old methods cant stop ransomware

Why Old Methods Can’t Stop Ransomware

During the American Revolution, sentries guarding encampments reportedly shouted, “Halt! Who goes there? Friend or foe?” As far as we know, there are no statistics that indicate how many foes identified themselves as such – or lived to tell about it.

Ransomware is not easily identified

As of this time, conventional anti-virus software is about as effective at identifying ransomware as Revolutionary War sentry was at identifying friend or foe. We do have some statistics for the current day.

A recent survey of 500 companies found that

  • 33% had been attacked by ransomware in the previous 12 months
  • More than half of those companies were operating multiple anti-virus software at the time.

old methods cant stop ransomware

Think about that.

  • Of 500 companies,165 had been attacked by ransomware
  • Of those 165 attacked, 87 were employing multiple lines of defense.

That’s like having multiple perimeters of sentries, none of which would identify the foe.

There’s a reason for that.

The common approach is called blacklisting. Software already identified as “foe” is blacklisted. The problem is that the software cannot be identified as evil until it has permeated someone’s defense perimeter. Once identified as malware, conventional anti-virus publishes, in effect, “Wanted” posters so that computers can recognize software already known to be malicious.

There’s a solution for that

The solution is in implementing the opposite of blacklisting. Computer techies call it “whitelisting.” Instead of issuing wanted posters, a whitelisting approach allows only known friends to pass.

Pernicious thinkers amongst our readership might be thinking that ransomware can disguise itself by wearing someone else’s clothes. Not so. If ransomware producers think that they can masquerade as a friend, they will be sorely surprised to discover that they are wearing the proverbial Emperor’s New Clothes. The ruse will be discovered, and the attempt at ransom will fail.

Are you adequately protected against ransomware? Don’t think so. Know so. Contact us and let us show you how you can be sure that you are protected.

Ransomware Myrtle Beach

Why Backups Aren’t Enough

Perfect backups will not always prevent the consequences of a ransomware attack, but backing up is vitally important.

Myrtle Beach Ransomware

 

The Problem with Ransomware:

A high-profile ransomware attack hit a well-known transportation agency over a recent holiday weekend.  This attack was a major eye-opening event, to say the least.  For the first time, a major transportation agency has been shut down by a ransomware attack.  To give you a few details, they estimated that approximately 900 of the computers in this agency were affected.  They were using backups and this provided them with the ability to restore data with no intentions of paying the ransom; so one would assume all was well.  Not exactly…

The transportation agency’s use of backups prevented them from losing all their customer and internal data.  The use of a simple backup prevented a major catastrophe for this agency.  Without the backups, they would have been faced with paying the ransom in this case, or been faced with heavy financial losses.  It took approximately 2 to 3 days in order for most of the computers to be restored and the rest followed within the week.  A large portion of their workforce was inaccessible for several days and some parts were down for almost an entire week.

The inability to work and work properly is going to cost any business money and valuable resources.  With the transportation agency’s computers inaccessible, they had to shut down the terminals and payment systems, allowing the public to ride the metro for free.  Many local articles stated that the systems being down was costing the agency $500K for every day that they were down and not working. This ransomware attack cost this transportation agency over a million dollars in the time they were down and not running.  Backing up a system can save data and is very important, but many times it is not quick enough to get you back online without losing valuable time.     

The Solution:

The story of the transportation agency demonstrates the vital importance of prevention when it comes to ransomware attacks.  In order to eliminate this problem before it begins, it’s important to put your emphasis on prevention instead of detection and recovery.  We believe that prevention is the only way to protect your business investment, and that is why we use global application whitelisting. Whitelisting allows you to avoid organized attacks and targeted areas because unknowns are always blocked no matter how new they are.  We have no way of knowing what antivirus protection the agency was using, but even with their backups they suffered huge financials losses due to downtime.

Prevention is key!  If you have any questions about ransomware attacks and how to keep your business protected, please give us a call at 843-282-2222 TODAY!

