Skip to main content

Ransomware: Prepare for hackers launching even more destructive malware attacks


The 'wiper' ransomware used in state-backed attacks like NotPetya is gaining round among cyber criminals, warns EU law enforcement annual cybercrime report.
The threat from ransomware continues to grow and it's possible that the file-encrypting malware attacks could become far more destructive as cyber criminals evolve and change their tactics.
European law enforcement agency Europol's annual cybercrime report – the Internet Organised Crime Threat Assessment (IOCTA) – lists ransomware as the most widespread and financially damaging cyber attack, despite a decline in the number of ransomware incidents.
However, cyber criminals are becoming more efficient, picking and choosing their targets with the aim of causing the highest amount of damage possible to organisations in order to demand much higher ransomware. To emphasise this – although without providing specific examples - the report details how in some cases, the ransom demanded is in excess over one million Euros.
But while ransomware in its current state is predominantly a means of making money for cyber criminals, the Europol report warns there's a risk of cyber criminals deploying ransomware attacks as a means of pure sabotage, something private companies are growing fearful of.
The NotPetya attacks of 2017 showed how much damage can be done by a destructive cyberattack of this kind: in some cases it led to large companies having to almost entirely restore their network from scratch, suffering large amounts of downtime and large financial costs as a result.
NotPetya looked like ransomware but the group behind it had no interest in receiving ransom payments, the motivation behind the attack was pure destruction. The target for this destruction was Ukraine, but the attack got out of control and spread around the world.
This kind of attack has predominantly been associated with nation-states – the Russian military has been accused of being behind NotPetya - however, the report warns that cyber criminals are increasingly incorporating wiper-style attacks as part of their campaigns.
A form of this ransomware attack emerged earlier this year. Named GermanWiper the ransomware hit organisations across Germany with attacks which didn't encrypt files, but rewrote the files to destroy them.
Ultimately, it meant that even if a user paid the ransom, they wouldn't get their files back at all – unless they had offline back-ups. 
Ransomware itself may have changed but the methods for distributing it have stayed the same over the last year: phishing emails and remote desktop protocols (RDPs) are the primary infection vectors of the malware.
Often, the attackers pushing ransomware are doing so with the aid of known vulnerabilities for which vendors have already issued security updates. Because of this, Europol stresses the importance of patching, especially when it comes to critical vulnerabilities.
The report notes that almost one million devices still haven't been patched against the powerful BlueKeep vulnerability, leaving networks open to attacks using the exploit.
The message from Europol is clear – ransomware and other cyber attacks won't be disappearing any time soon, especially if cyber criminals are able to take advantage of known vulnerabilities and old attacks.
"This year's IOCTA demonstrates that while we must look ahead to anticipate what challenges new technologies, legislation, and criminal innovation may bring, we must not forget to look behind us," said Catherine De Bolle, executive director of Europol.
"New threats continue to emerge from vulnerabilities in established processes and technologies. Moreover, the longevity of cyber threats is clear, as many long-standing and established modi operandi persist, despite our best efforts. Some threats of yesterday remain relevant today and will continue to challenge us tomorrow," she added.
There is one threat which appears to have almost dropped off the radar compared with its position in last year's report: cryptomining. The 2018 IOCTA warned about the rise of cryptocurrency mining malware, even suggesting that it "may overtake ransomware as a future threat".
However, while cryptomining attacks still do occur the number of attacks has declined – especially since the closure of Coinhive in March this year. Now, aside from exceptional cases, cryptomining is described as "a low-priority threat for EU law enforcement" moving forward as other current and future threats are combated.
"The global impact of huge cybersecurity events has taken the threat from cybercrime to another level. At Europol, we see that key tools must be developed to keep cybercriminals at bay. This is all the more important, considering that other crime areas are becoming increasingly cyber-facilitated," said De Bolle.

Comments

Popular posts from this blog

Bogus Android Clubhouse App Drops Credential-Swiping Malware

The malicious app spreads the BlackRock malware, which steals credentials from 458 services — including Twitter, WhatsApp, Facebook and Amazon. Researchers are warning of a fake version of the popular audio chat app Clubhouse, which delivers malware that steals login credentials for more than 450 apps. Clubhouse has burst on the social media scene over the past few months, gaining hype through its audio-chat rooms where participants can discuss anything from politics to relationships. Despite being invite-only, and only being around for a year, the app is closing in on 13 million downloads . However, as of now the app is only available on Apple’s App Store mobile application marketplace — there’s no Android version yet (though plans are in the works to develop one). Cybercriminals are swooping in on Android users looking to download Clubhouse by creating their own fake Android version of the app. To add a legitimacy to the scam, the fake app is delivered from a website purporting to b...

Razer has created a concept N95 mask with RGB and voice projection

  Razer claims to have made the world’s smartest mask: its new reusable N95 respirator called Project Hazel. It’s a concept design with a glossy outside shell made of waterproof and scratch-resistant recycled plastic, which is transparent to allow for lip-reading and seeing facial cues when you chat with people. Currently, there isn’t a price or release date attached. Razer refers to Project Hazel as a surgical N95, but it hasn’t yet earned any of the necessary approvals and certifications from the Food and Drug Administration, the Centers for Disease Control and Prevention, or Occupational Safety and Health Administration. In a statement to The Verge , Razer said it is working with a team of medical experts and scientists who are helping to develop the mask. The main features of this mask lie within its two circular zones that flank your mouth. They’re used for ventilation, giving the device an almost futuristic gas mask look. Razer claims Project Hazel will use active disc-type v...

Hackers Compromise Mimecast Certificate For Microsoft Authentication

A sophisticated threat actor compromised a Mimecast certificate used to authenticate several of the company’s products to Microsoft 365 Exchange Web Services, Mimecast disclosed Tuesday. The Lexington, Mass.-based email security vendor said the certificate used to authenticate its Sync and Recover, Continuity Monitor and Internal Email Protect (IEP) products to Microsoft 365 has been compromised. Mimecast said it was recently informed of the compromise by Microsoft. Mimecast’s stock is down $2.40 per share (4.67 percent) to $49 per share in pre-market trading Tuesday, which is the lowest the company’s stock has traded since Dec. 15. Mimecast declined to answer questions about whether the compromise of its certificate was carried out by the same threat actor who for months injected malicious code into the SolarWinds Orion network monitoring tool. Approximately 10 percent of Mimecast’s customers use the compromised connection, according to the company. Of those that do, Mimecast said cu...