[Heads-up] Unusual Ransomware Strain Encrypts Cloud Email Real-time

Stu Sjouwerman | Jan 13, 2018

RansomCloud.pngOK, here is something unusual and really scary.

KnowBe4's Chief Hacking Officer Kevin Mitnick called me with some chilling news. A white hat hacker friend of his developed a working "ransomcloud" strain, which encrypts cloud email accounts like Office 365 in real-time . My first thought was: "Holy $#!+". 

I asked him: "Can you show it to me?", and Kevin sent me a video demo, you can see it below. Lucky for us, this type of ransomware strain is not in the wild at the moment.

When I started looking into it, the proof of concept that he mentions in the video has been around for a while, but it's on the horizon, because if a white hat can do this, so can a black hat. I am wondering why they haven't already, because it's not all that hard to do.

This strain uses a smart social engineering tactic to trick the user to give the bad guys access to their cloud email account, with the ruse of a "new Microsoft anti-spam service".

Once your employee clicks "accept" to use this service,  it's game over: all email and attachments are encrypted real-time!  The ransomcloud attack will work for any cloud email provider that allows an application giving control over the email via oauth. With Google it will work if you get the app past their verification process. Outlook365 doesn't verify the app at this point so its much easier. 

See it for realz here (video is just 5 minutes) and shiver:

 

What Kevin recommends at the end of this video: "Stop, Look and Think before you click on any link in an email that could potentially give the bad guys access to your data." is now more true than ever.  

If you are a KnowBe4 customer and use either Gmail or O365, I recommend sending the special phishing template we created for this called "Microsoft AntiSpamPro Ransomcloud" and it lives in the "Phishing for Sensitive Information" category.

What Percentage Of Your Users Would Click On That Link?

Organizations are moving millions of users to O365. However, this video proves that being in the cloud does not automatically mean you are secure.  The Phish-prone percentage of your users is your number one vulnerability, as they remain to be the weakest link in your IT security, cloud or not.

Here is a way to get your users' phish-prone percentage baseline at no cost

KnowBe4's free Phishing Security Test allows you to choose which environment you want to test:

KnowBe4_Free_Phishing_Security_Test.png

If you choose the O365 option, your user will be send this Phishing Security Test (PST) email after you upload the email addresses and whitelist our domain:

O365_Phishing_Security_Test-1.png

As you just saw, cyber-attacks are changing all the time. We help you step your employees throuigh new-school security awareness training to better manage the urgent IT security problems of social engineering, spear-phishing and ransomware attacks. Take the first step now. No need to talk to anyone.

Find out what percentage of your employees are Phish-prone with our free Phishing Security Test (PST). If you don't do it yourself, the bad guys will. 

Get Your Free PST Now

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer

Topics: Ransomware

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.