What is ransomware ?

Ransomware is a subset of malware in which the data on a victim's computer is locked -- typically by encryption -- and payment is demanded before the ransomed data is decrypted and access is returned to the victim. The motive for ransomware attacks is usually monetary, and unlike other types of attacks, the victim is usually notified that an exploit has occurred and is given instructions for how to recover from the attack. Payment is often demanded in a virtual currency, such as bitcoin, so that the cybercriminal's identity is not known.

 

- Ransomware malware can be spread through malicious attachments found in emails or in infected malicious software apps, infected external storage devices and compromised websites. Attacks have also used Remote Desktop Protocol and other approaches that do not rely on any form of user interaction.

How do ransomware attacks work ?

 

- Ransomware kits on the deep web have enabled cybercriminals to purchase and use software tools to create ransomware with specific capabilities. They can then generate this malware for their own distribution, with ransoms paid to their bitcoin accounts. As with much of the rest of the information technology world, it is now possible for those with little or no technical background to order inexpensive ransomware as a service (RaaS) and launch attacks with minimal effort.

 

- One of the more common methods of delivering ransomware attacks is through a phishing email. An attachment the victim thinks they can trust is added to an email as a link. Once the victim clicks on that link, the malware in the file begins to download.

 

- Other more aggressive forms of ransomware will exploit security holes to infect a system, so they do not have to rely on tricking users. The malware can also be spread through chat messages, removable Universal Serial Bus (USB) drives or browser plugins.

 

- Once the malware is in a system, it will begin encrypting the victim's data. It will then add an extension to the files, making them inaccessible. Once this is done, the files cannot be decrypted without a key known only by the attacker. The ransomware will then display a message to the victim, explaining that files are inaccessible and can only be accessed again upon paying a ransom to the attackers -- commonly in the form of bitcoin.

Type Of Ransomware

 

Attackers may use one of several different approaches to extort digital currency from their victims:

 

Scareware : This malware poses as security software or tech support. Ransomware victims may receive pop-up notifications saying malware has been discovered on their system. Security software that the user does not own would not have access to this information. Not responding to this will not do anything except lead to more pop-ups.

 

Screen lockers : Also known simply as lockers, these are a type of ransomware designed to completely lock users out of their computers. Upon starting up the computer, a victim may see what looks to be an official government seal, leading the victim into believing they are the subject of an official inquiry. After being informed that unlicensed software or illegal web content has been found on the computer, the victim is given instructions on how to pay an electronic fine. However, official government organizations would not do this; they instead would go through proper legal channels and procedures.

 

Encrypting ransomware : Otherwise known as data kidnapping attacks, these give the attacker access to and encrypt the victim's data and ask for a payment to unlock the files. Once this happens, there is no guarantee that the victim will get access to their data back -- even if they negotiate for it. The attacker may also encrypt files on infected devices and make money by selling a product that promises to help the victim unlock files and prevent future malware attacks.

 

Doxware : With this malware, an attacker may threaten to publish victim data online if the victim does not pay a ransom.

 

Master boot record ransomware : With this, the entire hard drive is encrypted, not just the user's personal files, making it impossible to access the operating system.

 

Mobile ransomware : This ransomware affects mobile devices. An attacker can use mobile ransomware to steal data from a phone or lock it and require a ransom to return the data or unlock the device.

 

How do you prevent ransomware attacks ?

 

To protect against ransomware threats and other types of cyberextortion, security experts urge users to do the following:

 

- Back up computing devices regularly.

 

- Inventory all assets.

 

- Update software, including antivirus software.

 

- Have end users avoid clicking on links in emails or opening email attachments from strangers.

 

- Avoid paying ransoms.

 

- Avoid giving out personal information.

 

- Do not use unknown USB sticks.

 

- Only use known download sources.

 

- Personalize antispam settings.

 

- Monitor the network for suspicious activity.

 

- Use a segmented network.

 

- Adjust security software to scan compressed and archived files.

 

- Disable the web after spotting a suspicious process on a computer.

 

While ransomware attacks may be nearly impossible to stop, individuals and organizations can take important data protection measures to ensure that damage is minimal and recovery is as quick as possible. Strategies include the following:

 

• Compartmentalize authentication systems and domains.

 

• Keep up-to-date storage snapshots outside the primary storage pool.

 

• Enforce hard limits on who can access data and when access is permitted.

 

How to remove ransomware?

 

- There is no guarantee that victims can stop a ransomware attack and regain their data; however, there are methods that may work in some cases. For example, victims can stop and reboot their system in safe mode, install an antimalware program, scan the computer and restore the computer to a previous, noninfected state.

 

- Victims could also restore their system from backup files stored on a separate disk. If they are in the cloud, then victims could reformat their disk and restore from a previous backup.

 

- Windows users specifically could use System Restore, which is a function that rolls Windows devices and their system files back to a certain marked point in time -- in this case, before the computer was infected. For this to work, System Restore needs to be enabled beforehand so that it can mark a place in time for the computer to return to. Windows enables System Restore by default.

 

- For a general step-by-step process in identifying and removing the ransomware, follow these recommendations:

 

1.Create a system backup, and back up all important or integral files. If an organization cannot recover its files, it will be able to restore from a backup.

 

2.Ensure system optimization or cleanup software does not remove the infection or other necessary ransomware files. The files must first be isolated and identified.

 

3.Quarantine the malware using antimalware software. Also, make sure the attackers did not create a backdoor that can allow them to access the same system at a later date.

 

4.Identify the ransomware type and exactly which encryption method was used. Decryptor and ransomware recovery tools can help determine the type of ransomware.

 

5.Once identified, ransomware recovery tools can be used to decrypt files. Because of the different and evolving methods of ransomware, there is no absolute guarantee that the tool will be able to help.

 

Ransomware recovery tools include products such as McAfee Ransomware Recover and Trend Micro Ransomware File Decryptor.

Enjoyed this article? Stay informed by joining our newsletter!

Comments

You must be logged in to post a comment.

About Author

I am a article writer and ethical hacker....