Education
Ransomware: Definition and types
Ransomware is a growing problem for governments and industries across the globe. Read more to find out what it is and who is affected.
The world is becoming ever more reliant on the digital landscape. Due to evolving needs in every industry, there has been growing focus on moving resources and business operations to a digital landscape. Due to this shift to the digital landscape, the threat of ransomware has grown in recent years. In 2023, the average cost of a ransomware attack globally was over 5 million US dollars (1). The estimated overall cost of ransomware attacks in 2023 was almost 30 billion US dollars (1). This makes a ransomware attack a serious threat to organizations everywhere. According to the ENISA Threat Report for 2023, ransomware and DDoS are the biggest threat to organizations within the EU (2).
Ransomware Definition: Malicious Software
Ransomware is defined as malicious software that is installed on a system or network that encrypts files and requires the victim to pay a ransom for the files and system to be decrypted. Ransomware will encrypt all files on a system, or will encrypt the whole network entirely, preventing access to the files and network. Once the ransom has been paid to the group responsible, they will send a decryption key to the organization so the files and network can be released and accessed once more. However, the long-term effects of a ransomware attack can last for months or even years, with many organizations still experiencing system or network problems after the decryption was used.
Types of Ransomware: The most common types
There are several types of ransomware that exist, each with its own methods and targets. Some of the most common types include:
- Crypto Ransomware: This type encrypts files, making them unusable until a ransom is paid. Groups like REvil and Conti have been known for deploying such attacks.
- Locker Ransomware: Instead of encrypting files, locker ransomware locks the victim out of the entire system, rendering it unusable. The DarkSide group is notorious for this type of attack.
- Scareware: This type of ransomware displays fake warnings or alerts, tricking users into paying to remove non-existent threats. Often this type of ransomware will trick users into installing the ransomware on the system by using adware.
According to the ENISA Threat Report, the two most active ransomware groups in Europe are LockBit 3.0 and PLAY. LockBit was responsible for half of the recorded incidents in the first half of 2023, making them the greater threat in the European landscape. The main industries they targeted were in manufacturing and services, and the estimated number of victims is 224 (2). PLAY, on the other hand, focused on digital service providers and the services industries, with the estimated number of victims being 56 (2).
How Ransomware Attacks: Methods used to install ransomware
Ransomware can be sent through numerous ways, be it online or in physical form. However, before the attack can begin, the threat actor needs to gain access to the device or system to take control. Some common ways ransomware is sent include:
- Phishing E-Mails: This includes sending an E-Mail that appears legitimate and making the user click a suspicious link that installs the ransomware.
- Social engineering: This includes relying on human behaviors to trick users into disclosing confidential information to the threat actors.
- Adware: This involves ads that appear legitimate but are malicious. Once the user clicks on the ad the device will be infected with ransomware.
- Malware: This involves tricking users into downloading malicious software that installs ransomware on the device or system.
Who is Affected?
Ransomware does not discriminate; it can target individuals, small businesses, large corporations, and even government agencies. The impact can be devastating, leading to financial losses, compromised data, and damage to the reputation of the organization.
The most popular ransomware attack of 2023 happened to the MGM Resort in Las Vegas. This hotel chain fell victim to a ransomware attack due to a social engineering attack. The threat actors called the hotel front desk claiming to be an Executive and requesting access to the network. Once the threat actors gained access, they promptly locked down the network. Visitors could not gain access to their rooms, visitors could not be checked in or checked out, the elevators stopped working, and more. The hotel chain was forced to pay the ransom, but the result of this attack was financial losses and reputational damage, and they are still experiencing technical problems months after the attack occurred.
How to Protect Yourself: Ensure strict security measures are in place
There are various steps to follow to prevent falling victim to a ransomware attack. Some of them include:
- Keep all software updated: Software updates plug vulnerabilities in the software and update security.
- Backup data: Regularly backup data to the cloud and on a system that is separate to the network.
- Use antivirus software: Antivirus software will identify potentially malicious software and quarantine it.
- Keep an asset inventory: Create and maintain an inventory of all assets within an organization to allow them to be identified an isolated if infected.
- Implement awareness training for staff: Educate staff to ensure they are aware of any potential risks and know the procedures to follow in case of any suspicious activity.
- Use multi-factor authentication: This will prevent unauthorized access to systems and networks.
Conclusion: Ransomware is a threat to organizations and individuals both
Ransomware is a serious threat that continues to evolve, with cybercriminals targeting individuals and organizations worldwide. Knowing that ransomware is malicious software that can only be removed with a decryption key can ensure you are prepared in case of any suspicious activity within the organization. Understanding the three most common types of ransomware, how ransomware enters organizations and who is affected is essential in safeguarding against these malicious attacks. By staying vigilant, keeping software updated, and ensuring good cybersecurity practices, you can reduce the risk of falling victim to ransomware and its costly consequences.
Sources
- IBM report: What is Ransomware? | IBM
- ENISA Threat Landscape 2023.