13
1 6/28/22 Crypto Ransomware: a Real Problem with Real Solutions

Ransomware shuts down your client.. What do you do?

  • Upload
    webroot

  • View
    213

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Ransomware shuts down your client.. What do you do?

1 Tuesday, May 2, 2023

Crypto Ransomware:a Real Problem with Real Solutions

Page 2: Ransomware shuts down your client.. What do you do?

2 Tuesday, May 2, 2023

Agenda

Ransomware’s evolution

Costs of ransomware attacks

How ransomware infects systems

Conclusion

Major threattrends

How to avoid being a crypto ransomware

victim

Page 3: Ransomware shuts down your client.. What do you do?

3 Tuesday, May 2, 2023

Major Threat Trends

Page 4: Ransomware shuts down your client.. What do you do?

4 Tuesday, May 2, 2023

Polymorphic Malware Is the Norm

Source: Webroot – 2016 Threat Brief, February 2016

97% of new malwareis unique to a specific endpoint,

rendering signature-basedsecurity obsolete

Malware and PUAs have become overwhelmingly

polymorphic

Page 5: Ransomware shuts down your client.. What do you do?

5 Tuesday, May 2, 2023

“Good” and “Bad” Websites

Source: Webroot – 2016 Threat Brief, February 2016

Page 6: Ransomware shuts down your client.. What do you do?

6 Tuesday, May 2, 2023

High Success Rates of Phishing Attacks

Source: Webroot – 2016 Threat Brief, February 2016

of internet users will fall for a zero-day phishing attack in a year

50%

Page 7: Ransomware shuts down your client.. What do you do?

7 Tuesday, May 2, 2023

Mobile Apps Are Riskier than Ever

Source: Webroot – 2016 Threat Brief, February 2016

52%

30%

18%

22%

50%

28%

Increase indicates a shift to malicious and unwanted apps

2014 2015

Page 8: Ransomware shuts down your client.. What do you do?

8 Tuesday, May 2, 2023

Ransomware’s Evolution

Page 9: Ransomware shuts down your client.. What do you do?

9 Tuesday, May 2, 2023

What Is Crypto Ransomware?

Classification

Trojan horse

Type

Ransomware/crypto virus

OS affected

Windows

First observed

September 2013

Drive types

Local, network, and removable

Drive types

Spam botnet lures victim

Phishing email with attachment

Attachment downloader gets Zeus

Zeus gets CryptoLocker/CryptoDefense

Page 10: Ransomware shuts down your client.. What do you do?

10 Tuesday, May 2, 2023

Evolution of Crypto Ransomware

Increasing adoptionof IP anonymizing services

01

Ransomware-as-a-service

02

Detection issues due to thread injection, process

hollowing, and new exploits

03

Expanding pastWindows to macOS

04

Now a commodityextortion service!

Page 11: Ransomware shuts down your client.. What do you do?

11 Tuesday, May 2, 2023

How Ransomware Infects Systems

Page 12: Ransomware shuts down your client.. What do you do?

12 Tuesday, May 2, 2023

Silent Deployment

Before After

1

3

2

Page 13: Ransomware shuts down your client.. What do you do?

13 Tuesday, May 2, 2023

Click here for full presentation