Showing posts with label Ransomware. Show all posts
Showing posts with label Ransomware. Show all posts

Monday, November 9, 2020

Cybersecurity: Types of Attacks and What They Consist of

Cyberattacks hit businesses every day. John Chambers, CEO of the multinational Cisco said: "There are two types of companies: those that have been hacked and those that have been hacked but do not know it. To combat a world where computer security has become one of the pillars of organizations, in this article we explain the different types of cybersecurity attacks and what they consist of. Keep reading!

Types of Cybersecurity Attacks


Types of Cybersecurity Attacks: What is a Cyber Attack?

For starters, what is a cyber attack? A cyber attack is a set of offensive actions against information systems. These can be databases, computer networks, etc. The objective is to damage, alter, or destroy organizations or people. In addition, they can take down the services they provide, steal data, or use it to spy.

We live in a digital age. Today most people use a computer with the Internet. Therefore, due to the dependence on digital tools, illegal computer activity grows without stopping and seeks new and more effective forms of crime.

We can classify the types of cybersecurity attacks into three categories:

  • Phishing attacks
  • Malware attacks
  • Web attacks

PHISHING

Phishing is a type of social engineering that is used, generally, to steal user data. They can be credit card numbers or passwords, for example. It occurs when a criminal poses as a trusted person. Then it tricks the victim into opening a text, email, or SMS message using a malicious link. This link can cause a ransomware system to freeze, reveal confidential information, or install malware.

It is simple and very easy to use the technique, which is why it is one of the most dangerous. It can have disastrous results. For an individual, it can lead to identity theft, funds theft, or unauthorized purchases.

SPEAR PHISHING

On the other hand, spear phishing is computer attacks that target a specific person or employee of a specific company. To carry out these types of attacks, criminals meticulously collect information about the victim to gain their trust. Falling for these attacks is usually very common, since a well-prepared email, either with a malicious link or attachment, is very difficult to distinguish from a legitimate one.

This technique is widely used to attack companies, banks, or influencers.

WHALING

In third place on the list of types of cybersecurity attacks, we find whaling attacks. These attacks target a senior manager profile, such as CEOs or CFOs. The objective, like the previous ones, is to steal vital information, since those who occupy high positions in a company usually have unlimited access to confidential information. In most of these so-called "whaling" scams, the offender manipulates the victim to allow high-value wire transfers.

The phrase "whaling" refers to the size of the attack, as the whales are attacked depending on their position within the organization. These types of attacks are easier to detect compared to standard phishing. A company's IT security officers can reduce the effectiveness of this hack.

Malware or Malicious Software

Second, among the types of cybersecurity attacks are malware. Malware is code created to stealthily corrupt a computer system. It is a broad term that describes any malicious program or code that is harmful to systems. Intrusive malware invades, damages, or disables computers, computer systems, mobiles, etc. assuming control of operations.

The goal of malware is usually to get money from the user illegally. Although it generally cannot damage the hardware of the systems, it can steal, encrypt, erase data, or hijack the basic functions of a computer, as well as spy on its activity without anyone noticing.

Malware includes many types of malicious software, such as spyware, ransomware, Trojans, etc.

RANSOMWARE OR DATA HIJACKING

Ransomware is malicious software that, by penetrating our computer, gives the hacker the ability to block a device from a remote location. Also to encrypt the files, removing the user control of all the information and data stored.

In terms of its method of spread, ransomware is usually transmitted as a Trojan. That is, infecting the operating system. For example, downloading a file or exploiting a software vulnerability. The cybercriminal, who has encrypted the operating system files rendering the device unusable, usually asks for a ransom in exchange for removing the restriction on the documents.

AUTOMATIC DOWNLOADS

Automatic downloads to spread malware are one of the most common methods among types of cybersecurity attacks. Cybercriminals search for insecure web pages and plant a malicious script in the HTTP or PHP code on one of them. This script can install malware directly on the device of the user visiting the site. It can also take the form of an iframe that redirects the victim to a site controlled by the attackers. These attacks are called "automatic downloads" because they require no action on the part of the victim. You just have to visit that website.

TROJAN

A Trojan is a malicious software program that tries to disguise itself as a useful tool. They apparently spread software and persuade a victim to install it. Trojans are considered among the most dangerous types of cybersecurity attacks, often designed to steal financial information.

Users are tricked by some form of social engineering into loading and running Trojans on their systems. U activated nice, they allow cybercriminals to spy or steal your confidential information. Unlike viruses and worms, Trojans cannot replicate themselves.

For malware to be a Trojan, it only has to access and control the host machine without warning, under an innocuous appearance.

Attacks on a website

SQL INJECTION

Among the most popular types of cybersecurity attacks is SQL Injection. It is a method of infiltration of an intruder code that takes advantage of a computer vulnerability present in an application. That is, they take advantage of common design errors on web pages. The threat of SQL injections is a serious security problem related to databases. They are used to manipulate, steal, or destroy data.

Cybercriminals are capable of injecting malicious SQL queries into a website's input field, tricking the application into using the commands they want, and accessing the database they want.

An SQL injection attack can slow down the operation of a website, theft, loss or corruption of data, denial of access by any company, or even take full control of the server.

XSS OR CROSS SITE SCRIPTING

XSS attacks use third-party web resources to run scripts in the victim's web browser or programmable application.

They are a kind of injection in which the attacker sends malicious scripts to the content of web pages to discredit them. This occurs when a dubious source can attach its own code in web applications. This is sent in the form of Javascript code snippets executed by the victim's browser.

Exploits can include malicious executable scripts in many languages, including Flash, HTML, Java, and Ajax. XSS attacks can be very devastating. However, alleviating the vulnerabilities that these attacks allow is relatively simple.

What did you think of this article about the types of cybersecurity attacks? Leave us your comments and share! Also, do not forget to install total security software to protect your data from cybersecurity attacks.

