What to do in the face of growing ransomware attacks

Issue 8 2022 Cyber Security, Security Services & Risk Management

Doros Hadjizenonos.

FortiGuard Labs research found, last year, that the explosive growth in ransomware is mainly attributable to Ransomware-as-a-Service (RaaS) becoming increasingly popular on the dark web. This allows cyber criminals to purchase plug-and-play ransomware to achieve a quick payday.

This means that every organisation is at risk. Cyber criminals demanding a ransom to unlock key data and systems are targeting, no matter how big or small, or what sector they operate in, organisations around the world. In many cases, even when ransoms are paid, organisations are unable to recover all their data, leading to costly downtime and reputational damage.

Know your enemy

FortiGuard Labs explains that there are five primary ransomware attacks by types:

• Crypto ransomware or encryptors: Probably one of the most well known variants, this malware encrypts various files and data within a system, making the infected content inaccessible without a decryption key. This can also include lockers.

• Lockers: Similar to encryptors, but they lock the user out of their system entirely. Generally, the lock screen will display the ransom and demands, and in severe cases, will include a countdown clock to pressure victims into paying.

• Scareware: A fake software that claims to have detected a virus or similar issue with your system and directs the user to pay to solve the issue. Some variants will lock the user from other functionalities of the system, while others will flood the screen with pop-up alerts without causing any damage.

• Doxware/leakware: As the name suggests, leakware threatens to distribute sensitive information or company files online and pressures the user into paying a fee to prevent data from entering into the public domain.

• Ransomware-as-a-Service (RaaS): Malware carried out and managed by a professional hacker. The service is paid for by an individual and all aspects of the attack – from the distribution of the malware to payment collection and access restore – are carried out by hired professionals.

Knowing how attacks are carried out and staying up to date with the ever-changing threat landscape, are crucial in mitigating risk.

Have a plan

Despite 67% of organisations in our 2021 Ransomware Survey Report indicating that they have been a ransomware target (16% say they were attacked three or more times), 96% felt they were at least moderately prepared for another attack. Less than half had a strategy that included such things as network segmentation (48%), business continuity measures (41%), a remediation plan (39%), testing of ransomware recovery methods (28%), or red team/blue team exercises (13%) to identify weaknesses in security systems. Preparation, including a solid incident response plan, is critical.

Avoid common mistakes that could increase attack impact

Among the most common mistakes organisations make is incomplete security coverage, and a lack of visibility into the entire environment, which can allow attackers to move laterally for some time before the breach is discovered.

Good security hygiene puts the organisation in the best position possible for protecting against ransomware and ensuring employees are properly trained on threat trends is paramount for prevention. It is also important to equip all systems with the latest in cybersecurity defence and detection solutions, with advanced endpoint detection and response (EDR) technology, for example, integrated and consolidated into a single platform. Deflecting attacks entirely or detecting them as soon as there is a breach, are among the best measures to protect assets. It is also crucial to have immutable copies of all backups for rapid recovery.

Organisations should not underestimate their risk: they need to be prepared for ‘when’ they are attacked, not ‘if’.

First steps

In the event of malware detection, or an actual attack launching, the incident response plan should indicate who should be notified first. This usually includes the cybersecurity management team, whether that is the CIO or security manager for an internal security operations centre (SOC) team. The attack can also be reported to the South African Cybersecurity Hub. The top priority should be bringing the attack to the attention of a trained security expert to contain and remediate as quickly as possible.

By gathering as much information on the source and nature of the attack, organisations can patch the system for future prevention. Moreover, by learning how the malware was able to access the network will expose the holes hackers were able to exploit.


Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

Prevention-first approach to cybersecurity
News Cyber Security
Check Point CEO, Gil Shwed, highlights the increasing importance of artificial intelligence in defending evolving networks and protecting against cyber threats at annual CPX 360 customer and partner event.

Three new portable power stations to ease load shedding
News Security Services & Risk Management Products
EcoFlow has launched three portable power stations that provide sufficient power for consumers wherever they are; the DELTA 2 and RIVER 2 Series are feature-filled power solutions to the volatile electricity supply.

You cannot bribe a computer
Access Control & Identity Management Security Services & Risk Management
Corruption is a cancer that destroys the prospects and stability of countries and businesses. It widens wealth gaps and punishes the poor. It costs countries many billions in lost revenue.

How much protection does cyber insurance really give businesses?
Cyber Security Security Services & Risk Management
If organisations don’t meet even the minimum requirements of security and data protection, insurance will do them little good. Instead, it needs to be just one part of the digital resiliency toolbox.

Introducing adaptive active adversary
Cyber Security Products
New adaptive active adversary protection; Linux malware protection enhancements; account health check capabilities; an integrated zero trust network access (ZTNA) agent for Windows and macOS devices; and improved frontline defences against advanced cyberthreats and streamline endpoint security management.

Off-grid power solution for residential estate
Editor's Choice Security Services & Risk Management Residential Estate (Industry) Products
Coral Beach Estate, an upmarket residential estate based in East London, has been struggling with load shedding and power outages due to South Africa's energy crisis, as well as the vandalism of its power infrastructure.

SafeCity Guarding rolls out across 14 suburbs in Johannesburg
News Security Services & Risk Management
In a major drive to provide communities across Johannesburg with additional safety, Vumacam, in partnership with Fidelity ADT and other security providers across the region, rolled out the innovative SafeCity Guarding initiative in 14 suburbs.

FleetDomain underpins Afrirent’s value proposition
Logistics (Industry) Security Services & Risk Management
Afrirent, a 100% female black-owned fleet management company, has been relying on FleetDomain software for a number of years to help it deliver outstanding service to a growing number of clients.

Eleven steps to an effective ransomware response checklist
Editor's Choice Cyber Security
Anyone is a viable target for ransomware attacks and should have a plan in place to deal with a worst-case scenario. Fortinet offers this ransomware attack response checklist to effectively deal with an active ransomware attack.

Blurring the lines between data management and cybersecurity
Cyber Security IT infrastructure
In the past, data management and cybersecurity would fall under separate domains, but with more organisations making the shift to the cloud, data management and data protection have merged, essentially blurring the lines between the two.