Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Saturday, 27 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Guru Briefing: SentinelOne on Ransomware

by The Gurus
June 27, 2016
in News, This Week's Gurus
Share on FacebookShare on Twitter

News from SentinelOne today has announced a new variation of the CryptXXX Ransomware, which they’ve clocked earning over $50,000 in Bitcoin payouts for its proponents thus far.
As with other popular ransomware strains that have been improving with each iteration, the new CryptXXX is unbreakable by decryption tools and has already proven to be very successful in forcing ransom payments. Encryption flaws from old versions have been fixed, and the malware is now better at evading antivirus detection.
We sat down with Caleb Fenton, Senior Security Researcher at SentinelOne, to get the details on this new campaign and for his take on how organisations can adequately prepare for situations where this ransomware comes for their files.
ITSG: How does this variant CryptXXX differ from previous ransomware?
CF: Previous versions encrypted files incorrectly such that tools could remove the encryption, but this new version uses more robust encryption which may make it impossible for files to be decrypted. Other changes were made to avoid AV detection.  Structurally they moved code around enough to where previous AV signatures were rendered useless. 
ITSG: What is the most common method of this ransomware being deployed?
CF: It spreads through spam, though possibly other channels. We acquire binaries from various sources such as underground malware forums, and since we’re actively monitoring this family, we detected a sample which was similar but not identical to previous versions.
ITSG: Is ransomware here to stay, or will there come a day when it’s banished to history?
CF: Yes, for the simple reason that ransomware attacks are extremely successful today, and are relatively easy to launch. It does not require a great deal of sophistication on the part of the attacker, just access to the correct tools which can be purchased online or subscribed to in a RaaS environment. 
ITSG: What will organisations need to do to combat this variant of CryptXXX?
CF: The reactive response is to maintain a disciplined backup strategy, and have an internal strategy for how you’ll get access to BitCoins in a short amount of time.  The proactive response is to stop relying on static-based detection technologies.  This version of CryptXXX is designed very specifically to take advantage of those weaknesses. It is best to look towards technologies that use more dynamic, behavioural-based detection.
ITSG: We all know we shouldn’t pay up, but what happens if we do?
CF: You get your data back, but in the process your incentivising an ‘industry’ to further invest in new variants.  In order to stop this rise in ransomware attacks we need to make the cost to launch an attack prohibitive.  This will in turn take the profit out of the industry.  If there’s no profit the investment should decrease significantly.
So there you have it – looks like ransomware isn’t going anywhere fast so get backed up and don’t let your company get in the news for all the wrong reasons!
Caleb Fenton is Senior Security Researcher at SentinelOne.

Tags: antivirusattackAVBackupBitCoincaleb fentondataencryptedfilesMalwareRaaSRansomwaresentineloneSpam
ShareTweet
Previous Post

Crypto-ransomware attacks rise five-fold to hit 718 thousand users in one year

Next Post

Ransomware scum target corporate Office 365 users in 0-day campaign

Recent News

Keeper Security launches Microsoft Teams integration for privileged access management

Keeper Security launches Microsoft Teams integration for privileged access management

June 26, 2026
UK Museums Are a Cyber Incident Waiting to Happen and the Government Knows It

UK Museums Are a Cyber Incident Waiting to Happen and the Government Knows It

June 25, 2026
pqc

New Forescout Data Reveals Slow Progress Toward Quantum-Safe Security

June 24, 2026
AI-Powered Phishing Attacks Surge 1,380% as Criminal Platforms Render MFA Obsolete

AI-Powered Phishing Attacks Surge 1,380% as Criminal Platforms Render MFA Obsolete

June 24, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol