Fortifying Your Defences Against Ransomware
A new whitepaper from encrypted storage solutions provider iStorage urges businesses to adopt more robust measures to protect data from ransomware attacks.
The company highlights the emergence of Ransomware-as-a-Service (RaaS), which sees ransomware authors offering clients off-the-shelf malware variants, expertise from the cybercrime community and databases full of credentials as a particular threat that is capable of placing the means to implement an attack into the hands of many more prospective perpetrators.
CEO of iStorage, John Michael, explains: “Put simply, 2023 will see the coming together of the means, motive and opportunity when it comes to executing ransomware attacks.
The growing social unease and tense geo-political relations that may cause grievances, the lucrative gains to be made, and now easy access to ransomware technology are a toxic combination that should be a cause for concern for cyber security and IT professionals.
A single ransomware attack can net perpetrators millions of dollars, with recent attacks demanding upwards of US $70 million and cybercrime itself costing organisations US $6 trillion per year in global damages. The European Union Agency for Cybersecurity, ENISA, says ransomware now "ranks as a prime threat" in the cybersecurity landscape.
It has never been more imperative, therefore, to adopt a never trust and always verify stance with regards to access permissions.
Phishing attacks are also becoming more complex as technology evolves. For example, Spear phishing - crafting targeted attacks on individuals by aping high-level employees - can now be automated via AI to generate conversion rates of up to 80%. AI has been used to emulate the voices of CEOs, making phone-based phishing (known as vishing) truly effective. And as the power of AI grows, such deep fakes will infiltrate video calls too.
By doing nothing and assuming that an attack is something that will happen to other businesses will mean the situation becomes far worse in 2023.”
The European Union Agency for Cybersecurity, ENISA, says ransomware now “ranks as a prime threat” in the cybersecurity landscape.
Malware authors are flush with more directions of attack – and potential vulnerabilities lurking in a wider range of easily-accessed systems – than ever before.
Ransomware spreads through various means, including phishing emails with malicious links or attachments, portable computers, exposure to public Wi-Fi, and Zero-Day vulnerabilities.
Malicious threat actors are moving from simply locking down data to employing double and triple extortion tactics, whereby they intend to steal, threaten to share that information, and also make ransom demands against a business’s third-party clients.
Phishing attacks are also becoming more complex as technology evolves.
For example, Spear phishing - crafting targeted attacks on individuals by aping high-level employees - can now be automated via AI to generate conversion rates of up to 80%[3].
AI has been used to emulate the voices of CEOs[4], making phone-based phishing (known as vishing) truly effective.
And as the power of AI grows, such deep fakes will infiltrate video calls too.
[1]https://www.theverge.com/2021/7/5/22564054/ransomware-revil-kaseya-coop
[2]https://www.sdxcentral.com/articles/news/cisco-ceo-cybercrime-damages-hit-6-trillion/2021/05/
[3]https://www.scmagazine.com/analysis/phishing/ai-as-a-service-tools-craft-spear-phishing-emails-with-minimal-human-input
[4]https://www.wsj.com/articles/fraudsters-use-ai-to-mimic-ceos-voice-in-unusual-cybercrime-case-11567157402