Showing posts with label Cloud Antivirus. Show all posts
Showing posts with label Cloud Antivirus. Show all posts

Wednesday, November 4, 2020

What is a Computer Virus and How to Remove It | Free Antivirus

A virus is a type of malware - a harmful program created by hackers that can infect your computer or device in various ways. They can be really difficult to remove and can spread from one device to another. Fortunately, we can take some steps to protect your devices, and we have some suggestions on how to remove a virus.

Computer Virus

How does a computer virus work? Programmers are the ones who write a virus to place, overwrite, or replace another program on your computer to reproduce itself without your knowing it.

A virus can cause various problems on an infected device. This can quickly consume all of your computer's available memory, slowing or stopping your system. Viruses can damage data, destroy files, format hard drives, or make drives unreadable. A virus can enter your computer as an email attachment, in a downloaded file, or hidden on a zip drive or CD. In general, the presence of a virus is not evident on a website, in an email, or in another item.

Common Symptoms of Computer Viruses

Your computer may have a virus if you have any of these problems:

  • Suspension or blocking
  • Lost or damaged files
  • Problems saving files
  • The computer restarts unexpectedly
  • Programs open randomly
  • Task manager won't open
  • Constant pop-up boxes
  • Much more spam than usual in email
  • Windows updates won't install
  • Cannot open files and folders
  • Passwords changed
  • Problems installing new software
  • Considerable slowness in switching on and/or off
  • Unexpected errors such as low memory and missing system files
  • Hardware issues such as an unresponsive keyboard or printer

How to Avoid Having a Computer Virus?

We have some precautions you can take to take care of your devices:

Install a recognized antivirus. Even if you don't take any other preventive measures, using antivirus will offer your devices basic protection and monitoring against viruses. This ensures that if you do become infected, you will be warned quickly and can address the problem before the virus has a chance to do irreparable damage to your computer. All CenturyLink High-Speed ​​Internet customers can download Protegent Free Antivirus at no additional charge. Learn more about Protegent360. 

Keep your virus definitions up to date. To be effective, antivirus software must be kept up to date. It is important that you download the latest virus definitions when your antivirus software tells you to. You can automate this task so you don't forget to run it. Protegent360 security is cloud protection that offers continuous updates and monitoring, so you don't have to worry about updates.

Run your antivirus software routinely. Again, if you find this to be heavy (or just forget to do it), you can automate the task.

Be proactive. Analyze your files and programs. You can configure your antivirus software to automatically scan emails and files before opening / downloading them. It's good to scan ALL files, even if you trust the source.

Make backup copies of your files frequently. New malware is created daily. Having a backup of your data can save you if a virus bypasses your protection measures.

Keep your programs and operating system updated. This may seem like a challenge, but updates are essential to keep your computer virus-free. Updates often include patches to fix security vulnerabilities that could be exploited, and if you don't update your software, you could miss the latest update. You can also automate this task in your computer settings.

Protect your WiFi network. Enabling a WPA password on your home Wi-Fi will help prevent unwanted users from entering your wireless network. If you need to provide the Internet to friends, most routers allow you to set up a guest network that allows them to use the Internet without giving them access to your main network, thus protecting you from potentially infected devices. Certain CenturyLink leased modems also offer Secure WiFi, which has Prortegent360 built-in.

How to Remove a Computer Virus

If you think your device is infected, the first step is to run a full antivirus scan. 

If you use CenturyLink Security powered by Protegent360, there is no need to do anything else. The program runs continuously and automatically quarantines any threats it detects.

If your antivirus cannot remove the virus, these are the steps you should follow:

Try doing an online search to find out how to remove the virus. You are likely to get the most accurate results if you know the name or source of the virus you suspect or can describe the specific symptoms.

Call a professional. If you can't find a solution online, call an IT professional right away, before it gets worse.

Friday, October 30, 2020

An Overview of the Most Dangerous Ransomware Viruses in 2020 | Cloud Antivirus

For decades, cybercriminals have successfully exploited flaws and vulnerabilities on the World Wide Web. However, in recent years, there has been a clear increase in the number of attacks, as well as an increase in their rate - attackers are becoming more dangerous and malware is spreading at a rate never seen before.

