Although it is at the forefront of any discussion about security today, ransomware has only been a major part of the malware scene since 2014. The threat is still evolving, and IT professionals are sure to encounter even more advanced ransomware in 2017.

Tracking the Continued Rise of Ransomware in 2017

Ransomware generally revokes access to a victim’s endpoint or encrypts data on that endpoint before prompting the victim to pay a ransom to regain control. That’s the basic idea, but the devil is in the details.

These attacks have grown drastically more frequent in recent years. According to the IBM report, “Ransomware: How Consumers and Businesses Value Their Data,” 4,000 ransomware attacks occurred per day in 2016, four times more than the previous year.

Naturally, the total payout to cybercriminals has increased with the volume of attacks. The FBI reported that ransomware victims in the U.S. shelled out $209 million for their stolen data in just the first three months of 2016, a dramatic increase from the $24 million companies spent in all of 2015, according to Reuters. This growth shows no signs of slowing down.

Authorities generally advise victims not to pay the ransom, since there is no guarantee that they will receive a working decryption key. More importantly, paying the ransom funds future cybercriminal endeavors. Ransomware victims should resolve to slow this progress by refusing to pay for stolen files in 2017.

Consumers Versus Enterprise Users

Consumers in general may be unaware of the threat they face. Just 31 percent of consumers have specifically heard about ransomware, according to the IBM report. This creates a long-term problem when consumer actions are factored into a threat model because those consumers are less likely to know best practices for protecting data. IT experts must increase their efforts to educate people about ransomware as the threat landscape expands.

Enterprise users are, in general, much better informed about ransomware. The same survey found that 46 percent of executives had experienced ransomware attacks in the workplace and 70 percent of those executives paid to recover their stolen data. Larger enterprises are also more likely to train workers about IT security.

Social Engineering Going Strong in 2017

Most ransomware schemes depend on social engineering ploys to trick victims into activating the malware. This strategy served fraudsters well, so it’s safe to assume they’ll continue to employ it in 2017 and beyond. To mitigate the threat of an infection via social engineering, consumers should never open attachments from untrusted or unknown email.

Companies can implement policies to minimize actions that could lead to infections, but this is complicated by the legitimate need to frequently open attachments in a business setting. Many organizations would benefit from blocking Microsoft Office macros, because these are particularly popular vehicles for malware.

Not all attacks require user action to be implemented, however. Drive-by infections lurk in specially crafted pop-up advertisements. All a victim has to do is view a seemingly innocuous webpage. With social engineering, fraudsters like to keep it simple.

Low-Hanging Fruit

Ransomware typically targets the lowest hanging fruit. Cybercriminals are particularly well-versed in exploiting Windows vulnerabilities, for example. This malware does not need to infiltrate your entire system for long-term access; it simply needs a gateway to access your data, which doesn’t require advanced tools. Windows users have many default privileges that can be exploited to allow total access.

Ransomware will almost surely continue to grow in volume and complexity in 2017. Security analysts should keep an eye on the evolution of ransomware, which may bring advanced attacks, such as ransomworms, in the near future.

More from Fraud Protection

Virtual credit card fraud: An old scam reinvented

3 min read - In today's rapidly evolving financial landscape, as banks continue to broaden their range of services and embrace innovative technologies, they find themselves at the forefront of a dual-edged sword. While these advancements promise greater convenience and accessibility for customers, they also inadvertently expose the financial industry to an ever-shifting spectrum of emerging fraud trends. This delicate balance between new offerings and security controls is a key part of the modern banking challenges. In this blog, we explore such an example.…

Remote access detection in 2023: Unmasking invisible fraud

3 min read - In the ever-evolving fraud landscape, fraudsters have shifted their tactics from using third-party devices to on-device fraud. Now, users face the rising threat of fraud involving remote access tools (RATs), while banks and fraud detection vendors struggle with new challenges in detecting this invisible threat. Let’s examine the modus operandi of fraudsters, prevalence rates across different regions, classic detection methods and Trusteer’s innovative approach to RAT detection through behavioral analysis. A rising threat As Fraud detection methods become more and…

Gozi strikes again, targeting banks, cryptocurrency and more

3 min read - In the world of cybercrime, malware plays a prominent role. One such malware, Gozi, emerged in 2006 as Gozi CRM, also known as CRM or Papras. Initially offered as a crime-as-a-service (CaaS) platform called 76Service, Gozi quickly gained notoriety for its advanced capabilities. Over time, Gozi underwent a significant transformation and became associated with other malware strains, such as Ursnif (Snifula) and Vawtrak/Neverquest. Now, in a recent campaign, Gozi has set its sights on banks, financial services and cryptocurrency platforms,…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today