Friday, October 30, 2020

An Overview of the Most Dangerous Ransomware Viruses in 2020 | Cloud Antivirus

For decades, cybercriminals have successfully exploited flaws and vulnerabilities on the World Wide Web. However, in recent years, there has been a clear increase in the number of attacks, as well as an increase in their rate - attackers are becoming more dangerous and malware is spreading at a rate never seen before.

Most Dangerous Ransomware

Introduction

We are talking about the ransomware that made an incredible leap in 2020, causing damage to thousands of organizations around the world. For example, in Australia, ransomware attacks such as WannaCry and NotPetya have even raised government concerns. To summarize the ransomware “successes” this year, we will look at the 10 most dangerous and most damaging organizations. Hopefully next year we will learn lessons and prevent this kind of problem from entering our networks.

1. NotPetya

The ransomware attack began with the Ukrainian accounting software MEDoc, which replaced 1C, which was banned in Ukraine. In just a few days, NotPetya infected hundreds of thousands of computers in over 100 countries. This malware is a variant of the older Petya ransomware, except that the NotPetya attacks used the same exploit as the WannaCry attacks. As it spread, NotPetya affected several organizations in Australia, such as the Cadbury chocolate factory in Tasmania, which had to temporarily shut down their entire IT system. The ransomware also managed to infiltrate the world's largest container ship, owned by Maersk, which reportedly lost up to $ 300 million in revenue.

2. WannaCry

This ransomware, terrible in scale, has practically taken over the entire world. Its attacks used the infamous EternalBlue exploit, which exploits a vulnerability in the Microsoft Server Message Block (SMB) protocol. WannaCry infected victims in 150 countries and over 200,000 machines on the first day alone. We have published a personal file of this sensational malware.

3. Locky

Locky was the most popular ransomware in 2016, but it has not stopped operating in 2020. New variants of Locky, dubbed Diablo and Lukitus, emerged this year, using the same attack vector (phishing) to target exploits. Locky was behind the Australian Post email fraud scandal.

4. CrySis

This instance excelled in its masterful use of the Remote Desktop Protocol (RDP). RDP is one of the most popular ways to distribute ransomware, as cybercriminals can thus compromise machines that control entire organizations.

5. Nemucod

Nemucod is spread using a phishing email that looks like an invoice for shipping services. This ransomware downloads malicious files stored on compromised websites. In terms of phishing emails, Nemucod is second only to Locky.

6. Jaff

Jaff is similar to Locky and uses similar techniques. This ransomware is not remarkable for its original methods of distributing or encrypting files; on the contrary, it combines the most successful practices.

7. Spora

To distribute this type of ransomware, cybercriminals hack legitimate sites by adding JavaScript code to them. Users visiting such a site will receive a pop-up warning prompting them to update their Chrome browser to continue browsing the site. After downloading the so-called Chrome Font Pack, users became infected with Spora.

8. Cerber

One of the many attack vectors that Cerber uses is called RaaS (Ransomware-as-a-Service). According to this scheme, cybercriminals offer to pay for the distribution of the Trojan, promising a percentage of the money received for this. This “service” allows cybercriminals to send out ransomware and then provide other attackers with tools to distribute.

9. Cryptomix

It is one of the few ransomware that does not have a specific type of payment portal available within the dark web. Affected users must wait for cybercriminals to email them instructions. Cryptomix victims were users from 29 countries, they were forced to pay up to $ 3,000.

10. Jigsaw

Another malware from the list that started its activity in 2016. Jigsaw inserts an image of a clown from the Saw movie series into spam emails. As soon as the user clicks on the image, the ransomware not only encrypts but also deletes the files in case the user delays in paying the ransom, the size of which is $ 150.

Conclusions

As we can see, modern threats are using increasingly sophisticated exploits against well-protected networks. While increased employee awareness is helping to cope with the impact of infections, businesses need to go beyond basic cybersecurity standards to protect themselves. Defending against today's threats requires proactive approaches that leverage real-time analysis capabilities based on a learning engine that includes understanding the behavior and context of threats. You have to more depend on cloud antivirus rather than traditional antivirus so that your security protection will be totally cared for by the cloud server organization.

Tuesday, October 27, 2020

What is Computer Virus and Malware? What Are Their Types?

Computer viruses are small programs capable of causing great inconvenience to individuals, companies, and other institutions, after all, they can erase data, capture information, alter or impede the operation of the operating system, and so on. As if that were not enough, there are other similar software, such as  Trojan horses,  worms, hijackers,  spyware, and ransomware. In this text, you will learn a little about how these true "digital plagues" act and learn the basic differences between them.

Computer Virus and Malware

Before, What is Malware?

It is common for people to call viruses any program for malicious purposes. But, as the first paragraph of the text indicates, there are several types of "digital plagues", viruses being just one category of them.

Currently, a more heated term is used to generalize these programs: the name malware, a combination of the words malicious and software which means "malicious program". Therefore, malware is nothing more than a name created for when we need to refer to malicious software, be it a virus, worm, spyware, etc.

It is important to note that the word "computer" is used in this text in the broadest way, considering the various types of computing devices that exist: desktops, servers, smartphones, tablets, and so on.

It is also worth noting that malware is not limited to a single platform. There are those who think, for example, that there are only digital plagues for Windows, but that is not true. What happens is that the Microsoft family of operating systems is more popular and therefore more targeted. As there is no 100% secure software, malware can also be developed to attack any other platform, after all, there is always someone willing to discover and exploit its deficiencies.

What is a Computer Virus?

Illustrative image of virusesAs you already know, a  virus is a program with malicious purposes, capable of causing inconvenience with the most diverse types of actions: there are viruses that erase or alter users' files, which impair the functioning of the operating system by damaging or altering its functionality, which cause excess traffic on networks, among others.

