CyberheistNews Vol 6 #38 |
[ALERT] The FBI Warns That Ransomware Attacks Are Getting More Dangerous And Expensive |
In an alert published this week, the U.S. Federal Bureau of Investigation warned that recent ransomware variants have targeted and compromised vulnerable business servers (rather than individual users) and multiplying the number of infected servers and devices on a network.
Powerful Ammo For Budget
This FBI alert is powerful ammo for budget. It explains one more time what ransomware is, how fast it mutates, and that infections are skyrocketing. They explain what the potential losses are -- service disruptions, financial loss, and in some cases, permanent loss of valuable data -- and that it is challenging for the FBI to keep pace. I strongly suggest you send this link to the decision-making team that holds the infosec purse strings: https://www.ic3.gov/media/2016/160915.aspx
Knowing that the FBI only have about 800 cyber agents, including just 600 agents who conduct investigations, the agency doesn’t have the ability to address every attack, and must triage the most significant ones. You are on your own if the damage is less than a few hundred thousand dollars.
FBI: "Tell Us How Much Ransom You Have Paid"
The FBI is requesting victims reach out to their local FBI office and/or file a complaint with the Internet Crime Complaint Center, at www.IC3.gov, with the following ransomware infection details (as applicable):
- Date of Infection
- Ransomware Variant (identified on the ransom page or by the encrypted file extension)
- Victim Company Information (industry type, business size, etc.)
- How the Infection Occurred (e-mail, browsing websites, etc.)
- Requested Ransom Amount
- Bad Actor’s Bitcoin Wallet Address (may be listed on the ransom page)
- Ransom Amount Paid (if any)
- Overall Losses Associated with a Ransomware Infection (including the ransom amount)
- Victim Impact Statement
The FBI does not support paying a ransom to the adversary. Paying a ransom does not guarantee the victim will regain access to their data; in fact, some individuals or organizations are never provided with decryption keys after paying a ransom. Paying a ransom emboldens the adversary to target other victims for profit, and could provide incentive for other criminals to engage in similar illicit activities for financial gain. While the FBI does not support paying a ransom, it recognizes executives, when faced with inoperability issues, will evaluate all options to protect their shareholders, employees, and customers.
What To Do About It
"The FBI recommends users consider implementing the following prevention and continuity measures to lessen the risk of a successful ransomware attack:
- Regularly back up data and verify the integrity of those backups. Backups are critical in ransomware incidents; if you are infected, backups may be the best way to recover your critical data.
- Secure your backups. Ensure backups are not connected to the computers and networks they are backing up. Examples might include securing backups in the cloud or physically storing them offline. It should be noted, some instances of ransomware have the capability to lock cloud-based backups when systems continuously back up in real-time, also known as persistent synchronization.
- Scrutinize links contained in e-mails and do not open attachments included in unsolicited e-mails.
- Only download software – especially no charge software – from sites you know and trust. When possible, verify the integrity of the software through a digital signature prior to execution.
- Ensure application patches for the operating system, software, and firmware are up to date, including Adobe Flash, Java, Web browsers, etc.
- Ensure anti-virus and anti-malware solutions are set to automatically update and regular scans are conducted.
- Disable macro scripts from files transmitted via e-mail. Consider using Office Viewer software to open Microsoft Office files transmitted via e-mail instead of full Office Suite applications.
- Implement software restrictions or other controls to prevent the execution of programs in common ransomware locations, such as temporary folders supporting popular Internet browsers, or compression/decompression programs, including those located in the AppData/LocalAppData folder.
The FBI suggests additional considerations for businesses and note their first bullet where we can help you:
- Focus on awareness and training. Because end users are often targeted, employees should be made aware of the threat of ransomware, how it is delivered, and trained on information security principles and techniques.
- Patch all endpoint device operating systems, software, and firmware as vulnerabilities are discovered. This precaution can be made easier through a centralized patch management system.
- Manage the use of privileged accounts by implementing the principle of least privilege. No users should be assigned administrative access unless absolutely needed. Those with a need for administrator accounts should only use them when necessary; they should operate with standard user accounts at all other times.
- Configure access controls with least privilege in mind. If a user only needs to read specific files, he or she should not have write access to those files, directories, or shares.
