Ransomware (Ransomware)

What is Ransomware? How Can You Protect Yourself from Ransomware? The term "ransomware" comes from English and includes the term "ransom," which translates to "held for money." Ransomware is a malicious program that locks a computer for the user and can only be unlocked by paying the ransom. How exactly does ransomware work? How big is the threat of ransomware? How can you protect yourself from ransomware? We will explain all of this in this article!

8 Feb 2024 SintelSedat Akfidan 9 min read
Ransomware (Ransomware)

What is Ransomware?

Ransomware is a malicious software that is installed on a computer without being noticed by the victim. The difference between ransomware and normal malware is that ransomware directly interacts with the user of the affected system. Malware encrypts files or the entire computer. The hacker has control over the computer and demands a ransom. The device remains encrypted until the victim pays the ransom.

If the affected device is part of a network, such as in a company, malware can spread throughout the entire network and encrypt all devices in that network. This can shut down entire companies, hospitals, and universities.

What is Ransomware - Definition

What is the difference between Ransomware and Malware?

Most Common Malware Attacks 2019

Malware is a general term used for all programs that harm a device. Therefore, both viruses and ransomware are malware. Ransomware is a type of malware that spreads during activation and encrypts files on a network of infected computers. The device's encryption is only resolved by the hacker when the ransom is paid.

Is Ransomware a Virus?

No, ransomware is not a virus. Although both viruses and ransomware are malware, they are different. Viruses infect data and replicate themselves. Ransomware encrypts files. Therefore, the term "cryptovirus" is not entirely related to malware.

What is Cryptolocker / Cryptotrojan?

Cryptolocker is part of the ransomware family. Its aim is to obtain a ransom from the victim. Cryptolocker infects documents and forces the victim to pay a ransom.

Ransomware attacks carried out by crypto trojans can have serious (financial) consequences for companies. Crypto trojans have threatened the existence of some companies and even driven them to bankruptcy in certain cases. A perfect fear scenario: An employee of a company catches a crypto trojan on their work computer. The malicious software spreads throughout the company network quickly.

How big is the threat of ransomware?

Damages Caused by Ransomware

The threat of ransomware is much greater than it seems. Especially companies must be alert against phishing emails. By 2018, cyber criminals had already stolen eight billion euros. A significant amount, but even more was lost in 2019: damage caused by attacks that year increased by more than three times compared to the previous year, reaching about 24 billion euros.

What is the reason for this rapid increase in successful ransomware attacks? Cyber criminals have found the right niche. Advanced techniques and a bit of information about company employees (social engineering) allow hackers to infect a company's IT infrastructure with a simple phishing email. Hospitals have been the most frequent victims of encryption attacks.

How does Ransomware work?

It usually starts with a classic phishing email that lures users into downloading a malicious file. In most cases, the infection occurs through a tested PDF, DOC or XLS file. By opening the malicious file, the criminal has overcome the most important barrier. The installation on the relevant system takes place. It should be noted that the ransomware can work independently of activation. The ransomware attack can be prepared this way, but it can also be initiated later. The actual damage begins as soon as the ransomware is activated: encryption process begins. Individual files in a system or even several systems in a company network can be encrypted. From this point on, the user can no longer access specific files or even the entire computer. They lose complete administrative rights. Control is in the hands of the hacker.

After everything is encrypted, a notification appears on the victim's screen. Here, the hacker demands a ransom to remove the ransomware. Once this process is complete, the hackers only need to wait for the victim to pay the ransom. Linking the ransom demand to a final delivery date is an effective way for cyber criminals to increase pressure on victims. If the system owners do not make a payment by the final delivery date, the ransom demand may increase or the deletion process may start.

Ransomware attacks can cause significant damage, especially to companies. Experts and authorities generally advise against paying the ransom. In most cases, victims have no choice but to hope that the hackers will be well-behaved after payment. Usually, the decryption process is not carried out even after the ransom is paid.

How can you protect yourself against ransomware?

To protect yourself from ransomware, companies should be proactive and develop a cybersecurity plan against malicious software. Since detecting and combating ransomware is very difficult, different protection mechanisms should be used. The most important protection is training and sensitizing employees. Only those who know that ransomware exists and how it progresses can detect these types of attacks. Since the email inbox is one of the classic entry points for malicious software, a good spam filter should block or at least quarantine all executable files, zip files, and MS Office document macros. Hornetsecurity offers a solution that filters these threats with spam and virus filters before the email is delivered. Continuously improving these filters helps prevent increasingly professional attack tools and methods.

Eighteen different virus scanners with one of the highest detection rates (99.99%) control email traffic. A packaged and unrecognizable contaminated attachment is identified by Hornetsecurity's virus scanner and classified as spam.