Viruses, like any other type of malware, can be created in several ways. The first ones were developed in programming languages ​​like C and Assembly. Today, it is possible to even find tools that help in its creation.

How Do Viruses Act?

Viruses receive this name because they have propagation characteristics that resemble real viruses, that is, biological ones: when a virus contaminates a computer, in addition to carrying out the action for which it was programmed, it also tries to spread itself to other machines, just as they do biological viruses in the invading organisms.

In the past, viruses had a very limited range of action: they spread, for example, whenever a contaminated floppy disk was read on the computer. With the emergence of the internet, however, this situation has changed dramatically, for the worse.

This is because, with the internet, viruses can spread much faster and infect a much more significant number of computers. For this, they can explore several means, among them:

  • Security flaws ( bugs ): operating systems and other programs are not perfect software and can contain flaws. These, when discovered by people with malicious purposes, can be exploited by viruses, allowing contamination of the system, often without the user noticing;
  • E-mails: this is one of the most explored practices. The user receives messages that try to convince him to execute a file attached or present on a link. If the user does it without realizing that he is being deceived, his computer will surely be contaminated;
  • Downloads: the user can download a file from a specific website without realizing that it may be infected.

Viruses can also spread through a combination of means. For example, a person in an office can execute an e-mail attachment and thereby contaminate your computer. Then this same virus can try to exploit security holes in other computers on the network to infect them.

Other Types of Malware

As you already know, viruses are not the only malware that exists. The definition of what the pest is or does not depend essentially on its actions and ways of propagation. Here are the most common types:

Trojan Horse (Trojan)

Trojan horses  (or  Trojans ) are a type of malware that allow some way of remote access to the computer after infection. This type of pest can have other features, such as capturing user data to transmit it to another machine.

In order to be able to enter the computer, the Trojan horse usually passes for another program or file. The user can, for example, download it thinking that it is a tool for a specific purpose when, in fact, it is a trojan.

This type of malware is not designed to replicate itself. When this happens, it is usually a joint action with a virus.

Worm

The worms  (or maggots) can be interpreted as a more intelligent type of virus than others. The main difference is in the form of propagation: worms can spread to other computers quickly - either over the internet or via a local network - automatically.

It is explained: in order to act, the virus needs to have the "support" of the user. This occurs, for example, when a person downloads an infected attachment from an email and executes it. Worms, in turn, can infect the computer in a totally discrete way, exploiting flaws in applications or the operating system itself. Of course, a worm can also rely on a user's action to spread, as generally this type of malware is created to infect as many computers as possible, making any means that allow it to be acceptable.

Spyware

Spywares are programs that "spy" on users' activities or capture information about them. To infect a computer, spyware is often "embedded" in the software of questionable origin, often offered as freeware or shareware.

The captured data is later transmitted over the internet. This information can range from user browsing habits to passwords.

Keylogger

Keyloggers are small applications that can be embedded in viruses, spyware, or software of doubtful origin. Its function is to capture everything that is typed by the user. It is one of the ways used to capture passwords.

Hijacker

Hijackers are programs or scripts that "hijack" internet browsers. The main victims were the older versions of Internet Explorer. A hijacker can, for example, change the browser's home page and prevent the user from changing it, display advertisements in new windows, install toolbars, and prevent access to certain websites (pages of antivirus companies, for example). Fortunately, today's browsers have more security features, considerably limiting the action of this type of digital pest.

Rootkit

This is one of the most dangerous types of malware. They can be used for various purposes, such as capturing user data. So far, nothing new. What makes rootkits so threatening is their ability to hinder their detection by antivirus or other security software. In other words, rootkits are able to "camouflage" themselves in the system. For this, rootkit developers can make use of several advanced techniques, such as infiltrating malware into active processes in memory, for example.

In addition to being difficult to detect, rootkits are also difficult to remove. Fortunately, their complexity of development means that they are not very numerous.

Ransomware

Ransomware is a type of malware with a bolder "purpose": once active, the pest can block or limit (or allow its creator to do it remotely) access to files, folders, applications, entire storage units or even prevent the use of the operating system. To release these resources, the ransomware usually shows messages demanding payments. It is as if the computer has been hijacked.

To convince the user to pay the required amount, the message may contain threats or blackmail, saying, for example, that important data will be deleted or that private images of the person will be published on the internet if payment is not made.

Users who have their computer infected with ransomware should not give in to pressure and pay, not least because, not infrequently, nothing happens when this is done. Ideally, the person should use security software (endpoint security software) to try to remove the pest or, if unsuccessful, look for someone they can trust to do so.

Wednesday, October 21, 2020

Protect Google Drive Files From the Crypto-locker Virus | Antivirus Software

Ransomware affects cloud applications just as much as it affects local ones. This means that even if you got your cloud storage protected, it’s still not entirely safe. How come it is not safe? What will you do when you become a victim of ransomware? How do you protect your drive from it?

CryptoLocker viruses can easily compromise your files from simple actions, such as clicking on a link or downloading an email attachment. It spreads across all your data and starts to encrypt targeted files, leaving you with no choice but to “ransom” it. If you’ve automatically synced files to your Google Drive, then the uploaded data is now infected with ransomware.

Protect Google Drive Files From the Crypto-locker Virus

When this happens, restoring your files may not always be easy, as the only way is going back to the revision history in your drive and work on it one by one. There’s no point in time restoration and you need to manually go through all the file revisions. 

To ensure that this does not happen to you, here are a few simple steps:

  1. Secure a local antivirus software and do not rely on default computer antivirus.
  2. Have a cloud disaster-recovery software that allows restoring files to a point in time.

Is Google Vault supposed to save a copy of your files that you can restore? Yes, it still allows you to save a copy of your emails and files for archiving purposes, but it is not designed as a disaster-recovery application.

How can we help you? The top two steps are available for free when you sign up with any of our Cloud Concierge support services. We manage your daily IT tasks, like maintaining your G Suite accounts, setting up users, domain name registration, antivirus, and disaster recovery, so your business is not at risk with ransomware attacks.

From time to time, it has been seen that people who run into a bit of a pickle and they've got a CryptoLocker or Ransomware it's called, infected inside their Google Drive. It probably started on one of your computers and encrypted all of the files on your computer and you know what a CryptoLocker virus is, these are the kinds of things that encrypt all your files and then you get stuck. You have to pay somebody a Bitcoin to decrypt them, it doesn't always work, it's not always guaranteed. And in the meantime, you're basically left to ransom without access to any of your business files.

This is obviously a bad situation and if you're in that situation right now, fear not there is help and there are ways that we can get things resolved, but it's not always pretty. So, if you're in this situation right now, you've got your business lockdown. What's probably first happened is you've opened an email, you've clicked on a website or someone sent you a file, which has then infected your machine. So if you're on a Mac or a Windows machine, step number one is to actually isolate that and completely clean things up. So if you've still got your Google Drive connected to that computer, sign out right now, that will stop any more synchronization from happening if this fire still exists on your computer. You definitely want to work with an IT professional to actually clear that out. And most professionals recommend a clean slate wipe of the machine so there is absolutely no way that it can get back on there.

The next question is how do you go about restoring Google Drive? What do we do there? Unfortunately, the only way to get those files back is to work with the version history of Google Drive and one by one restore each one of those files. It's not a pretty process and you have to do it individually because there's just no other way to bring those back. Google doesn’t have a point in time restore in Google Drive, and so that means that each individual file you need to open the file, go to version history and restore it to another version. You may have tens, thousands, even hundreds of thousands of files that need to be restored, and this can be a pretty crazy time-consuming process. If that's not something that you'd like to do yourself, then we have a service where we can actually help make that happen for you.

Now I want to talk a little bit about prevention and what you should be doing to make sure that this doesn't happen to you. If I've just scared the crap out of you around how you may have your business brought to a standstill by being infected with Ransomware or CryptoLocker, you really need to pay attention to make sure that you take these critical steps so that you won't be affected by this happening. Step number one is to make sure that your computers are secure with local antivirus. Yes, computers are self-updating and they do most of the maintenance themselves these days and there is a basic antivirus built into Windows these days, but it's not always effective in stopping different variants of Ransomware or CryptoLocker. There are solutions that we recommend, and I'll cover some of those off later in this video, but you need to make sure that you have that antivirus installed on your machine so your local computer is protected. That is your first line of defense.

The second thing you need to do is you need to make sure you have cloud disaster recovery software and that backup disaster recovery software is going to allow you to restore your Google Drive to a point in time if anything ever goes wrong with that. Those two steps are the best way of defending yourself against Ransomware or CryptoLocker holding your files hostage. Now you might ask, Peter, well, what about Google Vault? Isn't Google Vault supposed to save all of my files and save a copy of them so if anything ever goes wrong in the business, then we've still got a copy inside of the vault? Well, Google Vault is still definitely useful for business owners because it allows you to have a copy of any email or any file that's going in or out of the business and keep that in a safe location inside the vault.

However, Google Vault will only allow you to still restore files one by one. It's not really designed to be a backup and recovery solution, it's more an eDiscovery solution, that's the technical term for it, and what that means is it's more for archiving and not necessarily for backup restoration and disaster recovery.

So, a quick recap of the two things that you need to do. Number one is to have cloud antivirus on your machine and that cloud antivirus should be specifically tailored to Ransomware or to stopping CryptoLocker viruses. Secondly, you should have a cloud disaster recovery software that will allow you to restore your Google Drive to a point in time. Now both of these are available for free when you sign up for one of our Cloud Concierge plans. Cloud Concierge is a small business G Suite support service which allows you to not only have us take care of day-to-day low-value tasks, like maintaining your G Suite account, setting up new users, archiving users when they leave your business, but we also manage everything that you need to take care of small business IT. That means any virus, that means domain name registration, that means the basics like having backup and disaster recovery so you are not at risk if something like this happens for your business.

The next step in securing your account from the risk of a CryptoLocker or Ransomware attack is to make sure that you actually have the correct security enabled in the different areas of your G Suite account. That means things like switching on two-factor authentication, locking down the admin panel, and being careful about which emails are allowed to be sent to your domain. Making sure your DNS settings are correct, like SPF, DKIM, and DMARC can also be additional layers of protection to make sure the emails being received by your business are legitimate and that your email isn't being used for spamming or for spreading any of these viruses as well.

Google has great spam filtering tools built-in, but some things can still make their way through, so it's always a better idea to use the Google web interface than actually using outlook on your local machine because that's another way that viruses can find their way into your local computers. If you're using Chrome OS, so a Chromebook or a Chromebox, well, they aren't susceptible to ransomware or any of these kinds of viruses at all, so that will completely eliminate the risk of you being attacked by ransomware or anything else that may lockdown and hold your files ransom.

Our support membership also includes an audit of all of your IT systems so we can make sure that you are not at risk of having your files disappeared or having to go through a hundred thousand files and restore them one by one. If right now you're in the position where your files have already been locked down well, our team can help with steps to make sure that it doesn't happen again and guide you through the process of restoring those files in the best possible way to make sure that they don't become re-encrypted, because that is something that is at risk if right now you're stuck.

Protect Yourself From Digital Hijacking by Ransomware

Ransomware is increasingly gaining prominence among cyber threats because it infiltrates and blocks (encrypts) victims' access to personal files - including documents, videos, and photos. This attack occurs in the background so that the Internet user does not realize what is happening until it is too late. What makes this attack a problem is that the encrypted files are stored on the user's computer, but are inaccessible.

