0
  • Home
  • Editorials
  • Press Releases (multiple industries)
  • Events
  • B2B PR
  • Podcast
  • Advertise
  • Events/Conferences
  • Contact our team
  • PR Distribution
PICANTE Today - Hot News Today PICANTE Today - Hot News Today
PICANTE Today - Hot News Today PICANTE Today - Hot News Today
PICANTE Today - Hot News Today PICANTE Today - Hot News Today
  • Home
  • Editorials
  • Press Releases (multiple industries)
  • Events
  • B2B PR
  • Podcast
PICANTE Today - Hot News Today PICANTE Today - Hot News Today
  • Home
  • Editorials
  • Press Releases (multiple industries)
  • Events
  • B2B PR
  • Podcast
Archives

Media Alert: Sophos shows how the most prevalent and persistent ransomware families attack victims

Posted by GlobeNewswire November 14, 2019
Share
READ NEXT
BlockApps and Tech Mahindra partner to accelerate adoption of blockchain business networks

Playbook for defenders covers attack tools and techniques used by 11 major ransomware families including WannaCry, SamSam, RobbinHood, Ryuk, MegaCortex, and more

      Automated, Active Attack-style was the Most Common Approach Seen Among Top Ransomware Families in the Report 

OXFORD, United Kingdom , Nov. 14, 2019 (GLOBE NEWSWIRE) — Sophos (LSE: SOPH), a global leader in next-generation cybersecurity, has published How Ransomware Attacks, a playbook for defenders that explains how ransomware variants attack and impact victims. The playbook complements the 2020 Threat Report released on Nov. 4, and features a detailed analysis of 11 of the most prevalent and persistent ransomware families, including Ryuk, BitPaymer and MegaCortex.

The research by SophosLabs highlights how ransomware tries to slip unnoticed past security controls by abusing trusted and legitimate processes, and then harnesses internal systems to encrypt the maximum number of files and disable backup and recovery processes before an IT security team catches up.

The tools and techniques covered by the playbook include:

The main modes of distribution for the major ransomware families. Ransomware is typically distributed in one of three ways: as a cryptoworm, which replicates itself rapidly to other computers for maximum impact (for example, WannaCry); as ransomware-as-a-service (RaaS), sold on the dark web as a distribution kit (for example, Sodinokibi); or by means of an automated active adversary attack, where attackers manually deploy the ransomware following an automated scan of networks for systems with weak protection. This automated, active attack style was the most common approach seen among the top families listed in the report.
       
Cryptographic code signing ransomware with a bought or stolen legitimate digital certificate in an attempt to convince some security software the code is trustworthy and doesn’t need analysis. 
       
Privilege escalation using readily available exploits, like EternalBlue, to elevate access privileges. This allows the attacker to install programs such as remote access tools (RATs), and to view, change or delete data, create new accounts with full user rights, and disable security software.

Lateral movement and hunting across the network for file and backup servers while staying under the radar in order to unleash the full impact of the ransomware attack. Within an hour, attackers can create a script to copy and execute the ransomware on networked endpoints and servers. In order to speed up the attack, the ransomware might prioritize data on remote/shared drives, target smaller document sizes first, and run multiple encryption processes at the same time.

Remote attacks. The file servers themselves are often not infected with the ransomware. Instead, the threat typically runs on one or more compromised endpoints, abusing a privileged user account to remotely attack documents, sometimes via the Remote Desktop Protocol (RDP) or targeting remote monitoring and management (RMM) solutions typically used by managed service providers (MSP) to manage customers’ IT infrastructure and/or end-user systems.

File encryption and renaming. There are a number of different methods for file encryption, including simply overwriting the document, but most are accompanied by either the deletion of the backup or original copy to hinder the recovery process.
             
The playbook explains how these and other tools and techniques are implemented by 11 ransomware families: WannaCry, GandCrab, SamSam, Dharma, BitPaymer, Ryuk, LockerGoga, MegaCortex, RobbinHood, Matrix and Sodinokibi.

“The creators of ransomware have a pretty good grasp of how security software works and adapt their attacks accordingly. Everything is designed to avoid detection while the malware encrypts as many documents as possible as quickly as possible and makes it hard, if not impossible, to recover the data. In some cases, the main body of the attack takes place at night when the IT team is at home asleep. By the time the victim spots what’s going on, it is too late. It is vital to have robust security controls, monitoring and response in place covering all endpoints, networks and systems, and to install software updates whenever they are issued,” said Mark Loman, director of engineering for threat mitigation technology at Sophos, and the author of the report.

