responding to ransomware - nymissa · ransomware is getting more sophisticated, and shifting to an...

23
X by Invincea Responding To Ransomware

Upload: others

Post on 22-Jul-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

X by Invincea

Responding To Ransomware

Page 2: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

Ransomware NightmaresX by Invincea

Ransomware is getting more sophisticated, and shifting to an enterprise threat

Page 3: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

Ransomware NightmaresX by Invincea

Page 4: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

To Pay Or Not To Pay?X by Invincea

Your money or your files?

Page 5: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

Argument for payingX by Invincea

“The ransomware is that good... To be honest, we often advise people just to pay

the ransom.”

-Joseph BonavolontaFBI Assistant Special Agent in Charge of the Cyber and

Counterintelligence Program Quote from 2015

Page 6: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

Money or Files?X by Invincea

50% of ransomware victims have paid

40% said they would pay if they were hit with ransomware

Source: BitDefender

Page 7: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

A RANSOMWARE

ANECDOTE

Page 8: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

Argument against payingX by Invincea

•We don’t negotiate with terrorists

•Paying incents attackers to keep using ransomware

Page 9: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

Argument against payingX by Invincea

"The FBI doesn’t support paying a ransom in response to a ransomware attack.”

-James TrainorFBI Cyber Division Assistant Director

Quote from April 2016

Page 10: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

Criminals Are UnreliableX by Invincea

"Paying a ransom doesn’t guarantee an organization that it will get its data back—we’ve

seen cases where organizations never got a decryption key after having paid the ransom.”

-James TrainorFBI Cyber Division Assistant Director

Quote from April 2016

Page 11: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

Average price of ransomware

Some ransom demands are as high as $50K

True cost of a large ransomware attack

Amount extorted by CryptoWall since 2015

True CostX by Invincea

Page 12: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

Ransomware Trends

Page 13: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

TargetsX by Invincea

Critical Infrastructure:

• Healthcare

• Government

• Law Enforcement

• Energy

• Financial

1

3

2

Page 14: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

Weaponized Office documents

Malicious email links

Unauthorized programs

Malvertising

Top Infection MethodsX by Invincea

Page 15: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

TrendsX by Invincea

Ransomware and Weaponized Docs (which can spread ransomware) increased in May

Page 16: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

Constant State of InnovationX by Invincea

•2-for-the-price-of-1 Ransomware: Ransomware + DDOS

•Hash Factory: Ransomware changes hash every 15 seconds

•Server-side Ransomware: Beyond the desktop

•Viral Ransomware: Spreads like a virus

Page 17: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

Recommendations

Page 18: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

• TeslaCrypt (v3.0-v4.2)

–ESET was able to get the decryption key by ASKING attackers for it. Seriously.

• Decryption tools are available for:

–777

–Xorist

–8Lock8

–GhostCrypt

Limited Decryption AbilityX by Invincea

Page 19: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

Common Advice Only Helps So MuchX by Invincea

•Keep Your AV up-to-date

•Filter your email

•Patch everything all the time

•Careful what you click

"Users will open attachments, they will visit sites that are infected, and when that happens, you just need to make sure that your security technology protects you.”

-Anup GhoshCEO, Invincea

Wired Magazine, May 2016

Page 20: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

Our RecommendationsX by Invincea

•Deploy anti-malware prevention

•Behavioral monitoring

•Isolation

•Back it up!!!!

"network shares are as at risk as your desktop system in a ransomware infection. If the

backups are done offline, and the backup is not reachable from the machine that is infected,

then you’re fine.”

-Anup GhoshCEO, Invincea

Wired Magazine, May 2016

Page 21: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

Business Continuity & Disaster RecoveryX by Invincea

• Develop a business continuity plan for what happens if you loose access to your data or systems

• Backup your data and airgap it from your primary network

–Put controls in place that will allow you to rapidly your recover files

• Have an IR plan in place with access to 3rd parties that can assist

Page 22: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

Final RecommendationX by Invincea

“Don’t pay unless you absolutely have to!”

-Yours trulyQuote from … today

Page 23: Responding To Ransomware - NYMISSA · Ransomware is getting more sophisticated, and shifting to an enterprise threat. Ransomware Nightmares ... 50% of ransomware victims have paid

THANK YOU

www.invincea.com