Protect Yourself From Ransomware

When the attack takes place, the malware informs the user that files have been encrypted and, if they want to recover them, it is necessary to pay an exorbitant amount, usually with bitcoins (virtual currency). Most users who suffer the attack do not have knowledge and experience in technology. Therefore, this problem becomes greater, as they will have to find out what bitcoins are and how to obtain them if they choose to pay the ransom. 

In today's INFO Mail, learn step by step how to protect your data and prevent ransomware attacks with procedures that are recommended by Protegent360.

1 Always make regular backups of your files. It is highly recommended to create two backup copies, one in the cloud (in Dropbox or Google Drive services) and the other recorded on a physical media (external HD or on a USB stick). It is important to give the “plan B” device viewing or reading permissions so that no one will have the possibility to modify or delete the files.

2 Periodically check that the backup is working. There are times when a failure in an accidental way can damage files.

3 Cybercriminals distribute fake emails posing as online stores or banks to entice the user to click on a malicious link that distributes the malware. This method is known as phishing. To avoid it, there is a need to improve your spam settings and never open an attachment sent by an unknown email.

4 Do not trust anyone. Malicious links can be sent through social networks by friends, co-workers, or some gaming partners who have already been infected in one way or another by cybercriminals.

5 Enable options like “Show file extension” in the Windows platform settings. This will make it much easier to distinguish potentially malicious files. As Trojans are programs, the user should keep an eye on files with extensions like .EXE, .vbs, and.SCR.

6 You also need to be aware, as many types of files that look common and familiar can be threats. Cybercriminals can make use of several extensions to mask malware in the photo, video, or document files.

7 Regularly update your operating system, browser, and also other programs that are used in an essential way by each of the users. Criminals tend to exploit vulnerabilities in order to compromise systems and updates will correct existing gaps and flaws, increasing security.

8 If you notice a clandestine or unknown process on the machine, interrupt the internet connection. Hopefully, the ransomware didn't have time to erase the encryption key on the computer, which gives it a chance to restore files. However, it is worth mentioning that the newest versions of ransomware have managed to infect several machines even offline.

9 If the files are encrypted, do not pay the ransom unless instant access to some of your files is critical. Every payment only fuels this illegal business that will thrive the moment people are caught in this scam.

10 If the device is infected, the user should try to find out the name of the malware: it may be an old version and relatively simple to restore the files. Ransomware was less advanced years ago. Always use one advanced security software such as endpoint security software.

Friday, October 16, 2020

CryptoLocker - How to Recover Files or Decrypt

CryptoLocker is an application that you would not like to find on your pc. It is classified as a ransomware that is known to encrypt each and every essential file on your computer. This ransomware uses a Bitcoin payment system - ransoms get paid using it, making it rather difficult to prosecute the hackers behind it.

CryptoLocker : Recover Files or Decrypt

How CryptoLocker is Installed on the Computer

CryptoLocker uses social engineering techniques, to ensure that it is the user who executes it. Specifically, the victim receives an email, pretending to come from a logistics company, which has a ZIP with an access code attached.

When the user opens the zip by entering the access key that comes in the email, he thinks that there is a PDF file inside and when he opens the fake PDF, he executes the Trojan. CryptoLocker takes advantage of the Windows policy of hiding the extensions by default, in such a way that the user is tricked "thanks" to this Windows feature.

  • When the user (the victim) executes the Trojan, it installs itself as a resident on the computer:
  • Performs an imitation of itself on a path of the user profile (AppData, LocalAppData)
  • Create an entry in the autoruns to ensure execution on restart.
  • Run 2 processes. One is the primary and the other to protect the original process in front of closures.

Encryption of Files on Disk

The Trojan produces a symmetric key for each file to be encrypted and encrypts the contents of the file with AES using this key. It then encrypts the key with an asymmetric public-private key (RSA) algorithm with keys greater than 1024 bits in length and adds it to the encrypted file. This procedure guarantees that only the owner of the RSA private key will be able to obtain the key with which the file has been encrypted. In addition to this, as an overwrite operation is performed, the restoration of the file through any technique is prevented.

The first thing the Trojan does once it runs on the victim's computer is to get the public key (PK) from a C&C server. In order to connect to its server, the Trojan incorporates an algorithm known as Mersenne twister to produce domain names (DGA). This algorithm uses the date of the day as a seed and can produce up to a thousand different domains day after day, of a fixed length.

When the Trojan has successfully downloaded the PK, it saves it in the HKCUSoftwareCryptoLockerPublic Key registry and begins encrypting the files on each and every hard drive on the computer and on network paths where the user has permissions.

How Can I Avoid CryptoLocker?

The infection procedure it uses is transmission by e-mail through the use of social engineering. With what our tips are:

  • Exercise extreme caution against e-mails from unexpected senders, especially those that include attachments.
  • Disabling the Windows policy that hides known extensions will also help to recognize an attack of this kind.
  • Having a backup system for our critical files, which ensures that not only in the case of infection we can mitigate the damage caused by malware, but we also cover hardware problems beforehand.
  • If we do not have a backup and we have become infected, we do not advise paying the ransom. This should NEVER be the solution to recover our files since it transforms this malware into a profitable business model, which will drive the development and expansion of this kind of attack.
  • UPDATE A Power Shell script has been created
  • Install and update antivirus; do a regular scan

If you have been unlucky enough to be infected by the CryptoLocker Trojan, we can provide you with a solution to recover the encrypted files.

Cryptolocker is Ransomware

Ransomware is a threat that goes beyond simple damage to a computer, it attacks us where it hurts us most, encrypting files that are vital to us and requesting a "ransom" usually in bitcoins.

Bad News Cerber 3, the new version of ransomware that is impossible to decrypt, although at present we have begun to develop tools to be able to decrypt this terrible algorithm, it is still one of the most difficult to recover.

The 10 Most Dangerous Ransomware

Conficker: Worm that allows remote operations and malware download.

Sality: Virus that allows remote operations and downloads of malicious programs.

