Ransomware is a threat to all businesses. However, due to ineffective or absent training and antivirus software, some organizations are more vulnerable than they may realize. In this article, we will outline what ransomware is, how it attacks networks, and how you can keep your business secure against this ever-present threat.
Il ransomware è un tipo di malware a cui i criminali informatici fanno ricorso per infettare un dispositivo o una rete con software dannoso, che quindi cripta i file e converte dati preziosi in codice illeggibile. Questi dati vengono tenuti in ostaggio dagli hacker, che li decriptano solo dopo il pagamento di un riscatto.
Molti si chiedono: il ransomware è un virus? La risposta è no. Ransomware e virus sono entrambi forme di malware che hanno metodi di attacco diversi: un virus infetta i file, mentre il ransomware li crittografa.
Le organizzazioni possono essere vittime di un attacco ransomware attraverso e-mail di phishing, vale a dire l’invio di messaggi contenenti un’”esca” per attirare le vittime, o download drive-by, in cui un utente visita un sito web infetto e scarica inavvertitamente del malware.
Per ransomware aziendale si intende un attacco ransomware contro un’azienda o un’organizzazione. La maggior parte degli attacchi ransomware colpisce le imprese, in quanto promettono la massima ricompensa per i criminali informatici, ma le specifiche variano da un obiettivo all’altro.
C’è un motivo per cui i criminali informatici tendono ad attaccare le aziende e non i singoli individui e ha a che fare con il modo in cui il ransomware si diffonde e il potenziale valore del crimine. In sostanza, come si diffonde? Il malware viene scaricato in un dispositivo quando qualcuno apre un’e-mail e/o fa clic su un URL discutibile. Generalmente, un’organizzazione più grande con più personale (quindi, più utenti che fanno clic) presenta maggiori opportunità per la diffusione del ransomware. Tuttavia, le aziende più grandi possono mettere in atto procedura di sicurezza più avanzate, per via di questo rischio di attacco superiore e poiché spesso hanno anche a disposizione un budget maggiore.
Le aziende più grandi sono anche più a rischio di un attacco ransomware a causa del valore dei dati in loro possesso. È probabile che abbiano maggiori quantità di dati più sensibili, quindi qualsiasi interruzione del servizio comporterebbe più costi operativi. Tenendo a mente questo aspetto, le organizzazioni di questo tipo potrebbero essere più propense a pagare un riscatto e ad alimentare una domanda maggiore. Ad esempio, un attacco ransomware contro un ospedale probabilmente frutterebbe un riscatto maggiore a un criminale informatico rispetto a uno contro un negozio di fiori.
Secondo l’opinione comune, la storia del ransomware ha inizio nel 1989 con un virus noto con il nome di "trojan AIDS". In un attacco orchestrato dal biologo Joseph Popp, 20.000 dischi contenenti un virus trojan sono stati distribuiti a una conferenza sull’AIDS dell’Organizzazione mondiale della sanità. Una volta compromesso un computer, sullo schermo compariva una richiesta di riscatto di 189 dollari da inviare a una casella postale a Panama.
Dagli anni 80, la tecnologia è avanzata e i criminali informatici non hanno più bisogno di utilizzare una casella postale per ricevere il denaro. Ora il riscatto si richiede in Bitcoin e il malware viene adattato per diventare più pericoloso e dirompente, ad esempio assumendo caratteristiche simili a quelle dei worm e innovando le tecniche di infezione. Anche le protezioni anti-ransomware si stanno adattando per difendere meglio le reti da questi attacchi sempre più sofisticati.
There are several types of ransomware – with attacks targeting small and medium-sized businesses to large-scale corporations and government-run healthcare providers. The size of the ransom can vary as well, from hundreds of dollars to millions.
Cryptolocker has been around since 2013 and is thought to be the first example of ransomware following the original 1989 attack. With the introduction of cryptocurrencies in the 2010s, cybercriminals were able to demand ransoms via an untraceable payment method. Cryptolocker was the first ransomware attack that used advanced encryption and included a ransom note with directions to pay with Bitcoin.
The malware sustained an attack from September until the following May, in which it infected 250,000 devices, and the criminals collected at least $3 million. Cryptolocker is detectable by the ransom note that appears on the screen.
Ryuk ransomware originated in 2018 and was based on an existing Trojan horse program, Hermes, that was first knowingly used in 2017. While Hermes was used in an attack by a North Korean state-sponsored cybercrime group, it is now widely believed that the malware was developed in Russia.
In 2021, a new “worm-like” variant of Ryuk, one that can automatically travel across multiple devices as the program spreads copies of unique versions of itself, was detected.
