Ransomware Attacks Step Up their Game and Now Look for NAS Devices

Stu Sjouwerman | Jan 7, 2020

ransomware-screen-skull-1It used to be that ransomware just looked for office files. Then backups became a secondary victim. New data from Kaspersky shows NAS devices are being added as targets.

The success of a ransomware attack depends solely on whether the victim can’t possibly recover. It’s the very reason why ransomware started using tactics like looking for the 40-ish backup filetypes, as well as using an attack loop (where the ransomware infects a machine but lies dormant for months to ensure multiple backups include the ransomware).

But attackers are now thinking in terms of how to cross-pollinate their code with cybercriminals well-versed in taking advantage of known vulnerabilities. According to researchers at Kaspersky, the goal is to attack the very NAS devices hosting an organization’s backups. If you were a ransomware author, it’s a smart move; your goal is to render the victim company unable to respond in any other way than to just pay the ransom.

It’s generally accepted that ransomware finds its way into an organization in one of two ways these days – either via an exposed and unsecure RDP connection, or via email. Addressing RDP is easy; don’t allow RDP via the Internet. But email is a larger challenge.

Despite best efforts, even organizations with a layered preventative security strategy in place still find that ransomware emails make their way all the way to the unsuspecting user. This last line of defense needs to be shored up with Security Awareness Training so that the user themselves becomes part of the organization’s defense, spotting the potentially malicious email and not engaging with its contents or attachments.

Test Your Network’s Defenses with our Free Ransomware Simulator

When employees bypass guidance and fall for social engineering, your network security is the last line of defense. Run our 100% harmless RanSim tool on Windows 10+ workstations to safely simulate 25 ransomware and cryptomining infection scenarios, pinpoint technical vulnerabilities, and get your results in minutes.

Launch Your Free Ransomware Simulation

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.