Locky: It mainly spreads via spam emails with a covert downloader.

Cutwail: Botnet used to send spam messages and take part in DDOS attacks

Zeus: Trojan used to steal banking information.

Chanitor: Install malicious payloads on infected machines.

Tinba: Banking Trojan.

Cryptowall: Ransomware that uses AES encryption and carries out C&C communication through TOR.

Blackhole: Exploit Kit that uses browser security flaws and plugins.

Nivdort: Bot used to steal passwords and modify settings.

Wednesday, September 23, 2020

Prevent 7 Malware Belong to Ransomware Families | Antivirus Software

7 Families of Ransomware


7 Ransomware and Prevention_Antivirus

1. SamSam

This crypto-ransomware encrypts user data with AES / RSA and then demands a ransom of 1 bitcoin or more to get the files back.

Original title: SamSam.

The file says samsam.exe.

Remote attackers use the JexBoss hacking tool to automatically detect vulnerable systems with outdated JBOSS versions and then launch an attack to remotely install SamSam ransomware on victims' computers. The malware supplied by SamSam is distributed to Windows systems by exploiting vulnerabilities in unpatched JBoss servers. Then it installs a web shell, identifies other systems connected to the network, and implements the SamSam ransomware to encrypt files on the network devices.

Source - https://id-ransomware.blogspot.com/2016/03/samsam.html

SamSam attacks started appearing in late 2015. In the past few years, they have seriously increased. For example, large enterprises such as the Colorado Department of Transportation, the city of Atlanta, and numerous medical institutions around the world have been affected by this ransomware attacks. SamSam is a great example of how the organizational prowess of attackers is just as important as their programming skills. SamSam does not indiscriminately look for a specific vulnerability, as some other variants of ransomware do, but rather works like a Ransomware-as-a-Service, carefully checking pre-selected targets for weaknesses, as well as applying holes that can be exploited to exploit vulnerabilities in the FTP and RDP protocols on the IIS server.

Initially, security researchers assumed SamSam was of Eastern European origin, as the vast majority of its attacks were directed against institutions in the United States. In late 2018, the United States Department of Justice indicted two Iranians who they claimed were behind the attacks. The indictment says the attacks resulted in more than $ 30 million in losses. But it is unclear exactly how much of this amount the authorities paid to the extortionists. At one point, the city government of Atlanta provided local media with screenshots of ransom messages that provided information on how to contact the attackers. This action led to the loss of a communication channel with the scammers, which may have prevented Atlanta from paying the ransom.

2. Ryuk

Ryuk is another variant of the ransomware virus that became widespread in 2018 and 2019. Its victims were organizations for which downtime is extremely critical. For example, the editors of the daily news, as well as the North Carolina water utility, which at the time was struggling with the aftermath of Hurricane Florence. The Los Angeles Times has written a detailed account of what happened when their own systems were infected with the virus. One of Ryuk's most insidious features is that it can disable Windows System Restore on infected computers, making it even more difficult to obtain encrypted data without paying a ransom. The requirements for capping were especially high, which corresponded to the level of the selected victims. The wave of attacks during the holiday season showed

Analysts believe Ryuk's source code is largely taken from Hermes, which was developed by the North Korean Lazarus Group. However, this does not mean that the Ryuk attacks themselves were carried out from North Korea. McAfee believes Ryuk was built on code purchased from a Russian-speaking vendor, in part because the ransomware virus does not support computers running Russian, Belarusian, or Ukrainian. But how exactly this Russian hacker (s) obtained the code from North Korea is unclear.

3. PureLocker

PureLocker is a new variant of ransomware that was the subject of this article jointly released by IBM and Intezer in November 2019. Running on Windows or Linux computers, PureLocker is a good example of a new wave of targeted malware. Rather than infiltrating computers with widespread phishing attacks, PureLocker appears to be tied to more_eggs backdoor malware, which has been used by several well-known cybercriminal gangs on more than one occasion. In other words, PureLocker is installed on computers that have already been compromised and are under some control of attackers. And instead of immediately starting to encrypt all the data it can access, it first runs a series of checks and identifies the most critical information. PureLocker does not show itself when run in sandboxes or malware research programs.

While IBM and Intezer did not disclose how widespread PureLocker infections are, they did show that most of them occurred on corporate production servers, which are obviously very important targets. Security researcher Intezer Michael Kajiloti believes that PureLocker is ransomware as a service, which is only available to criminal gangs that can pay in advance, as attacks using this software require participation and constant monitoring of highly qualified specialists.

4. Zeppelin

Zeppelin is a descendant of a family of viruses known as Vega or VegasLocker (another ransomware as a service) that has caused havoc among audit firms in Russia and Eastern Europe. Zeppelin has a number of new technical tricks, in particular, according to its configuration. But the main distinguishing feature of this ransomware from the Vega family is the ability to carry out targeted attacks. While Vega was distributed chaotically and mainly operated in a Russian-speaking environment, Zeppelin was not designed to run on computers in Russia, Ukraine, Belarus, or Kazakhstan. Zeppelin is distributed in several ways, including in the form of EXE, DLL, or PowerShell loader, but at least some of its attacks have been carried out using compromised managed security providers.

Zeppelin became widespread in November 2019, and a carefully curated list of its victims is further proof of its difference from Vega. The victims were healthcare organizations in North America and Europe. The ransom requirements were prepared to take into account the specifics of the area and specific to the infected organization. Security experts believe the move away from Vega's behavior is the result of a new and more ambitious actor, probably in Russia, using the codebase. Although the number of infections is not that high, experts believe what we have seen so far is confirmation of the possibility of more attacks using this virus.

5. REvil / Sodinokibi

Sodinokibi, also known as REvil, first appeared in April 2019. Like Zeppelin, Sodinokibi is a descendant of another virus family called GandCrab. He, too, had rules against enforcement in Russia and several neighboring countries, as well as in Syria, indicating his Russian origin. It had several distribution methods, including exploiting holes in Oracle WebLogic servers or Pulse Connect Secure VPN.

