Knowing About Ransomware - the Differences Between Cryptographic Trojans | Antivirus Software

 
Knowing About Ransomware - the Differences Between Cryptographic Trojans | Antivirus Software

What is ransomware?

Ransomware is a type of malware (malware) that is used by cybercriminals. If a computer or network is infected with ransomware, that virus blocks access to the system or encrypts existing data. The cybercriminals demand a ransom amount from their victims in exchange for decrypting the data! And to protect against infection with ransomware, always be careful and install a security app. And for those who fall victim to malware attacks, have three choices after an infection: they either pay the ransom, try to remove the malware, or restart the device. Places of entry for attacks that cryptographic Trojans typically exploit include Remote Desktop Protocol, phishing emails, and application security vulnerabilities. Thus, ransomware attacks target both individuals as well as companies.


Knowing about ransomware - the basic distinguishing signs

In general, there are two very common types of ransomware:


Ransomware for the device. This type of malware blocks access to basic computer functions, so you may, for example, not be able to access your device's desktop with the mouse and keyboard partially disabled, and this allows you to continue interacting with the window that contains the ransom request to pay the required amount. , But you cannot do anything else on the computer. But there is good news about this type of ransomware, which is that it usually does not target the very important files, rather what it does is not allow you to use it only, so it is unlikely to destroy your data completely.

Ransomware for files. The goal of this type of ransomware is to encrypt your important data, such as your documents, photos, and videos, but it does not disrupt the basic functions of a computer. This causes most users to panic as they can see their files but cannot access them! And what causes more panic is that the developers of this malware often add a countdown to the ransom demand with a message like this: "If you don't pay the ransom amount before this time, all your files will be deleted." Given the number of users neglecting to create backup copies of their important files on a cloud service or on an external storage device, this type of ransomware can cause a lot of damage, thus increasing the number of victims who pay the ransom required simply to recover their files.

Locky, Petya, and more.

Now you know what ransomware is and the two main types of it, and now it's time to find out some popular examples that will help you determine the risks ransomware poses to you:


Locky

Locky is a ransomware program that was first used in attacks in 2016 by a group of organized hackers, and that virus encrypted more than 160 types of files and was spread through fake emails with infected attachments. And users fall victim to these fake messages and install ransomware on their computers, and this method of spreading is called phishing, and it is one of the methods known as social engineering. Locky targets the range of file types often used by designers, developers, engineers, and testers.


WannaCry

WannaCry is ransomware whose attacks spread to more than 150 countries in 2017! This virus was originally designed to exploit a security vulnerability in the Windows operating system and was the invention of the US National Security Agency and a leak of the Hacker and Hacker Group Shadow Brokers. WannaCry infected 230,000 devices around the world, and its attacks struck a third of all government hospitals in the British Kingdom, causing losses estimated at up to 92 million pounds! Users were blocked and required to pay a ransom in bitcoin. The attacks of this virus revealed the problem of working on an outdated system because the hackers were exploiting a vulnerability in the operating system even though there had been a patch for it long before the attack. And the financial losses caused by the WannaCry virus are almost 4 billion USD!


Bad Rabbit

Bad Rabbit is ransomware that first started its attack in 2017 and spread via what's known as unintended download, or drive-by. In carrying out these attacks, insecure sites were used, and these attacks occurred when the user visited a real site without knowing that that site had been penetrated by fraudsters and injected with the virus. Most of these attacks do not need anything except for the user to open a page in which this virus was injected, in which case running an installation wizard that contains the malicious program disguised leads to infection. This is known as a malware dropper. Bad Rabbit prompts users to run an Adobe Flash installation wizard, for example, but this is a bogus install, thus infecting the computer with malware.


Ryuk

Ryuk is a cryptographic trojan horse that spread in August 2018, and it was disabling the recovery function for Windows operating systems, and this was making it impossible for users to recover encrypted data without an external backup, and it was encrypting hard drives on the network. This made the impact of the virus huge, and many of the targeted US institutions paid the required ransom amounts, and the total estimated losses reached more than the US $ 640,000.


Shade / Troldesh

The Shade or Troldesh virus is a ransomware program that spread in 2015, and it was spreading via spam emails containing infected links or attachments. The interesting thing was that the Troldesh virus attackers were communicating directly with their victims via e-mail, and the victims with whom they had a "good relationship" were getting discounts! However, this behavior was the exception, not the rule.


Jigsaw

Jigsaw is a ransomware program that started its attacks in 2016, and this virus gets its name from an image that is shown in the popular horror movie series Saw. With every additional hour that passed without paying the ransom, the Jigsaw virus was deleting more files, and this was making the user feel as terrified as in the movie because of the pressure that the image puts on users.