How to protect against ransomware

  • Check that you have a full inventory of all devices connected to your network and that any security software you use on them is up to date
  • Always install the latest security updates, as soon as practicable, on all the devices on your network
  • Verify that your computers are patched against the EternalBlue exploit used in WannaCry by following these instructions: How to Verify if a Machine is Vulnerable to EternalBlue – MS17-010
  • Keep regular backups of your most important and current data on an offline storage device as this is the best way to avoid having to pay a ransom when affected by ransomware 
  • Administrators should enable multi-factor authentication on all management systems that support it, to prevent attackers disabling security products during an attack
  • There is no silver bullet to security, and a layered security model is the best practice all businesses need to implement
  • For example, Sophos Intercept X  employs a comprehensive defense-in-depth approach to endpoint protection, combining multiple leading next-gen techniques to deliver malware detection, exploit protection and built-in endpoint detection and response (EDR)

The complete How Ransomware Attacks playbook, as well as a SophosLabs Uncut article, How the Most Damaging Ransomware Evades IT Security, are available.

About Sophos

As a worldwide leader in next-generation cybersecurity, Sophos protects more than 409,000 organizations of all sizes in more than 150 countries from today’s most advanced cyberthreats. Powered by SophosLabs – a global threat intelligence and data science team – Sophos’ cloud-native and AI-enhanced solutions secure endpoints (laptops, servers and mobile devices) and networks against evolving cybercriminal tactics and techniques, including automated and active-adversary breaches, ransomware, malware, exploits, data exfiltration, phishing, and more. The award-winning Sophos Central cloud-based platform integrates Sophos’ entire portfolio of best-of-breed products, from the Intercept X endpoint solution to the XG Firewall, into a single system called Synchronized Security. Sophos products are exclusively available through a global channel of more than 53,000 partners and Managed Service Providers (MSPs). Sophos also makes its innovative commercial technologies available to consumers via Sophos Home. The company is headquartered in Oxford, U.K., and is publicly traded on the London Stock Exchange under the symbol “SOPH.” More information is available at www.sophos.com.

Press Contacts:
Lesley Sullivan, Sophos
[email protected]

Samantha Powers, March Communications
[email protected]

Tags: itindustry Tech
Share
Share on Facebook Share on Twitter Share on Pinterest Share on Email
GlobeNewswire November 14, 2019
GlobeNewswire
View More Posts
GlobeNewswire is one of the world's largest newswire distribution networks, specializing in the delivery of corporate press releases financial disclosures and multimedia content to the media, investment community, individual investors and the general public.
Previous Article FORTUNE and Great Place to Work® Name Horizon Therapeutics plc to Best Workplaces for Parents List
Next Article Armorblox Achieves SOC 2 Type I Attestation

You Might Also Enjoy

One United Properties posts a consolidated turnover of 285.5 million euros and a gross profit of 88.6 million euros in 2024

Posted by Zoltán Tűndik February 27, 2025
READ MORE

QNB Group Strengthens Innovation and Fintech Ecosystem with Strategic MoUs at Web Summit Qatar 2025

Posted by Zoltán Tűndik February 27, 2025
READ MORE

Calderys invests in a state-of-the-art Innovation Center in Neuwied, Germany

Posted by Zoltán Tűndik February 27, 2025
READ MORE

MEXC Launches Campaign for ENA & USDe with $1,000,000 Rewards

Posted by Zoltán Tűndik February 27, 2025
READ MORE

PICANTE is a news publishing website which digests / hand picks the latest news about technology, entertainment, lifestyle, finance and politics and serves them to you daily.

Whenever you are looking the find out more about the latest in AI or mobile, wining and dining, home-land security across the world, data analytics, fashion, pop and movie culture, political developments and much more, you are in the right place. Just head to our menu and browse the topics by category. We are sure you will find information that you might not find in other media sources

Email: [email protected]

Latest Posts

Esker (Market Dojo) Recognised in the 2025 Gartner® Market Guide for Sourcing Applications

February 27, 2025

Whatfix Unveils ScreenSense: An AI Technology to Shape the Next Frontier of Digital Adoption

February 27, 2025

Veeva Direct Data API Now Included with Vault Platform to Enable AI Innovation

February 27, 2025

Consensus concludes sold-out debut event in Hong Kong and announces return to Asia in 2026

February 27, 2025

Bybit Takes Aim at Crypto Crime with Launch of Industry-first LazarusBounty.com Platform

February 27, 2025

HIPTHER Talks Podcast

  • About PICANTE
  • Advertise
  • Authors at PICANTE
  • Cookies
  • Contact Us
  • RSS
  • Sitemap
  • B2B Press Releases
  • Press Release Distribution Services
  • Privacy Policy
  • Terms of Service

Copyright © 2007 – 2025 HIPTHER. All Rights Reserved Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania

Our website uses cookies to improve your experience. Learn more about: Cookie Policy

Accept