Most Dangerous Ransomware

Introduction

We are talking about the ransomware that made an incredible leap in 2020, causing damage to thousands of organizations around the world. For example, in Australia, ransomware attacks such as WannaCry and NotPetya have even raised government concerns. To summarize the ransomware “successes” this year, we will look at the 10 most dangerous and most damaging organizations. Hopefully next year we will learn lessons and prevent this kind of problem from entering our networks.

1. NotPetya

The ransomware attack began with the Ukrainian accounting software MEDoc, which replaced 1C, which was banned in Ukraine. In just a few days, NotPetya infected hundreds of thousands of computers in over 100 countries. This malware is a variant of the older Petya ransomware, except that the NotPetya attacks used the same exploit as the WannaCry attacks. As it spread, NotPetya affected several organizations in Australia, such as the Cadbury chocolate factory in Tasmania, which had to temporarily shut down their entire IT system. The ransomware also managed to infiltrate the world's largest container ship, owned by Maersk, which reportedly lost up to $ 300 million in revenue.

2. WannaCry

This ransomware, terrible in scale, has practically taken over the entire world. Its attacks used the infamous EternalBlue exploit, which exploits a vulnerability in the Microsoft Server Message Block (SMB) protocol. WannaCry infected victims in 150 countries and over 200,000 machines on the first day alone. We have published a personal file of this sensational malware.

3. Locky

Locky was the most popular ransomware in 2016, but it has not stopped operating in 2020. New variants of Locky, dubbed Diablo and Lukitus, emerged this year, using the same attack vector (phishing) to target exploits. Locky was behind the Australian Post email fraud scandal.

4. CrySis

This instance excelled in its masterful use of the Remote Desktop Protocol (RDP). RDP is one of the most popular ways to distribute ransomware, as cybercriminals can thus compromise machines that control entire organizations.

5. Nemucod

Nemucod is spread using a phishing email that looks like an invoice for shipping services. This ransomware downloads malicious files stored on compromised websites. In terms of phishing emails, Nemucod is second only to Locky.

6. Jaff

Jaff is similar to Locky and uses similar techniques. This ransomware is not remarkable for its original methods of distributing or encrypting files; on the contrary, it combines the most successful practices.

7. Spora

To distribute this type of ransomware, cybercriminals hack legitimate sites by adding JavaScript code to them. Users visiting such a site will receive a pop-up warning prompting them to update their Chrome browser to continue browsing the site. After downloading the so-called Chrome Font Pack, users became infected with Spora.

8. Cerber

One of the many attack vectors that Cerber uses is called RaaS (Ransomware-as-a-Service). According to this scheme, cybercriminals offer to pay for the distribution of the Trojan, promising a percentage of the money received for this. This “service” allows cybercriminals to send out ransomware and then provide other attackers with tools to distribute.

9. Cryptomix

It is one of the few ransomware that does not have a specific type of payment portal available within the dark web. Affected users must wait for cybercriminals to email them instructions. Cryptomix victims were users from 29 countries, they were forced to pay up to $ 3,000.

10. Jigsaw

Another malware from the list that started its activity in 2016. Jigsaw inserts an image of a clown from the Saw movie series into spam emails. As soon as the user clicks on the image, the ransomware not only encrypts but also deletes the files in case the user delays in paying the ransom, the size of which is $ 150.

Conclusions

As we can see, modern threats are using increasingly sophisticated exploits against well-protected networks. While increased employee awareness is helping to cope with the impact of infections, businesses need to go beyond basic cybersecurity standards to protect themselves. Defending against today's threats requires proactive approaches that leverage real-time analysis capabilities based on a learning engine that includes understanding the behavior and context of threats. You have to more depend on cloud antivirus rather than traditional antivirus so that your security protection will be totally cared for by the cloud server organization.

Wednesday, October 28, 2020

Cybersecurity Tips for Business | Use Cloud Antivirus Service

The Internet is constantly growing and improving, thanks to this we can now communicate freely with people all over the world. With the spread of Wi-Fi, we began to create devices that also connect to the Internet by transmitting data over the network. This is great, but the flip side of the coin is that every person connected to the Internet on the planet now has their own networks and their own data, which can become a victim of theft.

Prevent Cybercrime Against Small Business

We believe that raising awareness of these vulnerabilities and educating the public can make the internet a little safer. It will be useful for businesses to learn about such effective information security measures as employing hackers, simulating phishing for their employees, and cyber insurance policies.

Basic Rules to Prevent Cybercrime Against Small Business

1. Be Careful With What You Post About Yourself and Others

How you talk about others on the Internet reveals a lot about your own personality. In addition, you can get yourself in trouble with the law or even become vulnerable to theft or burglary. People can track what you say online - so if you said you were going on vacation for the week, it should be easy for a potential burglar to find your address. Caution should be exercised about violations of NDAs, employment contracts, and other agreements that you have signed. In addition, it may be a violation of the law to disclose someone else's personal information or publicly accuse a person without any evidence.

2. Understand What Data Your Company Collects - and Make Sure It is Protected

In order to keep your business data safe, you must audit and determine which of them is public information (and therefore should not be closely guarded), which are of medium importance, so that they will not greatly affect the business. in the event of a leak (some security measures should be established for them) and, finally, which data is most important and confidential. The last category of data will greatly affect the business in the event of theft - and it must be protected as reliably as possible with the strictest access rights for employees and partners.

3. Use Multiple Authentication Factors

Authentication is the act of confirming identity (whether a user, computer, or other devices) by comparing the provided credentials with an existing database of authorized users before allowing a given system or application to access the system. For example, entering a username and password to access your email account. But instead of relying only on passwords, which are becoming increasingly insecure, we recommend using multiple factors for authentication. These factors include some user secrets (for example, username/password, answer to a secret question), some of their physical property (for example, digital certificate, smart card), and some biometric factor (for example, fingerprint, face recognition).

4. Enable Https for Your Site

An SSL / TLS certificate is installed on the server to activate HTTPS. This certificate encrypts all data between the browser and the server, be it personal or financial information that is entered on a web page, or the content of pages. In this way, information is protected from outsiders (for example, from intruders and government surveillance). SSL certificates can also tie your brand to a website: this allows visitors to verify that your site really belongs to your company and not a scammer (in the case of a phishing site). The EV SSL certificate clearly demonstrates this by coloring your browser address bar green and showing your company name.

5. Use Strong and Unique Passwords

Many black hackers sell data that they managed to get after hacking. This includes information about thousands, if not millions, of users and their passwords. If you use the same password on every account, then it becomes a trivial task for a hacker to gain access to all of your systems. Or a hacker can brute force the password. It is much more difficult if the password is long, composed of a variety of characters, and does not contain words from the dictionary. Use a password manager to ensure you don't forget unique passwords for each service.

6. Update All Software

Hackers are always looking for new vulnerabilities in the software your business is using. Finding them is as easy as finding a path on your Windows network. At the same time, the software companies themselves are working hard to release patches to fix these vulnerabilities, so it is very important to update the software as soon as an update is released.

7. Back Up All Data

Backups ensure that files can be recovered in the event of data loss. You should always store your data in different locations, physically separated, so that hackers cannot access everything at once. And the backups need to be updated regularly.

8. Install a Firewall on the Internet Gateway

Firewalls are designed to prevent unauthorized access to the private network. A set of rules can be established to determine which traffic is allowed and which is denied. A good firewall should monitor both inbound and outbound traffic.

9. Use the Cloud Antivirus

Cloud services are a useful tool, especially for small and medium-sized companies that want to place their data under the protection of a large company. When registering with a cloud antivirus provider, it is important to make sure you know everything about it. Where are the data centers, where exactly your data is stored, and how you can access it?

10. Security Training for Employees

From time to time security training should be arranged for employees to educate them about various cyber threats.

  • Establish rules for using your own devices in the workplace
  • Create an incident response strategy
  • Training employees to work with passwords
  • Make sure employees check for the letter s in https when they search the web
  • Use secure email communications and provide training on the risks of phishing attacks
  • Leaders must spread a culture of cybersecurity
  • Simulation of phishing to keep employees in good shape - in a playful way for interest

Monday, October 5, 2020

Do Cloud Services Need Antivirus | Cloud Antivirus

Recently, cloud services have become familiar, haven't they?

