{"id":35299,"date":"2019-07-18T18:29:35","date_gmt":"2019-07-19T01:29:35","guid":{"rendered":"https:\/\/www.enxmag.com\/twii\/?p=35299"},"modified":"2019-07-18T18:29:38","modified_gmt":"2019-07-19T01:29:38","slug":"effects-of-ransomware-dont-end-with-the-ransom","status":"publish","type":"post","link":"https:\/\/www.enxmag.com\/twii\/feature-articles\/2019\/07\/effects-of-ransomware-dont-end-with-the-ransom\/","title":{"rendered":"Effects of Ransomware Don\u2019t End With the Ransom"},"content":{"rendered":"\n<div class=\"wp-block-image\"><figure class=\"alignleft\"><img loading=\"lazy\" width=\"295\" height=\"233\" src=\"https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2019\/07\/Stu.jpg\" alt=\"\" class=\"wp-image-35300\"\/><\/figure><\/div>\n\n\n\n<p>A Florida city is still struggling to recover from a ransomware attack two weeks after the city paid the ransom, according to the <em>New York Times<\/em>. The attack began after a city employee downloaded a malicious document that arrived in an email.<\/p>\n\n\n\n<p>This document downloaded the Emotet Trojan, which in turn downloaded the Trickbot Trojan. These Trojans were then used to plant the RYUK ransomware within the city\u2019s systems. On June 10th, the ransomware encrypted 16 terabytes (more than 16,000 gigabytes) of information, including more than a century\u2019s worth of digitized municipal records.<\/p>\n\n\n\n<p>A city clerk who has spent years manually scanning these documents for preservation, told the <em>Times<\/em> that it\u2019s still not clear if everything will be recovered. \u201cIt puts us years and years and years behind,\u201d Sikes said.<\/p>\n\n\n\n<p>The victim decided to pay the $460,000 ransom on June 25 after failing to find a workaround. Most of the cost was covered by the city\u2019s insurance provider, with the city paying a $10,000 deductible. Even though the attackers provided the decryption key, the recovery process is taking a very long time.<\/p>\n\n\n\n<p>Mark A. Orlando, the chief technology officer for Raytheon Intelligence Information and Services, told the <em>Times<\/em> that attackers are improving their targeting to increase the chances that a victim will pay ransom.<\/p>\n\n\n\n<p>\u201cThese groups are always trying to find that sweet spot: What is enough someone will consider paying but not so much that they\u2019ll say, \u2018Forget that. It\u2019s easier to rebuild,\u2019\u201d Orlando said. \u201cThis is a situation where that amount is going up, and we have reached a new high-water mark as to what is getting paid out.\u201d<\/p>\n\n\n\n<p>Organizations need to maintain secure backups, but restoring from backups can be a lengthy and expensive process. Make sure you frequently test your restore procedure!<\/p>\n\n\n\n<p>Ideally, the attackers won\u2019t be able to gain a foothold in the first place. New-school security awareness training can teach your employees how to avoid falling for these attacks.<\/p>\n\n\n\n<p><strong>Brand-New Ransomware Simulator Tool Now with Two New Ransomware Scenarios<\/strong><\/p>\n\n\n\n<p>The bad guys are continuing to evolve their approach to evading detection. That\u2019s why we\u2019ve updated our Ransomware Simulation tool \u201cRanSim\u201d to include two new ransomware scenarios! <\/p>\n\n\n\n<p>These new scenarios simulate ransomware strains like GandCrab and Rokku that encrypt users\u2019 files and demands a crypto-ransom in exchange for the keys. <\/p>\n\n\n\n<p>GandCrab was a very active ransomware strain all throughout 2018 as well as since the start of 2019, and it is known for requesting up to $3,000 from its victims to decode encrypted files. While the creators of GandCrab announced in May they were shutting down their operation, make sure your organization is safe from this type of infection before another group takes it over, or worse, you won\u2019t have an option to decrypt your system!<\/p>\n\n\n\n<p>Try KnowBe4\u2019s NEW <a href=\"https:\/\/www.knowbe4.com\/ransomware-simulator\">Ransomware Simulator<\/a> version and get a quick look at the effectiveness of your existing network protection against the latest threats. RanSim will simulate 15 ransomware infection scenarios and 1 cryptomining infection scenario to show you if a workstation is vulnerable to infection. <\/p>\n\n\n\n<p>Here&#8217;s how RanSim works: <\/p>\n\n\n\n<ul><li>100% harmless simulation of real ransomware and <g class=\"gr_ gr_3 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling\" id=\"3\" data-gr-id=\"3\">cryptomining<\/g> infection scenarios <\/li><li>Does not use any of your own files <\/li><li>Tests 16 different types of infection scenarios <\/li><li>Just download the install and run it <\/li><li>Results in a few minutes! <\/li><\/ul>\n\n\n\n<p>This is a <g class=\"gr_ gr_4 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del\" id=\"4\" data-gr-id=\"4\">complimentary<\/g> tool and will take you 5 minutes max. RanSim may give you some insights about <g