Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Saturday, December 17, 2016

How do you get Ransomware? (Level 1)



How do you get Ransomware?

Most malicious software utilizes one of the most insecure and insecure-able aspects of the computing environment. The User. Yes, you and your coworkers are the most vulnerable part of your network.  Social engineering, in the form of “Phishing” and it’s evil son “Spear-Phishing”.  I’ll save the deeper dive on those for another post, but just think of them as attacks designed to get you to click on a file or link that you shouldn’t.  An email with an attachment from someone you don’t know is by far the most common Ransomware method of attack.  HR departments will get an email with an attachment that is titled “resume.doc”, or Sales will receive an email with an attachment that is titled “PurchaseOrderRush.doc”.  

2016-12-17
MDux

Thursday, December 15, 2016

Ransomware Data Points (Level 2)

Ransomware Data Points

In the next five days I will walk through some basics of Ransomware. This post lists out some data points from Kaspersky (with a few exceptions).  This should scare you.
If you're not at least alarmed, then you definately need to read the next few posts!

Ransomeware Data Points:

Statistics from Kaspersky Labs (Security software company)
2016 gave us:
758,044,650 attacks launched from online resources located all over the world
62 new ransomware families
          (most malware will have an original, and several versions.  Those together are called a family as they are all related)
11 fold increase in modifications to various malware from Q1 to Q3.
1 in 5 SMBs that were infected AND paid the ransom, never got their data back.
1 in 5 businesses worldwide suffered and IT security incident as a result of a ransomware attack.
42% of SMBs were hit with ransomware from Oct 2105 to Oct 2016
32% paid the ransom
67% of those affected lost part or all of their corporate data.  1 in 4 spent several weeks to restore access
97% of malware is unique to a specific endpoint, rednering signature-based security virtually useless
98% of Microsoft Office- targeted threats use macros (Microsoft, 2016)
600%+ incrase in attachement-based vs URL deliverd malware attacks from mid 2015 to 2015 (Proofpoint, 2015)
6000% increase in ransomware from 2015 to 2016 (IBM, 2016)

Who got hit, by sector?

Education – 23%  (23% of the Education sector was hit by Ransomware)
IT /Telcom – 22%
Entertainment/Media – 21%
Financial Services - 21%
Construction - 19%
Government/Public Sector/Defense – 18%
Manufacturing – 18%
Transport – 17%
Healthcare – 16%
Retail/Wholesale/Leisure – 16%

2016-12-15
MDux