Previously, I saved my documents on my PC and operated emails, websites, databases, etc. on my own server. Now that cloud services have become commonplace, all of these features are being replaced by cloud servers.

However, in order to introduce a new product, you need to understand the risks well.

First, I will explain the main risks of using the cloud.

so we often hear concerns about "cloud services". Antivirus is especially common. Services over the network inevitably carry the risk of viruses and unauthorized access, which are threats on the Internet.

So, this time, I would like to talk about antivirus measures that are of concern when using cloud services.

Cloud Antivirus

Attack on the Cloud

A problem these days is cyber attacks on servers. Not only cloud services but also corporate systems can be targeted by cyberattacks, but attack methods such as concentrating a large amount of access to paralyze communication and stealing information are used.

Although it is a risk that cannot be dealt with at the user level, cloud service vendors are taking various measures. Since the countermeasures of each vendor are published, please use it as a judgment standard at the time of introduction.

Not only cyber attacks but also disaster responses are properly taken by vendors. Similarly, countermeasures are open to the public, so please check when considering.

Viruses and Malware

A virus is a type of malware (malicious program) that can be executed and damaged without the user's knowledge.

Whether it is a cloud service or not, there is a risk that the virus will infect your local PC through email, websites, etc.

Many companies have installed cloud antivirus software depending on the infection route and the type of virus for cloud services, it also scans the data stored on the server.

Human Error

There are cases where account information is leaked due to improper management of account information or loss of a device, or data on the cloud is leaked due to incorrect file-sharing settings. There are measures such as strengthening account authority management, detecting abnormal access and suspending the account, and monitoring confidential information with DLP.

Exchange Online Protection (EOP)

Email is one of the gateways to malware intrusion. In some cases, the malware itself is attached to the email, but in other cases, spam emails can be used to promote access to the malware or become a gateway to phishing scams.

Exchange Online Protection (EOP) is equipped with spam filters, safe senders and rejected lists, IP addressing, content filters, etc., and has a quarantine function to detect and prevent unauthorized access.

Advanced Threat Protection (ATP)

Free antivirus software refers to a list of known viruses and detects matching programs like viruses, but it was difficult to deal with new viruses. Advanced Threat Protection (ATP) is an email filtering service that supports unknown viruses.

Saturday, October 3, 2020

What is Pharming and How to Protect From It?

Pharming is a malicious type of internet fraud that subverts the very foundations of the network. By manipulating web traffic, pharming attackers try to trick their targets into providing valuable personal information. As pharming is very sneaky, many victims only discover that they have been duped when it is too late. This article will cover what pharming is, how it works, and, most importantly, what you can do to prevent it from happening to you.

Protect from Pharming

What is Pharming?

Pharming is when a criminal hacker (or "pharmer") directs an internet user to a fake, rather than legitimate, website. These "spoofed" sites can capture the victim's confidential information, including usernames, passwords, and credit card data, or install malware on their computers. Pharmers generally focus on financial sector websites, such as banks, online payment platforms, or other e-commerce destinations, usually with identity theft as their ultimate goal.

Pharming attacks are effective because they trick victims and their computers. The pharmer tricks the victim's computer into sending him to his website, not where he should go. This works like this:

When navigating to a website, users enter the website's URL, which is converted by a DNS server to a numeric IP address. Confused? Calm. Think of the DNS server as a phone book, where the URL is the name of a website and the IP address is the telephone number of the website. Pharmers can edit the list and change the phone numbers that belong to the chosen website.

Pharming, in terms of computers, compromises internet traffic at the DNS level, sending the user to a fake website created by the hacker.

Scroll down for more information on how pharming works.

Pharming vs Phishing

So, what is the difference between pharming and phishing? These two strokes are similar, but not exactly the same. Phishing, as the name implies, uses bait: hackers send e-mails or other official-looking communications that invite victims to visit fake websites and enter their personal information.

Pharming ignores the bait and sends victims to the fake site without their knowledge or consent. Because victims are typing in URLs, instead of clicking links in a suspicious email, they are less likely to detect fraud. It is a more subtle fraud when compared to more obvious phishing techniques.

How to Protect Yourself Against Pharming

Fortunately, there are proven strategies you can practice to protect against pharming attacks. In addition to these pharming security tips, it's never a bad idea to review the basics of internet security in the digital age.

Choose a trusted internet service provider (ISP) - Most major ISPs will automatically filter out fake pharmer redirects, preventing you from accessing their website. The newer ISPs may seem tempting with attractive offers and very high speeds, but make sure they are as dedicated to your security as the more established providers.

Check your URLs for typos - After navigating to a website, wait for it to load and review the URL again. Pharmers often disguise their websites with little spelling tricks, including changed letters or letter replacements: for example, "aug.com" instead of "avg.com".

Look for URLs that start with HTTPS - If you see HTTPS, it means that all traffic between the site and you are encrypted, so it cannot be intercepted by a third party. Sites with this enhanced level of security automatically change their URL from HTTP to HTTPS, stating that their data is secure. This tip is especially important when making a financial transaction or exchange.

Stay away from questionable sites - Use common sense when browsing the internet. Stick to sites you can trust and stay away from anything that looks suspicious.

Evaluate sites before doing anything - If a trusted site doesn't look like the usual, you may be in a pharmer's version. Click on it a little and check that all pages are present and recognized. Many pharmers will not bother to include terms of service or privacy policies.

Avoid links and files from unknown sources - Be careful when downloading files and think twice before clicking on strange links. It is much more difficult for you to be tricked by pharmers if they are unable to install the malware on your computer.

Avoid e-commerce deals with by-products - If an electronic shopping discount sounds too good to be true, it probably is. Many pharmers will try to attract you at prices 10% to 20% lower than any product offered by legitimate stores. Check the price on competing sites before making a purchase.

Trust your antivirus software - Pay attention when your browser or antivirus software alerts you about browsing to a specific website. Even if you have used this site before, a warning can be an indication that it has been infected since your last visit. And speaking of antivirus ...

Protect yourself with powerful antivirus software from a trusted provider - the Protegent360 antivirus software protect your computer from malware and unwanted redirects pharming, especially when you accidentally stumble on an unsecured site. Attackers love to adjust their pharming strategies, and Protegent360 is constantly updated to ensure protection against new threats.

Monday, September 28, 2020

Prevent Cryptocurrency Mining Malware With Total Security

Ransomware, the flagship of malware, has for years spread terror and fear among businesses and users of the threat of data loss. Now, in 2020, Ransomware faces serious competition at the top of the cybercrime food chain .... cryptocurrency mining malware. According to Comodo Cybersecurity Threat Research Labs, crypto-based attacks have become the number one security threat for 2020 to date.

What is Cryptocurrency Mining Malware?

Cryptocurrency Mining Malware

Cryptomining, cryptocurrency encryption malware, or Cyptojacking, terms so new that they have not yet been added to online spellcheckers, are forms of malware that hijack a computer's resources and use them to mine cryptocurrency, like Bitcoin, without the user's permission. . Since mining cryptocurrency is a fairly large task on a PC or server, cryptocurrency mining malware has caught the attention of hackers and data, thieves, by harnessing the processing power of several devices at the same time. Essentially, its malware that creates an army of blindly crypto mining machines is auctioned off from their cybercriminal overlord.

In the first three months of 2020, Comodo said it detected 28.9 million crypto miner incidents out of a total of 300 million malware incidents.

Although Bitcoin is the most popular and well-known form of cryptocurrency, hackers target other types of online currency, such as Monero and Dogecoin. In fact, there are currently over 1,600 forms of cryptocurrencies, with more likely to come in the next few years, meaning this form of malware and illegal activity may be here to stay.

When it comes to devising type, virtually everything is at risk, including servers, computers, mobile devices, and devices connected to the Internet of Things (IoT). Also, as the competition between hackers is expected to accelerate, they will start to focus on high-end devices with more computing power to maximize their investment time.

Why is Cryptocurrency Mining Malware Beating Ransomware?

Cryptocurrency mining malware is gaining ground over ransomware as a means of blocking Bitcoin as it can go undetected for months or even years on a user's system, while ransomware immediately reveals its presence. to the user. Additionally, ransomware attacks are generally considered to be risky, as users can choose to sacrifice their data or restore a recent backup instead of forcing electronic cash. Cryptocurrency mining malware, however, when scattered across thousands of different devices, can generate millions in cryptocurrency.

Additionally, since ransomware has dominated the news over the past few years, many companies have stepped up their ransomware security practices, making it harder for cybercriminals to earn digital coins with common ransomware attacks. This has prompted hackers to seek out new, more profitable methods of deploying their skills.

How Do I Know if I Have Been Infected With Cryptocurrency Mining Malware?

Since this is a somewhat emerging threat, it might be a good idea to take a look if you've been a victim of this type of malware before. Here are some ways to check:

  • Monitor devices for high CPU usage
  • Install a network monitoring solution
  • Remind employees to notify IT if their devices are running slower than usual

Why should I care?

This threat represents another potential exploit in your systems and it also encourages attackers to re-prioritize to achieve stealth and persistence for extended periods of time. Although at first, it is not as damaging and time-consuming as ransomware, cryptocurrency mining malware can cause your computer resources to increase significantly and in some cases render them unusable and even increase your costs. electricity costs. Good security hygiene can help minimize the risk of your organization falling victim to these types of attacks, and you should continue to invest in security awareness training and an advanced antivirus like Protegent360's Total Security and anti-malware solution. Also, don't forget the basics.

Saturday, September 26, 2020

Cloud Antivirus Versus Traditional Antivirus

Cloud Antivirus Vs. Traditional Antivirus

When we talk about cloud antivirus or cloud antivirus, many people may have certain doubts regarding their operation and if they are a good solution to protect their data. Reality shows once again that antivirus in the cloud has established themselves as a way to protect our data more and more secure, often serving as redundancy for our antivirus PC, or even an alternative.

Cloud Antivirus Vs. Traditional Antivirus

What are the advantages of antivirus in the cloud compared to other software solutions to install on our desktop? Is a program in the cloud safer than a computer antivirus? Let's enter this interesting debate with some compelling reasons.

Cloud Antivirus Versus Traditional Antivirus

To clarify the concept, antivirus as a service is installed on a remote server, but thanks to our Internet connection it protects all our equipment, as well as our activity when browsing online. Panda Cloud, Bit Defender, and Protegent360 have developed cloud solutions for companies that are very useful when it comes to protecting multiple terminals in a company.

On the other hand, the traditional antivirus is the one we all know; You download it, install it on your computer and it starts working.

It must be said in favor of cloud antivirus that allows you to make your computer not go so slow. They free up your CPU from antivirus activity, and you don't have to constantly install updates. If you have the problem that the antivirus slows down your computer a lot, the best solution is to have your antivirus hosted on an external server.

Cloud antivirus is the most appropriate option to protect your email and all the online programs you use, although most cloud management software already has the necessary security systems on their servers. In addition, following good practices in online security, such as setting difficult passwords and avoiding downloading suspicious files and programs from unknown manufacturers.

Proponents of traditional antivirus believe that the danger of cloud antivirus software is that if malware affects your Internet connection, your computer will be left unprotected. However, it must be remembered that the vast majority of computer viruses enter through the Internet, so the cloud antivirus would stop it before it cut the connection.

A different question is whether or not we are using a good antivirus, since the fact that it is cloud does not mean that the software will be better. However, generally, the most advanced antivirus has a cloud version and is much more modern and efficient.

The experts on online security advise combining antivirus cloud with which we installed on the computer itself, using the traditional version as a backup for the hypothetical case that the Internet connection was cut. However, it should be remembered that surfing the web responsibly and following the best computer practices is the most effective way to prevent the entry of any computer virus.

Wednesday, September 16, 2020

How to Protect Your Data Backup From Ransomware?

Ransomware gets smarter by attacking backups to prevent recovery. To prevent this from happening, take a few simple steps.

Despite the recent decline in the number of attacks, ransomware still poses significant threats to businesses. Such attacks become more dangerous. In particular, ransomware authors understand that backups are significant defenses and modify their malware to track and destroy backups.

Reducing the Number of Ransomware

The company McAfee reported a decrease in the number of malware samples, and over the past year. According to the latest report, in the third quarter of 2019, the number of ransomware samples was less than half of the number of samples at the end of 2018, when their number reached about 2.3 million. According to Kaspersky Lab, 765,000 of its users were thrashed by malware that encrypted files over the past year, compared with more than five million that were attacked by crypto miners.

