Awareness Advocate On Ransomware Targeting NAS Systems

Researchers at Kaspersky have discovered a previously undetected encryption ransomware attack that targets network-attached storage systems. The ransomware findings were revealed in Kaspersky’s Q3 IT Threat Evolution Report.

Subscribe
Notify of
guest

1 Expert Comment
Most Voted
Newest Oldest
Inline Feedbacks
View all comments
Javvad Malik
Javvad Malik , Security Awareness Advocate
InfoSec Expert
December 3, 2019 1:32 pm

Ideally NAS and other backup systems should be offline and especially not accessible through the internet. Any organisation with NAS devices should ensure they are kept fully patched and up to date to prevent criminals from being able to directly infect them, or use the NAS as a launchpad into the environment.

Backups should be shipped to offsite locations frequently, so that even if onsite NAS is infected or fails, there is a safe copy from which data can be restored.

Most ransomware is successful either due to taking advantage of unpatched systems or through social engineering attacks. So organisations should take stock of their assets and ensure any publicly exposed ones are kept patched as well as ensuring all staff receive regular and up to date security awareness and training.

Last edited 2 years ago by Javvad Malik
Information Security Buzz
1
0
Would love your thoughts, please comment.x
()
x