What are Ransomware Attacks?

Once a ransomware virus gains entry into a network or device—typically through deceptive emails or by taking advantage of weaknesses in software applications—it scrambles the victim’s data, rendering it unusable, and then delivers a message with instructions on how to pay a ransom. Today’s ransomware carries a double threat: it not only locks down data but also threatens to leak it publicly or onto dark web marketplaces.

Categories of Ransomware Attacks

Now that you understand what ransomware malware is and how it operates, it is essential to familiarize yourself with the various categories of ransomware attacks, including crypto-ransomware, scareware, lock-screen ransomware, and leakware. The more knowledge you gain about these different ransomware types, the better equipped you will be to reduce their risks.

Crypto-Ransomware (Encrypting Ransomware)

Arguably the most widely recognized form of ransomware is crypto-ransomware, which secures a victim’s files after breaking into a computer system. Well-known examples such as Locky and WannaCry clearly show how easily a system’s security gaps can be exploited and how dangerous phishing attacks can become when criminals use modern ransomware equipped with complex encryption methods. Crypto-ransomware makes a victim’s data inaccessible and essentially worthless until the requested ransom is paid.

Scareware

A somewhat different category from standard crypto-ransomware is scareware. This type of ransomware tricks victims into believing that their computer is under attack from harmful viruses that have already compromised their files. Scareware is known for flooding its targets with fake security warnings and tools that claim to help clean the user’s machine and resolve problems that do not actually exist—all in exchange for a payment.

Screen-Locking Ransomware

One form of ransomware that has grown significantly more common as smartphones and mobile devices have become more central to everyday life is screen-locking malware. This ransomware type freezes a user’s device and displays unremovable, often threatening messages that pressure the user into paying a ransom. This variant frequently pretends to be an official alert from law enforcement agencies to further push victims toward paying up.

Doxware (Leakware)

Last on our list of ransomware categories is doxware—also called leakware—which threatens to publicly expose a victim’s private information unless a ransom is paid. Doxware combines the relatively recent practice of publicly revealing personal data, known as doxxing, with traditional crypto-ransomware. This type relies primarily on the fear of data exposure to force victims into giving in to the attacker’s demands.

How Do Ransomware Attacks Function?

Ransomware attacks generally begin with an initial infiltration step. Attackers use various entry methods and are skilled at quietly compromising systems. Most commonly, criminals use email attachments or links containing hidden malware that appears harmless. Other popular approaches to compromising user information with ransomware include pretending to be authoritative and trustworthy entities—such as law enforcement agencies—to carry out phishing schemes, or exploiting system weaknesses in outdated or unpatched software.

Once ransomware successfully enters a victim’s system, it targets important files and uses sophisticated algorithms to encrypt personal data, making it inaccessible. Unfortunately, victims of ransomware often only realize they have been attacked after their files are already encrypted and they have received a threatening ransom note.

Ransomware attackers typically outline their demands in these notes and use a countdown timer to pressure victims into paying. This ticking clock creates panic and urgency, especially when combined with encrypted critical data and the looming deadline imposed by the attackers. This combination maximizes the chances that the victim will comply with the attacker’s demands.

What Are the Delivery Methods for Ransomware Attacks?

There are several types of ransomware and multiple ways attackers deliver malicious software:

  • Messages containing dangerous links and email attachments.
  • Phishing attacks, where the attacker steals login credentials and then uses them to break into systems and install ransomware.
  • Remote desktop protocol (RDP) brute forcing, which involves exploiting poorly secured ports on remote desktop software. This method is becoming more common as more employees work from home.
  • Malicious websites and drive-by downloads, where the victim visits a harmful site that exploits a flaw in a particular application, operating system, or web browser, then automatically installs malware without the victim’s knowledge or consent.
  • System and software vulnerabilities, where unknown or unpatched bugs in the system allow an attacker to gain access, install ransomware, and eventually demand ransom payments from organizations.

What Are the Current Trends in Ransomware?

Attackers are known to exploit major regional, national, or global events—such as natural disasters, elections, and health crises—to distribute ransomware. For example, the year 2020 saw a massive surge in ransomware incidents, with estimates ranging between 300% and 700%. Researchers attribute this increase to the rise in remote workers, which led to weaker security controls, combined with fears and concerns surrounding the Covid-19 pandemic. For instance, ransomware distribution campaigns have frequently focused on promoting fake and harmful content and links related to topics such as:

  • Healthcare concerns, including cures, vaccines, and protective equipment in short supply, like masks and hand sanitizers
  • Financial distress and fake government payment scams
  • Remote work technology needs, such as video conferencing platforms

Why Are These Attacks Becoming More Frequent?

The recent spike in ransomware attacks can be attributed to several interconnected factors. Chief among them is the strong financial motivation driving perpetrators to carry out these attacks. These potentially large financial rewards, combined with the easy accessibility of ransomware tools, further worsen the alarming increase in ransomware incidents.