- Use virtualized environments to execute operating system environments or specific programs.
- Categorize data based on organizational value, and implement physical/logical separation of networks and data for different organizational units. For example, sensitive research or business data should not reside on the same server and/or network segment as an organization’s e-mail environment.
- Require user interaction for end user applications communicating with Web sites uncategorized by the network proxy or firewall. Examples include requiring users to type in information or enter a password when the system communicates with an uncategorized Web site.
- Implement application whitelisting. Only allow systems to execute programs known and permitted by security policy."
One thing missing from the FBI list is email server configuration. We all know that your users are the weak link in your IT security, and one of the very successful tactics the bad guys use is spoofed email addresses. When an email seems to come from a person they know, or has authority, the chance they fall for an attack increases dramatically.
No-Charge Domain Spoof Test
Can hackers spoof an email address of your own domain?
Are you aware that one of the first things hackers try is to see if they can spoof the email address of your CEO? If they are able to commit "CEO Fraud", penetrating your network is like taking candy from a baby.
Would you like to know if hackers can spoof your domain? KnowBe4 can help you find out if this is the case with our complimentary Domain Spoof Test. It's quick, easy and often a shocking discovery. Find out now if your email server is configured correctly, 82% are not!
Get Started Here: https://www.knowbe4.com/domain-spoof-test/
|
New Vicious And Highly Targeted Ransomware Attacks Made Public |
Here’s an example of a highly targeted ransomware attack, with bad guys using a phony Bank of Montreal (BMO) template to social engineer possible victims into clicking on a malicious attachment.
Chester Wisnewski, a Vancouver-based senior security adviser at Sophos Inc, said: "Literally as I got on the plane I got what looked like a BMO phish, and in fact it was ransomware. It was amazing how well crafted it was because the Web site booby-trapped with the exploit is literally a carbon copy of the BMO online login landing page.”
This is a good example which illustrates a SophosLabs blog post a bit earlier this year pointing to a growing trend of cybercriminals to target and even filter out specific countries when designing ransomware and other malicious cyberattacks.
Based on data collected from Sophos endpoints, firewalls and gateways, it shows attackers are now crafting customized phishing attacks using regional languages, ripped off logos, and/or pretending to be tax and law enforcement agencies. Their tactics include phony shipping notices, refunds, speeding tickets and electricity bills.
Looking for bad grammar or typos to tip you off? Nope, it's all flawless.
Wisnewski said: "Patching and updates are crucial. The latest versions of Microsoft Office are better at stopping document malware, giving admins the ability to disable macros in documents that came from the Internet. Similarly Windows 10 is more secure than Win 7, and using a sandbox and Web filtering are also useful," he added.
The report also said researchers have found different ransomware strains target specific locations. For example, versions of CryptoWall predominantly hit victims in the U.S., U.K., Canada, Australia, Germany and France. TorrentLocker has attacked primarily the U.K., Italy, Australia and Spain, while TeslaCrypt honed in on the U.K., U.S., Canada, Singapore and Thailand.
And here is the Latest Vicious Ransomware Strain
SecurityAffairs just published a new discovery you need to know about. A Brazilian Infosec research group, Morphus Labs, just discovered a new Full Disk Encryption (FDE) ransomware strain this week, dubbed “Mamba”, a snake with a paralyzing poison.
Mamba, just like Petya, uses a disk-level encryption strategy instead of the conventional file-based one. It simply prevents the OS from booting. Imagine your file servers being hit with this one -- full-disk encryption seems to become a ransomware trend. More: https://blog.knowbe4.com/meet-mamba-new-full-disk-encryption-ransomware
|
I Have An Invitation To Join A New Exciting Online Community! |
KnowBe4 has been running the HackBusters site for a few years now, providing you with trending IT security news. We have expanded it with a new exciting online community! I'd like to invite you to be one of the first to join us at: https://discuss.hackbusters.com.
The forum is divided into four main topics or categories:
- Social Engineering
- Ransomware
- Phishing
- Security Awareness Training
You are welcome to share your thoughts, opinions and ideas in these forums. We look forward to seeing you on our exciting new online community soon! Again, you are invited to be one of the first to join us at: https://discuss.hackbusters.com.
|
Warm Regards, Stu Sjouwerman |
|
|
|