The spread of Sodinokibi again pointed to an ambitious team of creators, possibly also positioning the virus as ransomware as a service. Its spread caused problems in 22 small towns in Texas, but it gained notoriety when it shut down Travelex currency exchange in the UK on the eve of 2019, forcing operators to use calculators and notebooks instead of computers. The extortionists demanded a crazy $ 6 million ransom, although Travelex refuses to confirm or deny this.

6. Robinhood

In early May, the administration of the American city of Baltimore was confronted with ransomware that infected a number of municipal computers. Some of the city services were completely paralyzed. Soon a message appeared on the city's website stating that the authorities could only be contacted by phone. The culprit is a ransomware program called Robinhood. The impact of the virus was estimated at $ 18 million.

In particular, in Baltimore, they wrote about such problems as:

the opportunity to submit an appeal to the mayor's office was lost since officials lost access to e-mail;

transactions for the sale of real estate were suspended (about 1.5 thousand);

the possibility of online payment of fines for incorrect parking and traffic violations was lost, which led to a violation of the payment deadlines;

the databases of the system of payment of utilities and taxes on real estate were affected. As a result, it turned out to be impossible to write and pay bills, as well as to receive a receipt on the absence of debts from the persons selling houses and apartments.

Source - https://www.baltimoresun.com/maryland/baltimore-city/bs-md-ci-ransomware-email-20190529-story.html

7. LockerGoga

On March 18, 2019, one of the world's largest aluminum producers, the Norwegian company  Norsk Hydro,  was attacked by a ransomware. All factories were successfully isolated, the processes were transferred to manual control where possible (at the factories for extrusion of aluminum profiles, it was possible to establish only 50% efficiency). The investigation into the attack required the involvement of local authorities and law enforcement agencies (National Security Authority / NorCERT, Norwegian Police Security Service, National Criminal Investigation Service), as well as a number of commercial companies. The reconstruction of the infrastructure has not yet been completed and some production facilities (for example, extrusion of aluminum profiles) are still operating at half their capacity.

According to the Norwegian Computer Emergency Response Team (Norwegian Computer Emergency Response Team), this is ransomware called LockerGoga.

Total

All existing ransomware works in a similar way: they penetrate the attacked system by hacking through an unprotected RDP configuration using e-mail spam and malicious attachments, spoofing downloads, exploits, web injections, fake updates, repackaged and infected installers, encrypt files from certain extensions, which can supposedly contain useful information, and then require a ransom to the cybercriminals' crypto wallets in order to return the files. Vulnerabilities in software and network protocols were often exploited for attacks against large objects, as attackers were willing to spend more resources to achieve large benefits.

In general, we can say that at the present time there is a high probability of targeted attacks on large organizations that are capable of paying large ransoms to cybercriminals. That said, hackers don't always develop hacking solutions and malware on their own. Attackers choose areas of activity in which disruption of business processes leads to maximum losses (for example, transport, critical infrastructure, energy).

How to Prevent this Malware

To prevent ransomware attacks, there are the following guidelines:

  • Timely update of the software used;
  • Conducting briefings with personnel, forming their understanding of which program can be ransomware;
  • Maintaining a backup policy and protection of backups;
  • Use of antivirus software from major vendors, as well as a ban on changing antivirus policies by an ordinary user.

From all of the above, we can conclude that the threat of ransomware is more relevant today than ever. Attackers take advantage of the fact that information owners are concerned with both its integrity and availability and confidentiality. Now they are telling the victim not only “you will not get your data back until you provide the ransom”, but also “we plan to post your confidential information on the Internet or sell it on the darknet to those who offer a higher price”. This takes ransomware to the next level in the business model they use and is also the most important innovation in their standard behavior. This restructuring of the business model ushers in a new era of hyper-targeted and custom-designed ransomware that will reach new and dangerous depths.

Thursday, September 17, 2020

10 Simple Ways to Protect Your Computer

Fear of being infected by the plagues of the internet is increasingly common. The more technology develops, the more things are done by personal computers, such as paying bills, files with personal information. In this way, it also increases the interest of hackers to break into systems. What must be done to protect the machines is always a question. "If I already have antivirus, why was I still infected?" It is not a program, but a set of activities that allow the PC to be as defended as possible. See 10 practical tips to increase your security.


1)Antivirus

Antivirus may not be solely responsible for computer security, but it is certainly one of the main and first steps for those who want to protect their machine.

It is possible to find good antivirus software - the paid ones that exist in the market are superior to the free ones since they offer wide support. 

2)Firewall

The firewall works, in a way, together with the antivirus. Since he is responsible for expelling what is doubtful before he enters the machine. Once inside (when the firewall fails) you still have the antivirus that will do what it can to eliminate.

3)Antispyware

Antispyware is responsible for performing scans on the computer to try to eliminate spyware from the system - programs left by hackers on your computer to collect your information.

4)Updated Operating

system When the system is out of date it is much easier for hackers to infiltrate the PC. Always keep it updated. Updates can be configured to be performed automatically or even manually - whenever the user wants it.

5)Do Not Access Unknown Links

In e-mails, websites, chat programs, or practically everything you have access to on the internet, it may, at one time or another, have a malicious link. Care and precaution in this situation are essential and directly helps to protect the machine.

6)Do Not Send Personal Data by E-mail

With the password of your e-mail, the hacker has, like you, access to all e-mails that have already been sent or received. Try, as much as possible, not to send your data, such as a bank account password, for example.

7)Unlikely and Different Passwords on Each Website

Placing different passwords on websites is an extremely important step in protecting your accounts. Even if someone finds out your password and login for a particular website, you will not be able to access others with the same digits. If you were unable to protect one account, at least you will be able to preserve the others.