Cybercriminals are attracted to ransomware’s profitability and the relative simplicity of executing attacks. With the rise of cryptocurrencies, the payment and money laundering processes have become more anonymous and less risky. Additionally, the growing interconnectedness of digital systems worldwide amplifies the potential impact of attacks, making them an appealing option for criminals. These factors together have led to a troubling rise in ransomware incidents globally, signaling an urgent need for stronger cybersecurity measures and greater public awareness.

How Has Ransomware Changed Over Time?

Ransomware has existed for quite some time—at least as far back as 1989—but over the past two decades, it has evolved into something far more sophisticated, profitable, and dangerous. The evolution of ransomware can be traced to several factors, including:

  • Improvements in malware coding techniques, including obfuscation methods that hide the malware from security tools
  • Lax security practices as well as the dramatic increase in the number of endpoints and bring-your-own-device (BYOD) policies
  • The ease with which aspiring criminals can access, distribute, and automate ransomware, such as through ransomware-as-a-service models
  • The arrival of cryptocurrencies, which not only facilitate payment but also allow cybercriminals to hide their identities from law enforcement
  • The growing number of businesses purchasing ransomware insurance
  • The willingness of victims to pay the ransom

Who Are the Ransomware Attackers?

There are both organized ransomware gangs and independent ransomware criminals who purchase ransomware through ransomware-as-a-service operators. Among the known attackers and groups believed to create, sell, or distribute ransomware are the Lazarus Group (North Korea), Fancy Bear (Russia), Sodinokibi (location unknown), and the Sandworm Team (Russia). However, it is essential to remember that many ransomware threats come from criminals operating independently and buying ransomware through a “ransomware-as-a-service” model. In fact, many well-known ransomware strains also sell their malware as a service to other attackers. These include Ryuk, Lockbit, Sodinokibi/REvil, and Egregor/Maze.

Which Industries Are Most Impacted by Ransomware?

While all industries are targeted by ransomware, some are affected more frequently, including government, healthcare, education, legal services, transportation, manufacturing, and farming and food production. Additionally, some ransomware strains may only target specific industries. For example, the Babuk ransomware appeared to focus on the transportation, healthcare, plastics, electronics, and agricultural sectors.

Ransomware Investigation and Incident Response

If you believe you have been hit by a ransomware attack, the most important thing is to avoid panic mode and instead conduct a thorough investigation. While decisive action should be taken as quickly as possible, every step you take should be informed and measured.

  • Work with an incident response company – Consider partnering with a professional incident response team that has current and deep knowledge of ransomware and how to best handle an attack.
  • Have an Incident Response Plan – Your plan should outline the processes to follow from an organization-wide perspective, including which teams and executives need to be notified, which experts or professionals should be brought in, whether you should contact authorities, your policy on ransom payment, and how to inform any internal staff or external customers who may be affected.
  • Understand the ransomware type – Spend time learning what you can about the specific strain or variant of ransomware so you can determine the extent of the damage, including whether the attackers likely moved sideways within your systems.
  • Know the attacker – Individual and group ransomware attackers all operate differently, so it is essential to understand your particular adversary’s tactics, techniques, and procedures (TTPs). For example, some may be willing to negotiate terms.
  • Know your timeline – It is important to understand how much time you have during the attack process to complete your investigation and decide whether you will be able to restore your data and devices.
  • Insurance – Ransomware insurance is increasingly popular. If you have coverage, make sure you know your policy terms.
  • Legal Counsel – Legal professionals can help you understand your business and regulatory obligations when disclosing and reporting the incident.

Ransomware Protection and Prevention Techniques

  • Maintain an Incident Response Plan – Having a customized incident response plan is essential to guide you when your business faces a ransomware attack or breach. A plan will help you determine the scope of business disruption, the extent of exposure, the necessary resources, and the step-by-step processes to get your business running again.
  • Ensure visibility – Know your systems and your organization. Businesses that fall victim to ransomware attacks often struggle if they have not taken the time to understand their security features, logging policies, and similar elements.
  • Perform regular backups – Engage in consistent system and data backups. If a ransomware attack occurs, something this simple could save you from having to pay the ransom.
  • Disable macros – Many ransomware strains need to be activated through a macro. Make sure your staff keeps macros disabled so that even if someone accidentally clicks a link and downloads ransomware, the malicious code will not install.
  • Avoid open RDP – Ensure you do not have any remote desktop protocols exposed to the internet that could provide easy access for an attacker.
  • Use multi-factor authentication (MFA) – MFA offers protection against ransomware attacks by helping to prevent a breach if an attacker has obtained someone’s login credentials.
  • Patch. Patch. Patch. – Make sure all your hardware, devices, systems, and software are regularly patched and updated to prevent attacks through vulnerabilities and bugs.
  • Apply least privilege – Limit access to resources (users, systems, or devices) based on the minimum needed for business operations to help prevent lateral movement across networks and systems if a breach occurs.
  • Provide training – Make phishing and social engineering training mandatory for all employees.

Leave A Comment

Name*
Message*

Scroll to top