100 New Ransomware Families
The world in 2016 sees a rapid rise of ransomware attacks that are increasingly targeting specific businesses and entire industries. A report by David Balaban for privacy-pc.com shows that ransomware attacks have occurred virtually on a daily basis in the past year. Moreover, ransomware groups develop attack techniques that use advanced methods applied in cyberespionage attacks. These attacks target specific industries or large organizations that use outdated cyber defense or are open for attacks.
Ransomware Attacks More Industries
According to a Symantec report, called Ransomware and Business, the services industry is most exposed to ransomware with 38 percent of organizational infections. Other industries that experience heavy ransomware attacks are manufacturing with 17 percent of infections followed by finance, insurance and real Estate and public administration that both account for 10 percent of ransomware infections. Nearly one third of all ransomware infections, 28 percent, occurred in the US. Other most attacked countries include Canada, Australia, India, Japan, Italy, the UK, Germany, the Netherlands, and Malaysia.
Another alarming trend is that the average ransom request now stands at $679 more than two-fold the $294 ransom demand at the end of 2015, according to the report. In 2016, some 100 new ransomware families are discovered while some ransomware groups provide ransomware-as-a-service, which greatly increases the availability of advanced attack techniques for virtually every cybercriminal.
Crypto-ransomware Is Most Common
A new trend shows that the shift towards crypto-ransomware continues and in 2016 only one variant of ransomware was not crypto-ransomware. According, to Symantec 80 percent of all ransomware was crypto-ransomware. A decade ago, the most widespread variants of ransomware were misleading applications such as fake antivirus programs that were used by the attackers to cheat the users to pay a fee for fixing non-existing infections or Malware.
At a later stage, the locker type of malware replaces fake antivirus apps but is now itself being replaced by crypto-ransomware. Crypto-ransomware uses encryption techniques that are unbreakable in practice and that is why it is considered the most effective type of ransomware.
A report by Gartner also finds that crypto-ransomware is the most used method to demand ransom from organizations worldwide. Since the crypto-ransomware encrypts is attacking files and data storage devices using unbreakable encryption methods, the best passive defense is to back up data on a regular basis and apply all available security patches on time.
Protection Is Mandatory
Endpoint protection platforms can provide acceptable level of security and protection and Gartner states that no single vendor leads in all functional areas. Therefore, selecting a platform that provides journaling and file backup capabilities is a good option for any business that wants to protect itself from encrypting malware. Another advanced method for protection includes malware sandboxing where any suspicious code is first executed in virtual environment to determine whether this is a malicious programming code. Any business should also take into account a vendor’s strategy for protecting workloads in public cloud Infrastructure-as-a-Service as well as what public cloud IaaS providers are supported by the vendor of the endpoint protection platform.
Furthermore, protection should include methods to detect attacks by malware where programming languages like JavaScript, PHP, Powershell, or Python are used. Attackers used these languages to create several new ransomware families in 2016 and each protection should envisage methods to detect such malicious code.
Ransomware is becoming more sophisticated rapidly and no business should take lightly the danger of ransomware attacks. With crypto-ransomware becoming so widespread, each organization should apply all required security measures and select a feasible endpoint protection platform to defend its data.
By Kiril V Kirilov