class=\"gr_ gr_5 gr-alert gr_gramm gr_inline_cards gr_run_anim Grammar multiReplace\" id=\"5\" data-gr-id=\"5\">your endpoint<\/g> security you never expected! <\/p>\n\n\n\n<p><em>This blog originally appeared on <\/em><a href=\"https:\/\/www.knowbe4.com\/\"><em>KnowBe4<\/em><\/a><em>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A Florida city is still struggling to recover from a ransomware attack two weeks after the city paid the ransom, according to the New York Times. The attack began after a city employee downloaded a malicious document that arrived in an email. This document downloaded the Emotet Trojan, which in turn downloaded the Trickbot Trojan. These Trojans were then used to plant the RYUK ransomware within the city\u2019s systems. On June 10th, the ransomware encrypted 16 terabytes (more than 16,000 gigabytes) of information, including more than a century\u2019s worth of digitized municipal records. A city clerk who has spent years manually scanning these documents for preservation, told the Times that it\u2019s still not clear if everything will be recovered. \u201cIt puts us years and years and years behind,\u201d Sikes said. The victim decided to pay the $460,000 ransom on June 25 after failing to find a workaround. Most of the cost was covered by the city\u2019s insurance provider, with the city paying a $10,000 deductible. Even though the attackers provided the decryption key, the recovery process is taking a very long time. Mark A. Orlando, the chief technology officer for Raytheon Intelligence Information and Services, told the Times that attackers are improving their targeting to increase the chances that a victim will pay ransom. \u201cThese groups are always trying to find that sweet spot: What is enough someone will consider paying but not so much that they\u2019ll say, \u2018Forget that. It\u2019s easier to rebuild,\u2019\u201d Orlando said. \u201cThis is a situation where that amount is going up, and we have reached a new high-water mark as to what is getting paid out.\u201d Organizations need to maintain secure backups, but restoring from backups can be a lengthy and expensive process. Make sure you frequently test your restore procedure! Ideally, the attackers won\u2019t be able to gain a foothold in the first place. New-school security awareness training can teach your employees how to avoid falling for these attacks. Brand-New Ransomware Simulator Tool Now with Two New Ransomware Scenarios The bad guys are continuing to evolve their approach to evading detection. That\u2019s why we\u2019ve updated our Ransomware Simulation tool \u201cRanSim\u201d to include two new ransomware scenarios! These new scenarios simulate ransomware strains like GandCrab and Rokku that encrypt users\u2019 files and demands a crypto-ransom in exchange for the keys. GandCrab was a very active ransomware strain all throughout 2018 as well as since the start of 2019, and it is known for requesting up to $3,000 from its victims to decode encrypted files. While the creators of GandCrab announced in May they were shutting down their operation, make sure your organization is safe from this type of infection before another group takes it over, or worse, you won\u2019t have an option to decrypt your system! Try KnowBe4\u2019s NEW Ransomware Simulator version and get a quick look at the effectiveness of your existing network protection against the latest threats. RanSim will simulate 15 ransomware infection scenarios and 1 cryptomining infection scenario to show you if a workstation is vulnerable to infection. Here&#8217;s how RanSim works: 100% harmless simulation of real ransomware and cryptomining infection scenarios Does not use any of your own files Tests 16 different types of infection scenarios Just download the install and run it Results in a few minutes! This is a complimentary tool and will take you 5 minutes max. RanSim may give you some insights about your endpoint security you never expected! This blog originally appeared on KnowBe4.<\/p>\n","protected":false},"author":178,"featured_media":35300,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1650,82,87,88,1638],"tags":[527],"_links":{"self":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/35299"}],"collection":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/users\/178"}],"replies":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/comments?post=35299"}],"version-history":[{"count":2,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/35299\/revisions"}],"predecessor-version":[{"id":35302,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/35299\/revisions\/35302"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/media\/35300"}],"wp:attachment":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/media?parent=35299"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/categories?post=35299"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/tags?post=35299"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}