India is among the top 5 countries in the world to be affected by ransomware. This actionable security advisory aims to provide information about ransomware and ways to counter this threat.
What is ransomware?
In layperson’s terms, ransomware is someone locking up your door with their lock and demanding a ransom from you to provide the key.
Technically, ransomware is malicious software (malware) that seeks to
elicit a ransom payment from a victim. When ransomware infects a system it commonly encrypts all of the document files on the hard drive as well as accessible network folders. Documents so encrypted are unusable unless decrypted with a unique decryption key held by the attackers.
After a ransomware infection takes hold, instructions on how to pay the ransom are presented, typically demanding payment in the virtual currency known as Bitcoin to obtain the decryption key.
How can a system become infected with ransomware?
Ransomware infections typically occur by opening malicious attachments and links in spam/phishing emails and by browsing to a website that’s been compromised to infect visitors. Systems infected with other forms of malware can also be commanded by attackers to retrieve and install ransomware.
Can ransomware spread from one computer to another?
Yes. Ransomware is becoming contagious. A recent ransomware version additionally attempts to infect other computers and transform affected document files into infectious ransomware programs. An uninfected system can become infected when such a document is opened. In this way, ransomware infections can spread across systems that access a common shared folder, for example.
Does security (anti-virus) software protect against ransomware?
Anti-virus software detects and prevents infection from known ransomware variants, but there can be a period between the release of a new ransomware variant and effective anti-virus protection. Running up-to-date anti-virus software is important but protection is not absolute. Security software that includes an intrusion prevention feature can also help to prevent ransomware from spreading between systems.
I have been hit by ransomware. Can I hope to recover without paying ransom?
Given the strength of the lock used (encryption) it would take months and maybe years—to decrypt. In case you have been hit by an older versions of ransomware, you may just get lucky. Some of the older ransomware have fatal flaws in them in which they store the decryption key in memory or on the hard drive.
Should I pay?
Paying a ransom does not guarantee an organization will regain access to their data. In fact, some individuals or organizations were never provided with decryption keys after paying a ransom. Recent cases have come to light where ransomware deletes all files on infection and no files are recoverable even after payment of ransom.
Paying a ransom emboldens the adversary to target other organizations for profit and provides a lucrative environment for other criminals to become involved. While we do not advocate paying a ransom, there is an understanding that when businesses are faced with an inability to function, executives will evaluate all options to protect their shareholders, employees, and customers.
How can I avoid getting hit by ransomware?
Like every other cyber threat, while you can never totally eliminate the threat, you can significantly reduce the chances of getting affected by following some simple steps:
Action to be taken by users of computer systems
Action to be taken by CIO/CISO
Sources: FBI Circular on ransomware, City University of New York advisory on ransomware
About Confidis
Confidis works at the intersection of business and technology. We provide advisory services in security, continuity and technology. Our extensive experience in providing management consulting services in various domains including strategy, operations, Information Technology, security, and training enables us to provide innovative ways of developing people, skills and business that can make a difference to you and your company. We believe in having our “skin in the game”. Hence, our services extend beyond providing merely advice to management. We are prepared to implement the advice we give.
Disclaimer
Confidis refers to Confidis Advisory Services Private Limited. This material is prepared by Confidis. This material (including any information contained in it) is intended to provide general information on a particular subject(s) and is not an exhaustive treatment of such subject(s) or a substitute to obtaining professional services or advice. This material may contain information sourced from publicly available information or other third party sources. Confidis does not independently verify any such sources and is not responsible for any loss whatsoever caused due to reliance placed on information sourced from such sources. Confidis, by means of this material, is not rendering any kind of professional advice or services.
You should seek specific advice of the relevant professional(s) for these kind of services. This material or information is not intended to be relied upon as the sole basis for any decision which may affect you or your business. Before making any decision or taking any action that might affect your personal finances or business, you should consult a qualified professional adviser.
Confidis shall not be responsible for any loss whatsoever sustained by any person or entity by reason of access to, use of or reliance on, this material. By using this material or any information contained in it, the user accepts this entire notice and terms of use.
©2016 Confidis Advisory Services Private Limited