Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Saturday, 1 April, 2023
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Guru Briefing: SentinelOne on Ransomware

by The Gurus
June 27, 2016
in News, This Week's Gurus
Share on FacebookShare on Twitter

News from SentinelOne today has announced a new variation of the CryptXXX Ransomware, which they’ve clocked earning over $50,000 in Bitcoin payouts for its proponents thus far.
As with other popular ransomware strains that have been improving with each iteration, the new CryptXXX is unbreakable by decryption tools and has already proven to be very successful in forcing ransom payments. Encryption flaws from old versions have been fixed, and the malware is now better at evading antivirus detection.
We sat down with Caleb Fenton, Senior Security Researcher at SentinelOne, to get the details on this new campaign and for his take on how organisations can adequately prepare for situations where this ransomware comes for their files.
ITSG: How does this variant CryptXXX differ from previous ransomware?
CF: Previous versions encrypted files incorrectly such that tools could remove the encryption, but this new version uses more robust encryption which may make it impossible for files to be decrypted. Other changes were made to avoid AV detection.  Structurally they moved code around enough to where previous AV signatures were rendered useless. 
ITSG: What is the most common method of this ransomware being deployed?
CF: It spreads through spam, though possibly other channels. We acquire binaries from various sources such as underground malware forums, and since we’re actively monitoring this family, we detected a sample which was similar but not identical to previous versions.
ITSG: Is ransomware here to stay, or will there come a day when it’s banished to history?
CF: Yes, for the simple reason that ransomware attacks are extremely successful today, and are relatively easy to launch. It does not require a great deal of sophistication on the part of the attacker, just access to the correct tools which can be purchased online or subscribed to in a RaaS environment. 
ITSG: What will organisations need to do to combat this variant of CryptXXX?
CF: The reactive response is to maintain a disciplined backup strategy, and have an internal strategy for how you’ll get access to BitCoins in a short amount of time.  The proactive response is to stop relying on static-based detection technologies.  This version of CryptXXX is designed very specifically to take advantage of those weaknesses. It is best to look towards technologies that use more dynamic, behavioural-based detection.
ITSG: We all know we shouldn’t pay up, but what happens if we do?
CF: You get your data back, but in the process your incentivising an ‘industry’ to further invest in new variants.  In order to stop this rise in ransomware attacks we need to make the cost to launch an attack prohibitive.  This will in turn take the profit out of the industry.  If there’s no profit the investment should decrease significantly.
So there you have it – looks like ransomware isn’t going anywhere fast so get backed up and don’t let your company get in the news for all the wrong reasons!
Caleb Fenton is Senior Security Researcher at SentinelOne.

FacebookTweetLinkedIn
Tags: antivirusattackAVBackupBitCoincaleb fentondataencryptedfilesMalwareRaaSRansomwaresentineloneSpam
ShareTweetShare
Previous Post

Crypto-ransomware attacks rise five-fold to hit 718 thousand users in one year

Next Post

Ransomware scum target corporate Office 365 users in 0-day campaign

Recent News

Data Privacy Day: Securing your data with a password manager

For Cybersecurity, the Tricks Come More Than Once a Year

March 31, 2023
cybersecurity training

Only 10% of workers remember all their cyber security training

March 30, 2023
Pie Chart, Purple

New API Report Shows 400% Increase in Attackers

March 29, 2023
Cato Networks delivers first CASB for instant visibility and control of cloud application data risk

Cato Networks Recognised as Leader in Single-Vendor SASE Quadrant Analysis

March 29, 2023

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2019 IT Security Guru - Website Managed by Calm Logic

  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2019 IT Security Guru - Website Managed by Calm Logic

This site uses functional cookies and external scripts to improve your experience.

Privacy settings

Privacy Settings / PENDING

This site uses functional cookies and external scripts to improve your experience. Which cookies and scripts are used and how they impact your visit is specified on the left. You may change your settings at any time. Your choices will not impact your visit.

NOTE: These settings will only apply to the browser and device you are currently using.

GDPR Compliance

Powered by Cookie Information