8)Beware of Downloads

Downloads are one of the main reasons for the insertion of pests in machines. Occasionally, when looking for a special program, the site may imply that the download will be made via a link that will lead to viruses. Even if all the steps have been done perfectly, still pay attention to any additional software that the program indicates during installation. Avoid accepting everything during the process. Even if you don't have any malware, additional ones can still decrease the effectiveness of your machine and make it more vulnerable.

9)“.exe” and “.scr” Files

A simple trick, but not always effective, to check if the link contains viruses is to hover over it (without clicking) and check - in the lower-left corner the browser status bar - where you will be taken if you click on it. If it is a ".exe" it means that it is an executable, that is, a program, probably, and not a website. So, the possibility of being malware is very great. The ".scr" usually refers to screen savers, which often confuse the user. Avoid, whenever possible, clicking on the links that appear with such extensions.

10)Trusted Sites

It is common, especially when using search engines, to be directed to unknown shopping sites, to watch videos, or other actions. Some users have enough malice to be able to operate on such sites without acquiring viruses, but for laymen to avoid such pages, at least in the beginning, it is essential.

Wednesday, September 16, 2020

How to Protect Your Data Backup From Ransomware?

Ransomware gets smarter by attacking backups to prevent recovery. To prevent this from happening, take a few simple steps.

Despite the recent decline in the number of attacks, ransomware still poses significant threats to businesses. Such attacks become more dangerous. In particular, ransomware authors understand that backups are significant defenses and modify their malware to track and destroy backups.

Reducing the Number of Ransomware

The company McAfee reported a decrease in the number of malware samples, and over the past year. According to the latest report, in the third quarter of 2019, the number of ransomware samples was less than half of the number of samples at the end of 2018, when their number reached about 2.3 million. According to Kaspersky Lab, 765,000 of its users were thrashed by malware that encrypted files over the past year, compared with more than five million that were attacked by crypto miners.

BitDefender Threat Research Director Bogdan Botezatu says the main reason for stopping ransomware attacks is because security companies are better protected against them. “There will always be new versions of ransomware, some of which will be more cultivated than others and some more difficult to catch, but we do not wish the ransomware to become much larger in scale,” he says. "At least not more than last year."

“For several years, ransomware has been the main threat, but the numbers have declined significantly,” said Adam Kujava, head of malware research at Malwarebytes. However, the ransomware that is there is evolving, he says. For example, malware authors take advantage of the latest exploits such as the ones leaked from the NSA. “We see them popping up in many relatives of malware,” he says. “When you use this kind of exploit, if you infect one system, you can infect a lot more using these exploits. You're creating a much bigger goal - that's a trend. "

Backup is the New Target of Ransomware

According to Kuzawa, the Ransomware now deletes all backups that come along the way. For example, a common ransomware tactic is to delete automatic copies of files that Windows creates. “So if you go to system recovery, you can't go back,” he said. "We've also seen how they access shared network drives."

Two recent examples of ransomware that have a sight on the backups, - Samsam and Ryuk. In November, the US Department of Justice indicted two Iranians to use malware SamSam to extort more than $ 30 million in more than 200 victims, including hospitals. The attackers maximized the damage by launching attacks outside business hours and "encrypting the victims' computer backups," the indictment says.

Most recently, Ryuk hit several major objectives, including the Los Angeles Times and the provider of cloud data Data Resolution. Ryuk includes a script that removes shadow volumes and backup files, according to security researchers at Check Point. “While this particular malware variant is not specifically designed for backups, it compromises simplified backup solutions that result in storing data on file shares,” says Brian Downey, senior director of product management at Continuum, based at Boston. a technology company that offers backup and recovery services.

The most common way is to use a Microsoft Windows feature called "Previous Versions," said Munir Hahad, head of threat research at Juniper Networks. This allows users to restore earlier versions of files. “Most ransomware variants delete shade copy snapshots,” he says, counting that most ransomware attacks will also attack backups on connected network drivers.

Ransomware Attack on Opportunistic, Untargeted Backups

However, this does not mean that all backups are vulnerable. According to David Lavinder, chief technology officer at Booz Allen Hamilton, when ransomware uses backups, these are not intentional targets. Depending on the ransomware, it usually works by scanning the system looking for certain types of files. “If it locates the extension of the backup file, it will encrypt it for sure,” he says.

Ransomware is also trying to spread by infecting as many other systems as possible, he says. This is a type of worm, as is the case with WannaCry, where more activity is expected to be seen in the future. “We don't desire to see deliberate targeting of backups, but we do expect to see more attentive efforts,” he says.

You can protect your backups and systems from these new ransomware tactics by taking a few basic protection.

Supplement Windows Backups With Extra Copies and Third-party Tools

To protect itself from ransomware that deletes or encrypts local file backups, Kujawa suggests using additional backups, third-party utilities, or other tools that are not part of the default Windows configuration.

Isolate Backups

The more barriers live between the infected system and its backups, the more difficult it will be for the ransomware to get to it. One common mistake people make is that users use the same authentication method for their backups as elsewhere, according to Landon Lewis, CEO of Pondurance, a cybersecurity consulting firm in Indianapolis. “If your user's account is compromised, the first thing an attacker wants to do is to elevate their privileges,” he said.

Store Multiple Copies in Multiple Locations

Lewis recommends that companies keep three different copies of their important files using at least two different backup methods, and at least one of them should be in a different location. Cloud backups provide an easy-to-use off-site backup option, he says. “It is very inexpensive to block online storage. It's hard to argue why someone wouldn't use it as an additional backup method. And if you use a different authentication system, that's even better. " Addition to cloud storage companies should rely on cloud antivirus for any potential vulnerability.

November 27 is Black Friday and November 30 is Cyber ​​Monday

One of the strongest sales campaigns in shops and online sales recently established in Spain is Black Friday and Cyber ​​Monday. A tradition...