BitDefender Threat Research Director Bogdan Botezatu says the main reason for stopping ransomware attacks is because security companies are better protected against them. “There will always be new versions of ransomware, some of which will be more cultivated than others and some more difficult to catch, but we do not wish the ransomware to become much larger in scale,” he says. "At least not more than last year."

“For several years, ransomware has been the main threat, but the numbers have declined significantly,” said Adam Kujava, head of malware research at Malwarebytes. However, the ransomware that is there is evolving, he says. For example, malware authors take advantage of the latest exploits such as the ones leaked from the NSA. “We see them popping up in many relatives of malware,” he says. “When you use this kind of exploit, if you infect one system, you can infect a lot more using these exploits. You're creating a much bigger goal - that's a trend. "

Backup is the New Target of Ransomware

According to Kuzawa, the Ransomware now deletes all backups that come along the way. For example, a common ransomware tactic is to delete automatic copies of files that Windows creates. “So if you go to system recovery, you can't go back,” he said. "We've also seen how they access shared network drives."

Two recent examples of ransomware that have a sight on the backups, - Samsam and Ryuk. In November, the US Department of Justice indicted two Iranians to use malware SamSam to extort more than $ 30 million in more than 200 victims, including hospitals. The attackers maximized the damage by launching attacks outside business hours and "encrypting the victims' computer backups," the indictment says.

Most recently, Ryuk hit several major objectives, including the Los Angeles Times and the provider of cloud data Data Resolution. Ryuk includes a script that removes shadow volumes and backup files, according to security researchers at Check Point. “While this particular malware variant is not specifically designed for backups, it compromises simplified backup solutions that result in storing data on file shares,” says Brian Downey, senior director of product management at Continuum, based at Boston. a technology company that offers backup and recovery services.

The most common way is to use a Microsoft Windows feature called "Previous Versions," said Munir Hahad, head of threat research at Juniper Networks. This allows users to restore earlier versions of files. “Most ransomware variants delete shade copy snapshots,” he says, counting that most ransomware attacks will also attack backups on connected network drivers.

Ransomware Attack on Opportunistic, Untargeted Backups

However, this does not mean that all backups are vulnerable. According to David Lavinder, chief technology officer at Booz Allen Hamilton, when ransomware uses backups, these are not intentional targets. Depending on the ransomware, it usually works by scanning the system looking for certain types of files. “If it locates the extension of the backup file, it will encrypt it for sure,” he says.

Ransomware is also trying to spread by infecting as many other systems as possible, he says. This is a type of worm, as is the case with WannaCry, where more activity is expected to be seen in the future. “We don't desire to see deliberate targeting of backups, but we do expect to see more attentive efforts,” he says.

You can protect your backups and systems from these new ransomware tactics by taking a few basic protection.

Supplement Windows Backups With Extra Copies and Third-party Tools

To protect itself from ransomware that deletes or encrypts local file backups, Kujawa suggests using additional backups, third-party utilities, or other tools that are not part of the default Windows configuration.

Isolate Backups

The more barriers live between the infected system and its backups, the more difficult it will be for the ransomware to get to it. One common mistake people make is that users use the same authentication method for their backups as elsewhere, according to Landon Lewis, CEO of Pondurance, a cybersecurity consulting firm in Indianapolis. “If your user's account is compromised, the first thing an attacker wants to do is to elevate their privileges,” he said.

Store Multiple Copies in Multiple Locations

Lewis recommends that companies keep three different copies of their important files using at least two different backup methods, and at least one of them should be in a different location. Cloud backups provide an easy-to-use off-site backup option, he says. “It is very inexpensive to block online storage. It's hard to argue why someone wouldn't use it as an additional backup method. And if you use a different authentication system, that's even better. " Addition to cloud storage companies should rely on cloud antivirus for any potential vulnerability.

November 27 is Black Friday and November 30 is Cyber ​​Monday

One of the strongest sales campaigns in shops and online sales recently established in Spain is Black Friday and Cyber ​​Monday. A tradition...