CryptoLocker

CryptoLocker is a ransomware program that first appeared in 2007 and spread through infected email attachments. This virus was looking for important data on infected computers and then encrypting it, and it infected nearly half a million computers. Law enforcement agencies and security companies eventually managed to control a global network of hacked home computers that were being used to spread the CryptoLocker virus, and this allowed those agencies and companies to intercept the data that was being sent over the network without criminals noticing it, and finally, they were able to create a portal Electronically, victims can obtain a key to unlock their data so that they can recover their data without the need to pay a ransom to the criminals.


Petya

Petya (completely different from ExPetr) is a ransomware program that first started its attack in 2016, then was republished by GoldenEye in 2017. This virus was not encrypting certain files, it was encrypting the entire hard drive of the victim, and it was doing this by encrypting the file table The main file (Master File Table) was thus impossible to access the files on the hard drive. The Petya ransomware spread to corporate HR departments via a fake app that was located in an infected Dropbox cloud service link.


There is a newer version of Petya called Petya 2.0, and it differed from it in some key points in how the attacks were carried out, but both were very dangerous to the devices.


GoldenEye

The Petya virus came to life again through the GoldenEye virus, and this caused a global ransomware attack in 2017, GoldenEye is known as the "deadly brother" of the most famous virus, WannaCry, and has infected more than two thousand targets, including a group of the largest oil producers in Russia as well as Several banks. And suddenly events turned and tensions when the GoldenEye virus forced the Chernobyl nuclear power plant to manually check its radiation level after they were prevented from using their Windows computers.


GandCrab

GandCrab is a more specialized and targeted ransomware program as it was threatening to expose the victims' porn habits, and it was claiming that it managed to hack the victim's webcam and ask him to pay a ransom in exchange for not disclosing anything. If the ransom was not paid, a very embarrassing clip for the victim would be posted online. The GandCrab ransomware first appeared in 2018, and it has continued to evolve into multiple other versions. As part of the "No More Ransom" initiative, security service providers and government executives have developed a ransomware decryption tool to help victims recover their sensitive data from the GandCrab virus.


B0r0nt0k

B0r0nt0k is a file encryption ransomware tool focused specifically on Windows and Linux-based servers. This ransomware encrypts files on the Linux server and adds the extension ".rontok" to the end of the file name. This way, it not only poses a threat to files, but it also makes changes to device startup settings, disables device functions and applications, and adds entries to registry, files, and programs.


Dharma Brrr ransomware program

Brrr is the new version of Dharma ransomware, this type that scammers install manually after hacking desktop services connected to the Internet; As soon as the criminal activates the ransomware, he begins encrypting the files he finds, and the encrypted data gets the file extension ".id- [id]. [Email] .brrr".


FAIR RANSOMWARE ransomware

FAIR RANSOMWARE is a ransomware program that aims to encrypt data, and it does so using a powerful algorithm whose job is to encrypt all of the victim's documents and private files, and then add the extension ".FAIR RANSOMWARE" to all the files that have been encrypted.


MADO ransomware program

MADO is another type of ransomware that encrypts files, after which it adds the .mado extension "to the last names of the files that are being encrypted, so they can no longer be opened."


Ransomware attacks

As we discussed above, ransomware searches for targets throughout life, and the ransomware that is requested usually ranges from $ 100 to $ 200, but some attacks require much more than that, especially if the attacker knows that the blocked data represents a significant financial loss to the company. Those have been attacked, so cybercriminals can make large sums of money using these methods. In the two examples below, the victim of the cybercriminal is or is more unique than the type of ransomware used.


WordPress ransomware

WordPress ransomware, as its name suggests, targets WordPress site files, and the victim is blackmailed and asked for a ransom, as is usual with traditional ransomware. The higher the demand for your WordPress site, the more likely it will be attacked by cybercriminals with ransomware.


Wolverine case

Wolverine Solutions Group is a health service provider that was the victim of a ransomware attack in September 2018, and this malware encrypted a large number of company files and made it impossible for many employees to open the files. Fortunately, however, expert analyzers were able to work on decrypting and restoring the data on October 3. But this does not negate the fact that much patient data was compromised in the attack. Names, addresses, medical data, and other personal information could have fallen into the hands of cybercriminals.


Ransomware as a service

Ransomware as a service gives cybercriminals with low technical capabilities the opportunity to implement ransomware attacks, as malware has been made available to buyers, and this means less risk and higher profit for programmers of such applications.

Make sure you have an up-to-date antivirus program running. A product like Protegent360 Antivirus Software protects your computer and blocks viruses and malware in real-time.


Summary

Ransomware attacks come in many different shapes and come in all shapes and sizes. Attack introduction methods are also an important factor in the types of ransomware used. To estimate the size and extent of an attack, it is always necessary to think about what could be lost or what data could be deleted or published. Regardless of the type of ransomware program, creating a backup copy of data in advance and correct handling of security applications can drastically reduce the severity of an attack.


 

Comments

Popular posts from this blog

Why Not to Restart Your Computer if It Is Infected With the Ransomware | Total Security

What Is a Ransomware Virus and How Do You Protect Your Computer From It | Total Security

What is a zero-day threat? Free Antivirus Software