Advanced Threat Protection takes it one step further and reliably detects various unknown types of malicious software in addition to ransomware attacks. Hornetsecurity Advanced Threat Protection (ATP) offers solutions on a broad basis. These include URL rewriting and URL scanning.

If an attack is successful, having up-to-date backups is essential. This way, an uninfected older version can be loaded. This keeps data loss as low as possible. Backups can be done manually or automatically. A cloud solution would be a great option for companies to back up data.

Ransomware attacks usually use email. Well-camouflaged emails reach the target company employee's computer as PDF, EXE or JPEG files. In most email clients, the display of file extensions is disabled by default, so users generally cannot identify the format of the file at first glance.

Unwittingly, infected files are opened and ransomware is executed. Therefore, it is important to enable the display of file extensions in your email client settings.

Closing security vulnerabilities is also very important. Microsoft's Remote Desktop protocol is often used as a security vulnerability. This feature allows ransomware to spread within local networks in isolated cases. In this way, the malicious software spreads rapidly across the network. System updates are also essential. The older the software, the more entry points are known and can be exploited. If you're still using Windows 7 or even Windows XP, you shouldn't be surprised if your computer is infected and encrypted. That's why WannaCry used a vulnerability in older Windows systems (EternalBlue). Many companies ignored it. Patches or updates were not applied. This resulted in many successful ransomware attacks on companies.

Are there ransomware scanners available?

If ransomware is already on the computer, it usually spreads quickly. If the ransomware has not yet been activated, an up-to-date antivirus program can help. However, the most logical solutions are those that detect ransomware before it reaches the computer. Classic antivirus programs like GDATA, which protect against all types of malicious software, can also help here. However, if protection against phishing emails is in question, an extended spam filter should be used. In this case, for example, a ransomware prevention scanner such as Hornetsecurity's cloud solution Advanced Threat Protection can be helpful. The service protects against attacks using ransomware such as Locky, Tesla or Petya, filters phishing emails and prevents fake threats. Hornetsecurity ATP uses various detection mechanisms to achieve this: in addition to sandboxing, URL rewriting and URL scanning are also used. Freezing, i.e., the "freezing" of suspicious emails, is also part of Hornetsecurity ATP.

How Advanced Threat Protection Works

How is Ransomware removed?

Once ransomware has entered and infected the computer, there is usually no good exit path. Either you pay the ransom (which police advise against) or you reinstall the computer (with the hope of having an updated backup). However, there are decryption tools for some ransomware attacks. All you need to do is visit the website https://www.nomoreransom.org/crypto-sheriff.php?lang=en. No More Ransom provides decryption for over 50 different types of ransomware.

What types of ransomware are there?

There are basically two different types of ransomware. Crypto ransomware encrypts files to prevent users from accessing them. Locker ransomware keeps the user out of their computer, so they cannot access it. There are also subtypes of these two variants. Scareware is a fake software that claims to find non-existent errors and problems on your PC. The software demands money to solve the problem. Scareware can also lock your computer (lockscreen ransomware). Leakware, also known as Doxware, blackmails users with claimed data leaks. If the user does not pay, the data will be published, threatening Leakware.

The Mutation of Ransomware Emotet

An example of a ransomware attack – Emotet

Emotet is one of the best-known variations of ransomware and has even been featured in daily media. Our Security Lab closely examined Emotet and examined it. You'll learn exactly how Emotet works on a detailed knowledge base page:

Read More

Ransomware risk for companies

The threat of ransomware to companies is very high. If a personal computer is infected by ransomware, it's annoying but generally not a reason for bankruptcy. However, if a company computer is infected by a virus, it can lead to the company's bankruptcy. Ransomware usually spreads throughout the entire network and infects all devices in that network. Result: All companies can no longer operate. Files are lost, working hours are lost, business cannot continue. In a 15-minute article, IT expert Dr. Yvonne Bernard explains in detail how ransomware like Emotet can destroy and eliminate a company (The video is in German).

Which ransomware are used in 2020?

We are at the beginning of 2020 and the first ransomware wave is still going full speed. Daily reports about Greta Thunberg and Fridays for Future are also being used by criminals. Emails are sent in the name of the young activist. The Hornetsecurity Security Lab has seized emails where cyber criminals claim to be holding a large demonstration in favor of climate protection and are asking recipients for support. It is claimed that the time and address of the global attack are in the attached file. When the recipient opens the attachment, an encrypted document appears. The user is asked to edit and activate the content of the document. After this instruction, a macro that downloads malicious software is executed.

Should I pay the ransom for a ransomware attack?

No, experts and investigating authorities advise against paying the ransom. In most cases, data is not decrypted even after payment and the computer remains unusable. Therefore, ransomware prevention solutions should be used and preventive measures should be taken to ensure that paying the ransom is not an option in the first place.

Source: What is Ransomware? How can you protect yourself against ransomware? (hornetsecurity.com)