Its 2022 and Ransomware Menace Refuses to Go Away

In the previous posts, we have discussed how mobile devices are the new attack surfaces for cybercrime, and cyber-kinetic attacks are here to stay. In this post, we would like to shed some light on the ever-growing menace of ransomware attacks.

On the surface of the matter, a ransomware attack is one of the most viable business models for threat actors – regardless of their geography. An attack that gains unauthorised access to vital infrastructure, encrypts it and holds it captive with a ransom. The ransom is often demanded in the form of bitcoins or other cryptocurrency, which if not paid there will always be a lingering threat of the stolen data being leaked in underground forums. What is, therefore, at stake is not data alone. It is the damage to reputation and the loss of consumer confidence as well.

To put things into perspective, here are some facts and figures on the ransomware threat landscape:

  1. Almost 37% of all businesses and organizations, globally, were hit by ransomware in the year 2021.
  2. Recovering from a ransomware attack has, on average, costed businesses USD 1.85 million in 2021.
  3. While 32% of the ransomware victims paid the ransom, they could get only 65% of the stolen data back.
  4. Overall, ransomware cost the world approximately USD 20 billion in 2021.

As per our research, ransomware operators have upgraded to following a four-layered approach of targeting organisations that includes:

  1. Infiltrate into the target organization’s network
  2. Exfiltrate and encrypt data
  3. Demand ransom and “Name & Shame”
  4. Leave behind footprints in the targeted organizations to return and attack again

As these attacks promise immense profits, along with a strong reputation amongst their peer group, cybercriminals have now opted for this model named Ransomware-as-a-Service (RaaS). In RaaS, ransomware developers sell/ establish affiliates for their tools.

Given that the cost of hacking tools has come down substantially, and the attack surface is expanding at a rapid pace, researchers believe that the ransomware industry could further evolve into a subscription model – wherein organizations/ businesses would pay the cybercriminals to not attack them.

Another interesting development in the ransomware landscape is the recruitment of insiders to improve their attacks. A survey conducted between 7 December 2021 and 4 January 2022, found that 65% of its respondents were approached by ransomware attackers to gain the initial access into critical infrastructure. Here it is important to note these cybercriminals are making most of the ongoing trend of “the great resignation” in the United States. The money offered to these employees was mostly below USD 500,000 – which can be quite enticing for those who are quitting or are on the verge of resigning.

Therefore, based on attack vectors like phishing emails, exploitation of vulnerabilities, and now leveraging the real-time trend of great resignation – the need of the hour is to build strong security boundaries to keep the ransomware criminals at bay.

As per our cyber threat intelligence (CTI) team, here are some of the best ways through which organizations and businesses can safeguard critical data and infrastructure:

  1. Prioritize resources (based on classification, criticality, and business value) and understand the true scope and impact of a potential ransomware event. It is an important factor in contingency planning for future ransomware events, emergency responses, and recovery actions allowing the organization to prioritize the response and recovery activities.
  2. Block exploit-like behaviour. Monitor endpoints memory to find behavioral patterns that are typically exploited, including unusual process handle requests. These patterns are features of most exploits, whether known or new. This will be able to provide effective protection against zero-day/critical exploits and more, by identifying such patterns.
  3. Periodically conduct red team exercises to identify externally exposed and insecure internal information.
  4. Consider implementation of a people-centric Insider Threat Management (ITM) that is designed for modern work-from-anywhere workflows and provides cross-collaboration between technical and non-technical representatives (from IT, HR, compliance and legal, etc).
  5. Deploy solutions to keep track of employee actions and correlate information from multiple data sources and leverages several techniques (sophisticated behavioral analytics, machine learning, adaptive baselining, heuristics, reputation databases, signature-based detection). Use Network Detection and Response (NDR) solution to overcome challenges when dealing with insider threats.
  6. Implement competent security protocols and encryption, authentication, or access credentials configurations to access critical systems in your cloud and local environments.
  7. Enable zero-trust architecture and multifactor authentication (MFA) to mitigate the compromise of credentials.

Cyber-Kinetic: The War Goes Beyond the Wire

Cyber-Kinetic: The War Goes Beyond the Wire

The loss of critical data, operational disruption, financial loss, most of all reputational damage – These are all considered to be common impacts of a cyberattack. While all these factors cause an enormous negative effect on the business, none of them cause any physical damage – perhaps this is the reason cyberwar is often called “war over the wire”. And only when individuals and organizations were building and rebuilding their cyber security frameworks – Scott Applegate’s words about “The Dawn of Kinetic Cyber” seems to be slowly turning into a sharp reality. Cybercriminals are no longer following the path of non-violence. Depending on the monetary gains and national interests, these criminals have switched to causing physical damage and are not afraid to fight till the death.

The Merging Worlds of Cyber-Physical and Cyber-Kinetic

As we switch to getting “smart” in almost every aspect of our lives with easy adoption of the Internet of Things (IoT) and Industrial Control Systems (ICS), we end up building cyber-physical systems (CPSes) around us. In 2006, Dr. Helen Gill of the National Science Foundation defined these systems as “physical, biological, and engineered systems whose operations are integrated, monitored, and/or controlled by a computational core. Components are networked at every scale. Computing is deeply embedded into every physical component, possibly even into materials. The computational core is an embedded system, usually demands a real-time response, and is most often distributed.”

So, if you think about it, from our water management systems and power grids to automated insulin pumps and defibrillators – most of us are surrounded by CPSes on a regular basis. While there is hardly any doubt that these CPSes have enhanced and improved the way we lead our lives, we cannot deny the inherent exposure to the disquieting possibilities of a tangible cyber threat.

