Endpoint

10/25/2016
03:00 PM
Steve Zurier
Steve Zurier
Slideshows
Connect Directly
Twitter
RSS
E-Mail
50%
50%

7 Scary Ransomware Families

Here are seven ransomware variants that can creep up on you.
Previous
1 of 8
Next

Image Source: Trend Micro

Image Source: Trend Micro

As the season of evil witches, ghosts, goblins, and ghouls approaches, it’s time to be on guard. But security managers face scary prospects year-round, especially as new strains of ransomware escalate. And ransomware variants are getting more pervasive - and creepier - than ever. 

The FBI says that from Jan. 1, 2016 to June 30, 1,308 ransomware complaints have been reported, totaling $2,685,274 in losses. 

And it appears that the ransomware “business” will continue to grow for cybercriminals. Ed Cabrera, chief cybersecurity officer at Trend Micro, says his research team tracked 29 ransomware families last year, and this year is on pace to track well more than 100 variants.

"These ransomware attacks are much different than traditional data breaches in that they go right after the victim," Cabrera says. "It's not like in the past where data was exfiltrated and sold to other criminals."

Most of these ransomware variants encrypt a person’s machine and try to extract a ransom, typically several hundred dollars. What keeps security managers up at night is that ransomware has made its way to the enterprise. The $17,000 ransom paid by Hollywood Presbyterian Hospital earlier this year is of particular note. But new variants attack entire databases and servers – and they now use familiar chat features to make it easier for the victims to pay the ransom.

As a cautionary tale for the season, here are seven of the scariest ransomware variants. This list is based on a consensus drawn from interviews with Trend Micro's Cabrera; Chris Day, CISO of Invincea; and Bryan Lee, threat intel analyst for Unit 42 at Palo Alto Networks.

 

 

Steve Zurier has more than 30 years of journalism and publishing experience, most of the last 24 of which were spent covering networking and security technology. Steve is based in Columbia, Md. View Full Bio

Previous
1 of 8
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
lorraine89
50%
50%
lorraine89,
User Rank: Ninja
11/1/2016 | 8:52:13 AM
Cyber security
As holiday season nears, it is the by far most lucrative season for hackers and keyboard warriors to sneek into people's data for their monetary gains. Protect IP address with genuine vpn server like PureVPN that offers encryted online connection and those with strict no logs policy. 
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
10/27/2016 | 12:15:16 PM
Re: Jigsaw
Wow.  What a (scarily, saddeningly) clever way to still get something out of those who have had the foresight to back up their data (and, accordingly, otherwise wouldn't pay to get ransomed data unlocked).
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
10/27/2016 | 12:12:27 PM
Re: Jigsaw
@Dr.T: On top of that, it's a way for them to "double-dip."  First, pay up to get your data back.  Next, pay up so that no one else gets it.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
10/27/2016 | 12:11:24 PM
Re: Ransomware; new industry
@Dr.T: A big contributing factor to why this "industry" developed has to do with spam.  After the huge spam crackdown a few years ago, black-hatters had these botnets and malware under their control...but spamming was no longer particularly profitable or worth the risk for them.  Accordingly, they had to come up with new business models.

Enter ransomware.

Ironically enough, if we had left the spammers alone, we might not have seen this particular "innovation."
Shantaram
50%
50%
Shantaram,
User Rank: Ninja
10/26/2016 | 6:01:27 PM
Re: 192.168.l.l
It's really impressive

thx
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
10/26/2016 | 3:17:20 PM
Re: Jigsaw
"... doxware ..."

I was reading about this the other day, obviously when the victim does not pay for the old files hackers still want to get someting out of it. 
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
10/26/2016 | 3:14:54 PM
Re: Jigsaw
"... As companies grow aware of the threat of ransomware ..."

I say they are not. It looks like companies are willing to pay to get the data back instead of investing a good backup system.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
10/26/2016 | 3:12:32 PM
Re: Jigsaw
"... Jigsaw's scheme is particularly brilliant  ..."

there might be better ways but it is impressive.

 
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
10/26/2016 | 3:09:30 PM
Re: candid photographer
" ... Excellent blog  ...":

Agree. Good information.
Dr.T
100%
0%
Dr.T,
User Rank: Ninja
10/26/2016 | 3:08:27 PM
Ransomware; new industry
I could not believe that there has been a new instruct created out of cyber-attacks. We are not in the right track at all.
Page 1 / 2   >   >>
Want Your Daughter to Succeed in Cyber? Call Her John
John De Santis, CEO, HyTrust,  5/16/2018
Don't Roll the Dice When Prioritizing Vulnerability Fixes
Ericka Chickowski, Contributing Writer, Dark Reading,  5/15/2018
Why Enterprises Can't Ignore Third-Party IoT-Related Risks
Charlie Miller, Senior Vice President, The Santa Fe Group,  5/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "Security through obscurity"
Current Issue
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-11311
PUBLISHED: 2018-05-20
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials.
CVE-2018-11319
PUBLISHED: 2018-05-20
Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potentially the root). This improper handling might be exploited for arbitrary code execution via a malicious gcc plugin, if an attacker has write access to ...
CVE-2018-11242
PUBLISHED: 2018-05-20
An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypted and have cleartext that might lead to sensitive information disclosure, as demonstrated by data/com.makemytrip/databases and data/com.makemytrip/Cache SQLite database files.
CVE-2018-11315
PUBLISHED: 2018-05-20
The Local HTTP API in Radio Thermostat CT50 and CT80 1.04.84 and below products allows unauthorized access via a DNS rebinding attack. This can result in remote device temperature control, as demonstrated by a tstat t_heat request that accesses a device purchased in the Spring of 2018, and sets a ho...
CVE-2018-11239
PUBLISHED: 2018-05-19
An integer overflow in the _transfer function of a smart contract implementation for Hexagon (HXG), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized increase of digital assets by providing a _to argument in conjunction with a large _value argument, as exploited in the wild in ...