Malware Takes Hackers to Terrifying New Roles

You may not be familiar with the term, but there is a new breed of hackers out there known as “nation-state attackers.” They are an evil bunch who use malware to create upheaval and harm to people on a material level. They are life-threatening, rather than just being a financial threat. We think of people who use malware as only being after the money of their victims, but that’s not the case any longer. Their role has now taken a terrifying turn…

It’s scary to think of, but nation-state hackers are now able to hack our systems of infrastructure, such as power grids, water supply and even transportation systems. How would a failure of power or transportation affect us? Malware has the potential of bringing down the infrastructure of a major metropolis at any time, making it a terrifying enemy. In the age of modern technology, our world faces modern threats. Malware is a big part of it.

Ransomware has been a big part of the malware problem and is quite the money maker. It’s growing out of control. Hackers have altered the lives of ordinary citizens by hacking into the systems that control everyday life.

As scary as it is, it’s unfortunately not a new problem. In the Ukraine last year, more than 225,000 people had their power shut down by a sinister group known as the Black Energy Group. Just last week, a nasty form of malware manifested itself in yet another energy company in Europe.

It had the ability to give hackers backdoor access to the system and obtain all the data that would allow them to create havoc. When the system is in the early stages of being rebooted, that’s when a lot of the automatic security software kicks in.

Backdoor

This malware can get in at these early stages of a reboot and do its damage, gaining the info and access it needs. What makes it even more sophisticated is the ability for it to go undetected by removing itself automatically should it get sandboxed in by one of these security systems.

Hackers are using increasingly dangerous malware and ransomware. It’s never been more important to protect yourself than now and there’s never been a better way to do it than with Tech Sentries.

Call us today 843-282-2222 and sign on for the best protection you can buy!

Scareware

Scareware – What Is It? Should You Be Concerned?

According to IN Homeland Security, the probability of scareware, a software developed to be the solution to a nonexistent problem, is going to make a huge return. The possibility of these forecasts being true seems rather high.

A security specialist recently got in touch with the Spiceworks IT platform for help on a possible scareware infection. The IT expert reported that after running multiple scans, nothing was suggesting there was an internal problem. It is believed these messages were scareware, utilized to trigger the user to call the number within the message for “assistance.”Scareware

In an effort to avoid falling for incorrect information or alarms meant to scare you, contact Tech Sentries if you receive any messages on your computer about a malware infection. If you call the phone number noted in the malware alert, there is an excellent chance you’re calling the hackers. This can be a significant problem, as you might be offering payment information or remote access to an individual who is most certainly not looking out for your best interest. As I stated, it is best to call your security software application business directly.

This results in another question. What about phones and tablets? Do you have security software on them? If so, you may need to use it if you’re a part of the most recent Pokémon Go trend. Reports made by Huffington Post stated the app “Guide and Cheats for Pokémon Go” included scareware, which potentially includes ransomware. So, to be clear, not only could you possibly get messages for concerns that are nonexistent, you might likewise be infected with ransomware ! Your best option for this particular case—avoid this app completely.

Call us today (843-282-2222) or contact us at www.techsentires.com and see how we can keep you safe, all while you sleep or work. Never worry about scareware or being held hostage by ransomware.

ransomware sidekick

Ransomware Has a New Sidekick

ransomware sidekick

Ransomware is nasty no matter how you slice it. And now it has a sidekick called ranscam. In this article, we want you to know what it is and how to keep from becoming a victim of it.

The very term “ranscam” sounds like what it is—ransomware that gets wormed in to your computer system and creates a ransom demand that it sends to you. It does not cause your files to be encrypted but it does actually delete them! In the ransom demand, you will be told what they want you to do to retrieve your files, but you can rest assured it involves collecting money from you.

ransomware ranscam

Many cyber security experts believe this particular strain of ransomware will not last very long since its reputation is very negative. Other ransomware is far more sophisticated such as that in the series called Crypto. The only reason these viruses exist is for their creators to turn a very quick profit. This poses the question of how you can tell if your computer has been affected by either ransomware or the ranscam virus.

