A bit of background...
Ransomware is a form of malware that encrypts private information and
demands payment in order to decrypt it.
- CryptoLocker first appeared in 2013
- New variants emerge all-too-regularly
- Current wave has roots in the early days of Fake Anti-Virus
- Locky is one of the newest flavors to menace internet users
- Common ransom demands for USD 200 – 500 but run as high as thousands of dollars
- Technology used changes rapidly
- Office documents with macros enabled are often used to dupe users into letting the trojans in
Although Anti-Virus programs are slowly becoming more effective at stopping these threats, users being duped (or not having safeguards in place) often allow the threats to invade and lock down critical data.
How does RANSOMWARE get in?
#1 SPAM
- from plausible senders
- phishing attachments (i.e. invoices, delivery notices, bank imposters, etc.)
- Office attachments that enable macros (word, excel, etc.)
#2 Exploit kits
- Black market tools used to exploit unknown vulnerabilities (zero-day or patient zero attacks)
- Browser vulnerabilities
When attachments are opened by the user, the malicious code downloads and executes the ransomware payload.
BEWARE OF THINGS THAT MAY LOOK LIKE THESE EXAMPLES:
What RANSOMWARE DOES TO YOUR COMPUTER: