Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Turning Back Time on Ransomware
Articles

Turning Back Time on Ransomware

ISBuzz TeamBy ISBuzz TeamApril 3, 2019Updated:April 3, 20196 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Ransomware no longer dominates the malware landscape – but it still has the power to inflict serious disruption. Orli Gan, Head of Product Management and Product Marketing, Threat Prevention at Check Point looks at why organizations still need to be vigilant about ransomware – and how they can stop attacks causing damage

Just when it seemed that ransomware was becoming a thing of the past, it has reared its ugly head again.  While cryptomining malware dominated the malware landscape throughout 2018, replacing ransomware as the most popular method for cybercriminals to earn illicit cash, ransomware didn’t disappear entirely – it just got more targeted.  

Cybercriminals moved away from distributing millions of emails with no specific victim in mind, to carefully planned and targeted ransom attacks. A key example is the recent attack on Norsk Hydro, one of the world’s largest aluminum manufacturers, which showed that ransomware has lost none of its power to cause disruption despite the decline in its usage.

Late in the evening of Monday 18 March, Norsk Hydro was hit by the ‘LockerGoga’ ransomware, a relatively new variant which was first seen in January 2019.  The malware forced the company to isolate all plants and operations across the US and Europe, and switch to manual operations and procedures wherever possible. The malware encrypted critical systems, and a request for a ransom payment made.

Even though the company’s actions during the attack have been widely praised as textbook examples of internal and external incident response processes, it still suffered serious disruption.  While the company was able to quickly get many systems back to something approaching normal operations, it experienced ‘production challenges and temporary stoppages at several plants’. The company has said it is slowly bringing affected systems back online, but the preliminary cost of the incident had been estimated at 300 – 350 million Norwegian kroner (around $30M).  

Basics of ransomware readiness

So how can companies avoid being similarly disrupted by ransomware attacks?  The good news is, even highly sophisticated malware attacks can be neutralized and even prevented outright with relatively simple cybersecurity tools and processes.  Network segmentation, for example, is easy to implement – it’s a basic principle of intelligent network architecture – but it is incredibly effective at containing the spread of malware, preventing it from moving laterally across networks to infect and scramble other system.  

It’s critical to have good backups of data, which are stored separately from the organization’s main network. This is the only way to ensure that, if the worst happens and a ransomware attack takes hold, critical files and information can be recovered once the infection is removed.

Employee education is also a powerful weapon. Attachments and links should only be opened from truly trusted sources. If a user is asked to run macros on a Microsoft Office file, then the simple answer is – don’t! Macros are frequently used as the trigger for downloading ransomware, so being asked to run them on a simple Office file is a common indicator of a ransomware attack. Spreading this type of awareness should be a core part of employee IT training.

And of course, keeping traditional antivirus and other signature-based protections up to date is critical.  But these measures can still be bypassed by modern ransomware. More advanced protections, such as threat extraction and advanced sandboxing, are needed to reinforce existing defenses.

Preventing infections

Threat extraction works on a simple premise:  the vast majority of ransomware and malware is distributed via email, hidden in the common file types used for business – Word documents, PDFs, Excel spreadsheets and so on. So from a security standpoint, it’s best to assume that any email attachment is always infected – and to extract any potential threat from it before passing it to the user.  Documents attached to emails are deconstructed at the email gateway, and suspicious content (such as macros and external links) removed. The document can then be reconstructed safely and sent onto the intended user. This eliminates the risks from infected files without delaying users’ work.

Advanced sandboxing works in parallel with threat extraction, to detect even unknown malware for which signatures do not yet exist. Sandboxing inspects an incoming file for suspicious elements at the CPU level, below the application or OS layers on the processor, enabling it to see through any evasion techniques built into the malware, and block the potential infection before it can take hold.  

But even these measures are not perfect – no defense can ever be 100% failsafe.  There’s always a slim chance that ransomware could slip through. However, an additional layer of last-ditch protection is available to nullify even the most advanced ransomware that manages to successfully breach the organization’s defenses and start the infection process.

This final defensive line works by monitoring endpoints continually for the behavioral indicators which all types of ransomware variant follow.  These indicators are:

  1. Creating a text document, which will include the ransom message to the user
  2. They delete, or attempt to delete, all shadow copy and backup files so that information cannot easily be recovered
  3. They then start to encrypt some or all of the files on the machine

These give an opportunity for ransomware forensics tools to identify an attack in microseconds and act to mitigate its impact.

Rolling back attacks

These forensics-based ransomware defenses sit on individual machines, monitoring for the tell-tale signs of ransomware described above.  Once ransomware indicators are detected, an infection is nullified using a ‘rollback’ mechanism. This works by creating an instantaneous backup of everything on the machine, but only during the process of infection (rather than creating continuous shadow copy files which, as mentioned, ransomware attempts to seek out).  Then the ransomware is quarantined to block further spread, and the backed-up files, together with the back-up image of the PC, can be used within minutes to replace the files encrypted by the ransomware. This minimizes disruption and enables normal business processes to restart within minutes, rather than days or weeks.  

In conclusion, ransomware is unlikely to ever disappear.  It’s unlikely that organizations can ever fully prevent and block every ransomware attack that targets them.  However, with a forensics-based approach as a critical last line of defense against these damaging attacks, it’s possible to turn back time and nullify their impact.  

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roundcube RCE Vulnerability Disclosed Early Amid Active Exploitation

June 10, 20255 Mins Read

Fake Indian Government Portal Used to Spread Cross-Platform Malware in Suspected APT36 Campaign

May 13, 20253 Mins Read

New Federal Alert Warns U.S. Businesses of Medusa Ransomware Surge

March 13, 20254 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}