variants, this malware encrypts various files and data within a system, making the infected content inaccessible without a decryption key. This can also include lockers.

• Lockers: Similar to encryptors, but they lock the user out of their system entirely. Generally, the lock screen will display the ransom and demands, and in severe cases, will include a countdown clock to pressure victims into paying.

• Scareware: A fake software that claims to have detected a virus or similar issue with your system and directs the user to pay to solve the issue. Some variants will lock the user from other functionalities of the system, while others will flood the screen with pop-up alerts without causing any damage.

• Doxware/leakware: As the name suggests, leakware threatens to distribute sensitive information or company files online and pressures the user into paying a fee to prevent data from entering into the public domain.

• Ransomware-as-a-Service (RaaS): Malware carried out and managed by a professional hacker. The service is paid for by an individual and all aspects of the attack – from the distribution of the malware to payment collection and access restore – are carried out by hired professionals.

Knowing how attacks are carried out and staying up to date with the ever-changing threat landscape, are crucial in mitigating risk.

Have a plan

Despite 67% of organisations in our 2021 Ransomware Survey Report indicating that they have been a ransomware target (16% say they were attacked three or more times), 96% felt they were at least moderately prepared for another attack. Less than half had a strategy that included such things as network segmentation (48%), business continuity measures (41%), a remediation plan (39%), testing of ransomware recovery methods (28%), or red team/blue team exercises (13%) to identify weaknesses in security systems. Preparation, including a solid incident response plan, is critical.

Avoid common mistakes that could increase attack impact

Among the most common mistakes organisations make is incomplete security coverage, and a lack of visibility into the entire environment, which can allow attackers to move laterally for some time before the breach is discovered.

Good security hygiene puts the organisation in the best position possible for protecting against ransomware and ensuring employees are properly trained on threat trends is paramount for prevention. It is also important to equip all systems with the latest in cybersecurity defence and detection solutions, with advanced endpoint detection and response (EDR) technology, for example, integrated and consolidated into a single platform. Deflecting attacks entirely or detecting them as soon as there is a breach, are among the best measures to protect assets. It is also crucial to have immutable copies of all backups for rapid recovery.

Organisations should not underestimate their risk: they need to be prepared for ‘when’ they are attacked, not ‘if’.

First steps

In the event of malware detection, or an actual attack launching, the incident response plan should indicate who should be notified first. This usually includes the cybersecurity management team, whether that is the CIO or security manager for an internal security operations centre (SOC) team. The attack can also be reported to the South African Cybersecurity Hub. The top priority should be bringing the attack to the attention of a trained security expert to contain and remediate as quickly as possible.

By gathering as much information on the source and nature of the attack, organisations can patch the system for future prevention. Moreover, by learning how the malware was able to access the network will expose the holes hackers were able to exploit.


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Cybersecurity needs actual intelligence before artificial intelligence
Information Security AI & Data Analytics
Cybersecurity depends on interpretation. A tool can tell you that something unusual has happened, but people need to determine whether it is a genuine risk, the business impact, and how to respond without causing unnecessary disruption.

Read more...
Duxbury Cybersecurity sharpens reseller offering
Duxbury Networking Information Security News & Events
Duxbury Networking has strengthened its Duxbury Cybersecurity business unit by adding WatchGuard and Cynet, giving South African resellers broader, more integrated coverage for the security risks customers are now asking them to address.

Read more...
Echoes of 2018? Follow-up on Woolworths explosions
Technews Publishing News & Events Security Services & Risk Management Retail (Industry) Facilities & Building Management
SMART Security Solutions follows up with Jimmy Roodt to find out more about an old connection to the Woolworths bombings from 2018. The investigation remains ongoing.

Read more...
NEC XON detects and stops ransomware attack
NEC XON Information Security IoT & Automation
Ransomware attacks rarely begin with chaos. More often, they start quietly, with probing, mapping, and patient reconnaissance inside a target’s network. That was the situation facing a global recruitment firm when cybercriminals attempted to navigate its systems.

Read more...
Next-generation cash-in-transit vehicle
News & Events Security Services & Risk Management
Fidelity Services Group has unveiled a new, purpose-engineered Cash-in-Transit (CIT) vehicle designed to redefine crew protection, deter threats, and enhance operational resilience in an increasingly complex criminal environment.

Read more...
Sara AI Pentesting available in South Africa
Information Security News & Events
Synack and Wolfpack Information Risk are offering Sara AI Pentesting to organisations across South Africa, helping companies move from point-in-time testing to continuous security validation with AI and human expertise.

Read more...
Sophos establishes South African legal entity to strengthen local operations
News & Events Information Security
Global cybersecurity company, Sophos, has announced the formation of its local legal entity, which will support local invoicing, partner enablement, compliance requirements and expanded regional investment.

Read more...
AURA partners with Discovery to launch Discovery 911
News & Events Security Services & Risk Management
AURA has announced a partnership with Discovery Insure to power the security-response component of its new Discovery 911 virtual panic-button offering, which is available through the Discovery Insure app.

Read more...
Cybersecurity in a digitally connected security industry
SA Technologies Information Security IoT & Automation
As more organisations move towards digital visitor management, cloud-based access control, mobile applications, biometric verification, and connected security platforms, cybersecurity must be viewed as part of the full security environment.

Read more...
Enterprises must prepare for digital conflict
Information Security
Cyberattacks can be launched remotely and at scale. A coordinated attack launched from anywhere in the world can disrupt supply chains, shut down utilities, or expose millions of customer records within minutes.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.