Even though the timeline of cyber-kinetic attacks can be traced beyond the Stuxnet attack on the Iranian nuclear facility (2009-10), the 2021 incident wherein a hacker tried to pump a dangerous amount of chemicals into the water system of Florida – highlights the implications of such attacks.

Time to Redesign Our Security Paradigm?

As highlighted in our Cyber Security Predictions for 2022, kinetic-cyber results in:

  1. Forcing the victims to be more open to negotiations when faced with the prospect of potential human casualties, and
  2. Enhancing the credibility of cybercriminals amongst peers and finetuning their ability to bring in big financial gains, cause the maximum reputational damage, recruit affiliates, etc.

Our cyber threat intelligence team observes that verticals like critical infrastructure, healthcare, and research, would be targeted predominantly because of the ongoing COVID-19 pandemic, and the availability of vulnerable assets, including unpatched, outdated, or forgotten assets still in use.

Therefore, it is time organizations move beyond the traditional security paradigm and adopt solutions that are in sync with the emergent threat landscape. Some of the best ways in which one can future-proof against cyberattacks, especially kinetic-cyber are:

  1. Securing the organization’s internet-facing properties with robust security protocols and encryption, including authentication or access credentials configuration, to ensure that critical information stored in databases/servers is always safe.
  2. Implement a holistic security strategy that includes controls for attack surface reduction, effective patch management, active network monitoring, through next-generation security solutions, and ready to go incident response plan.
  3. Blocking exploit-like behavior as well as monitoring endpoints memory to find behavioral patterns that are typically exploited, including unusual process handle requests. These patterns are features of most exploits, whether known or new.
  4. Always listen to the research community and customer feedback when contacted about potential vulnerabilities detected in the organization’s infrastructure, or related compliance issues.
  5. Lastly, conducting regular audits in the critical sector like data centers to prevent downtime to a significant level and foster a culture of cybersecurity – wherein organizations encourage and invest in employee training so that security is an integral part of your organization.

 

Mobile Devices: The Emergent Playground for Ransomware Attacks

Take Steps To Enhance Your Mobile Cybersecurity Now!

There is a very good chance that you are reading this article on your mobile device, with perhaps 1-2 other apps simultaneously open through which you are either shopping for daily groceries, killing zombies or checking your bank statement.

What started out as a device for voice communication has redefined wireless communication and connectivity through video calls, social media platforms, online shopping and has turned into a vibrant storehouse of precious professional as well as personal data. For cybercriminals, this playground of unsecured mobile devices is like a free ticket to Disneyland.

Get a Personal Digital Bodyguard for Your Mobile Device with DeFNCE

As You Go Mobile, So Do Cybercriminals

To understand why any device is under attack, one must first figure out what attackers are looking for. Cybercriminals, especially ransomware groups, are constantly looking for data that carry commercial value. This data – which if lost or sold – can bring in major repercussions like damage to personal reputation as well as significant financial loss.

Now, given that your mobile phones carries very personal and private data that is beyond just the contact details of your family and friends, it has emerged as one of the top attack surface vectors for several cyber-attacks.

Why Mobile?

It is not just the availability of critical personal information and financial data but also the fact that mobile security is still in a nascent stage which makes it a low-hanging fruit for cybercriminals. In 2021, the number of mobile devices stood at almost 15 billion and is expected to reach 18.22 billion by 2025. Statisticians project the data volume created by IoT connections to reach a massive total of 79.4 zettabytes by 2025. Combine this congenial condition with the flourishing Ransomware-as-a-Service (RaaS) business model – and what you get is possibly one of the most lethal cyber-attack vectors in the history of technology.

Now consider this – 75% of the respondents of a recent survey agreed on being highly reliant on cloud-based mobile apps; with 31% accepting of being lax on security restrictions when installing new mobile apps due to the ongoing pandemic. The survey also found that one in every 25 mobile apps has already leaked user credentials, at one point or another.

For those of you who are data-driven, the above-given numbers paint a rather gory picture of the device which has turned into an extension of your personality. And as such, mobile devices are fertile ground for disastrous ransomware attacks.

Infographic: 7 tips to tighten your mobile security

One of the best ways to boost up your mobile security is by keeping anti-virus software updated to detect and remove malicious software. Enabling zero-trust architecture and multi-factor authentication (MFA) to mitigate the compromise of credentials will go a long way in securing your mobile devices. Most of all, avoid installing mobile apps by clicking on links in emails, social media posts, text messages, and websites that look suspicious. Here at CYFIRMA, we recently released a mobile defence app that can help scan your device for possible data breaches and malicious apps.

This can be followed by restricting data access through the adoption of the principle of least privilege on both BYOD and company devices. Organizations can also ensure that only authorized and secure users or devices can access corporate infrastructure through zero-trust network access (ZTNA) policies for on-premises or private apps and cloud access security broker (CASB) capabilities for cloud-based apps and infrastructure.

Given that work from home (WFH) is the current norm, it will be prudent to direct traffic from mobile workers via special gateways with customized firewall and security controls such as content filtering and data loss prevention capability. Our cybersecurity experts also recommend restricting which applications may be installed through whitelisting (preferable) or blacklisting them.

Implementing Mobile Device Management (MDM) and Mobile Application Management (MAM) policies to enhance corporate data security providing monitoring, managing, and securing mobile devices such as laptops, smartphones, and tablets that are used in enterprises is another way in which organizations can beef up the security of mobile devices.

Lastly, as cliched as it can get, educating personnel about the security of their mobile device and social media security risks will be the best way to tackle ransomware attacks in the long term.

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.