Knowing your device has been infected by WannaCry ransomware is easy – you’ll see the line “Oops, your important files are encrypted.” The attack was first used in 2017, when more than 230,000 computers were infected in a day.
In each attack, cybercriminals charge $300 in bitcoin for the decryption of their files, with the ransom doubling if demands are not paid in time. WannaCry is also a worm-based malware that can automatically travel across networks.
Sodinokibi is a family of ransomware that targets Windows devices. When infected by Sodinokibi ransomware, also known as REvil, you will see a ransom note appear on the screen, demanding bitcoin to decrypt all your files. This malware targets everything on a device except what is listed in its configuration file. The malware was first used in 2019.
Also known as CrySiS, Dharma ransomware is known for attacking small to medium-sized businesses and demanding smaller ransoms to increase the likelihood of victims paying
The ransomware usually attacks via Remote Desktop Protocol and was first detected in 2016. The malware was the basis for the creation of Phobos ransomware, which works similarly.
Petya ransomware has to encrypt files to function, and while other malware may encrypt specific critical data, Petya can target your entire hard drive and prevent your device from turning on. The ransomware was first used in 2016 but made a name for itself in 2017 with a new variant known as GoldenEye.
Cerber is an example of ransomware-as-a-service (RaaS), based on the software-as-a-service model. The malware creators license Cerber to other cybercriminals and in exchange, get a cut of the ransom payment. Once infected, a device will show the Cerber ransom note with the demands on the screen. The malware can also encrypt files on any unmapped network shares.
First detected in 2016, Locky ransomware spreads via emails. It is known for targeting an LA-based hospital and demanding $17,000. This was followed by attacks on numerous other healthcare organizations. However, there have been no high-profile attacks using Locky since that initial wave.
Ransomware has had a huge impact on the digital world, having extracted billions of dollars from victims throughout the years. Let’s take a look at some of the biggest examples of the most disruptive and expensive ransomware attacks:
Falling victim to a ransomware attack is bad news for your business’s finances - not just from the ransom itself, but you could also face fines from data privacy regulators or lose business due to the negative impact on customer trust.
According to Cybersecurity Ventures, the cost of global ransomware attacks alone is estimated at $20 billion in 2021, and a business is thought to be attacked by malware every 11 seconds. On top of that, European businesses are facing additional GDPR fines for poor security operations. In 2020, British Airways was faced with a £20 million ($26 million) fine from the regulator – however, the initial fine was £183 million ($239 million).
If loss of money isn’t enough, many businesses struggle with recovery – especially the smaller ones. Around 60% of small businesses close after falling victim to a data breach. In 2020, The Heritage Company, an Arkansas-based telemarketing firm closed following its 2019 ransomware data breach. Whether it’s the cost of managing the attack, the recovery operations, or the loss of clients, ransomware recovery can take its toll on a business.
When a business lacks effective security measures, it becomes vulnerable to cyberattacks.
Lack of staff training is a key vulnerability for businesses. If employees don’t know how to spot a suspicious email, detect ransomware, and report an issue, they run the risk of infecting devices and the entire network. Staff may not be aware that their devices are susceptible to attacks, or the risks of ransomware for Macs or Linux ransomware. While these two operators may have reputations for stronger built-in security than Windows, they are still at risk of a cyberthreat.
Third-party apps can also be an entry point from which cybercriminals can penetrate your network. They may find it easier to access an app than your system, and use this opening to infect your devices with malware.
While staff may create vulnerabilities, a secure business will have a functioning antivirus tool in place that can protect against potential malicious software when accidentally downloaded. Software needs to be regularly updated (or ‘patched’) to fix bugs and address vulnerabilities – unpatched software could lead to cracks in your defenses.
There are many effective ways to protect your business against a ransomware attack, and avoid becoming a target. As with many cyberattacks, criminals gain access to a network due to bad IT practices. These include:
This is why operational security is vital. Training staff and thorough credentials go hand-in-hand. Staff must be trained on how best to access the network, especially when working remotely, as well as how to spot phishing emails, report suspicious activity, and create strong passwords. All this should be outlined in a business continuity plan – and while prevention is better than cure, it also helps to have plans for IT disaster recovery and business continuity in place. Other key measures to prevent a ransomware attack include:
There are many tell-tale signs that a computer has been compromised by ransomware – the most obvious one being the ransom note. Here are some other common indicators:
If you’ve been subject to a ransomware attack, here are the key steps to take:
An effective cybersecurity tool is key for any business of any size. Avast Small Business Solutions will spot malicious files and prevent ransomware attacks. Protect your company devices and data today.