Anatomy of a Ransomware Attack!

Words
290
Reading
2 min
Listen
Play
9y

Anatomy of a Ransomware Attack!

There are aspects of ransomware that I've been wondering about, and of which I would like your comments on:
1. After paying ransomware, how many victims actually receive what they paid for?
2. FBI statistics point to a high percentage of people paying up, why?"
3. In some versions, because of the randomness in the encryption, not even the attacker can restore the files, so why pay?
4. Is the narrative in the Cisco video below accurate?

Ransomware was recently on my mind and so wanted to share some thoughts about the matter. To get some definitions out of the way, essentially it is malicious software that aims to extort something from the victim (usually Bitcoin). There are two popular forms, one that threatens to publish private data and the other that threatens to block access to one's own data.

In the second version of ransomware, files are often encrypted during runtime by leveraging well known vulnerabilities. These vulnerabilities, more often than not, already have patches available - we are mostly talking about unpatched machines.

The effects and consequences quite known:

Temporary or permanent loss of sensitive or proprietary data
Financial losses incurred to restore systems and files
Potential harm to an organization's reputation
Disruption of regular operations

ANATOMY OF AN ATTACK


Published last year, it still gives an interesting narrative...

An interesting aspect of the Petya version of ransomware is that even if you pay up, you may still be without your files. According to the July 1st US Homeland Security bulletin US-CERT TA17-181, based on the encryption method used it is not likely that files can be restored even by the attacker. This version also attempts to crawl the local subnet (network) to infect other unpatched systems.

Anatomy of a Ransomware Attack! | Ecency