Kidnapping 2.0 - Ransomware on the Rise
Every week we read about new encryption trojans such as Locky or TeslaCrypt. This type of malware, also known as cryptotrojans or ransomware, fundamentally follows the rules of a classic kidnapping. However, in the digital age, data is kidnapped instead of people. Instead of locking victims in a dark cellar, the data is encrypted on the spot and thus withdrawn from the access of the extortion victims. Communication is no longer via letters composed of newspaper clippings, but via the anonymous TOR network. The ransom is finally not thrown from a bridge in a plastic bag, but can be conveniently paid with the digital currency Bitcoin.
Since when have encryption trojans existed?
The Federal Office for Information Security (BSI) reports the first major occurrences of encryption trojans in 2010. Since September 2015, however, a first major wave of encryption trojans could be observed, which since the beginning of 2016 has developed a completely new dynamic with a tenfold increase in the number of trojans discovered compared to October 2015. So far, ransom demands have mostly remained in the triple-digit range, as the malware is still distributed indiscriminately to as wide a mass as possible. However, the first campaigns can already be observed that are specifically targeted at certain industries and professional groups such as lawyers. As a result, ransom demands will increase significantly in the future, as they can be more precisely adapted to the willingness to pay of the "customers".
How can one get infected?
Most infections with extortion trojans currently still take place through spam email campaigns. In this process, for example, a real invoice email from a real company, including signature and email sender details, is forged. In the attachment of these emails, the trojan is then hidden, for example in an Office document. Other ways of distribution in the past were so-called drive-by infections. In this case, the malware is loaded and installed by visiting a compromised website. This is done by exploiting security vulnerabilities in browsers and browser plug-ins. Websites are not only used to spread encryption trojans, however. Security vulnerabilities of websites have already been exploited to encrypt the contents of the web server. Most recently, cases of unprotected remote maintenance access have become known, via which encryption trojans were spread.
What can an encryption trojan do?
Said cryptotrojans encrypt files on infected systems and thus make them unusable for the user. If a PC is infected by a trojan, not only the files on the hard disk, but also files on connected network drives or cloud storage can be encrypted. As a result, an entire company can be brought to a standstill quickly by a single infected computer. An infection is also fatal if a backup solution exists, but it is permanently connected to the PC and thus also made unusable by a ransomware infection. In addition to the company's own damage through lost data and the reputational damage if the incident becomes known, possible consequential damage for customers and partners must also be considered if service promises can no longer be kept or important customer documents are affected.
A well-known example of the dramatic effects of an organization's infection by an encryption trojan was the Lukas Hospital in Neuss in February of this year. There, important operations could no longer be carried out due to the complete failure of the IT systems as a result of the infection.
The manufacturers of the malware are currently continuously developing their trojans, so that new distribution paths and extortion strategies are constantly emerging. The currently most widespread encryption trojans are: Locky, TeslaCrypt, Cryptolocker, Cryptowall, CryptXXX, Jigsaw, CryptoHitman, Petya, TorrentLocker, Cryptodef, PowerWare, and KeRanger.
How can one protect themselves from a ransomware infection?
In the further articles of this series, we will discuss
- what should be done in the event of an acute ransomware infection,
- how to protect oneself preventively against encryption trojans,
- what a trojan such as Locky exactly does when it has infected a computer and
- how to deal with the demand to transfer Bitcoins.
An overview of all articles already published can be found on our topic page Ransomware .
An infection with an encryption trojan is usually a sign of general deficits in the data protection and IT security management of an organization. Therefore, we help you not only with a quick reaction in an emergency , but also in designing your IT processes securely and operating effective crisis prevention.
On 21.05.2016 in the category Data Security published.