Read on….

If you are wanting to know if you have either ransomware or ranscam, unfortunately, you can’t really know. And if you pay the ransom demand, there’s no guarantee that your files will be recovered. Remember—it’s a criminal asking for the money so you’re not paying a normal person. They could care less about your personal pictures, movies and other files. They only want your money. Even if you pay what they demand, they really don’t care about your stuff so you probably will never see your files again.

If you think you’ve been victimized by ransomware, you need to understand and follow the following steps:

  • Don’t pay any ransom money! All you’re doing is funding these hackers to continue on to their next criminal act.
  • Restore your system by using your back-up files. Do NOT pay anything!
  • Let the FBI know. The FBI needs to know about these hackers in order to bring justice through legal proceedings.
  • Report all cyber-criminal activity you see to IC3, which is a federal agency. It is here so you can file any complaints.
  • ALWAYS notify your security company!! They MUST know if they’ve missed a huge security threat or they won’t be able to protect against it in the future.
  • Keep in mind you are helping to protect others by reporting any breech of security.
  • Educate yourself! Simply doing one webinar or meeting is not enough. You must keep up with some continuing education on the matter and really know what you’re dealing with.

Tech Sentries has the latest and greatest cyber security technology on the market today!

Call us today (843-282-2222) or contact us at www.techsentires.com and see how we can keep you safe, all while you sleep or work. Never worry about being infected with crazy ransomware again!

ransomware alert 090716

Ransomware Alert – 09.07.16

In yet another case of “Don’t believe everything you read,” a new ransomware attack has been discovered.

If this image shows up on your computer, the first thing you need to know is that THERE IS NO GOVERNMENT CENTRAL SECURITY TREATMENT ORGANIZATION. You and your computer are being held for ransom.

(843) 282 - 2222 info@techsentries.com
According to one reliable source, the “new ransomware that pretends to be from a fake organization called the Central Security Treatment Organization has been discovered by security researcher MalwareHunterTeam. When the Central Security Treatment Organization ransomware infects a computer it will encrypt a victim’s files and then append the .cry extension to encrypted files. It will then demand approximately 1.1 bitcoins, or $625 USD, in order to get the decryption key.”

The new CryLocker ransomware will

  • send information about the victim to the Command & Control server using User Datagram Protocol (UDP).
  • use social network site to upload and host information about each of the victims.
  • query the Google Maps API to determine the victim’s location using nearby wireless SSIDs.
  • stay persistent despite continual reboots
  • require a victim’s personal ID information with payment

For those who are wary, but not quite vigilant enough, this ransomware has a special feature designed to “prove” that the organization can unencrypt your computer files. It includes a user demo decryption of a single file. They apparently think that if you don’t fall for trick number one, you might fall for trick number two. These guys are good at understanding human nature too. Then again, we would remind you, “Fool me once, shame on you. Fool me twice, shame on me.”  Our goal is for you not to be fooled – ever.

Bleepingcomputer.com has detailed information about CryLocker. KnowBe4 has a free Ransomware Hostage Rescue Manual available to educate consumers and businesses on how to deal with these growing threats.

For fast, effective, and reliable protection against ransomware and other computer threats, contact Tech Sentries at 843-282-2222.

malvertising

Guard Your Technology Against Malvertising

malvertising

When you juxtapose “malicious” or “malware” and “advertising,” you get the portmanteau “malvertising.” Although malvertising has existed for about 30 years, it is not yet a household word, even among many computer techs. That is probably going to change following a malvertising attack discovered on Google June 2, 2017.

The attack caught users unaware as they innocently clicked on a sponsored AdWords search engine response to the big box retailer, Target. Expecting to land at Target’s website, users were unwittingly redirected to another URL where they were greeted with a Microsoft look-alike site that warned them to call a phone number to remove an infected file on their computer. The file itself was non-existent.

Malvertising typically works because the malware is not on your PC. It is propagated by inserting malicious codes into ads on trusted websites. Malvertising is particularly pernicious in that neither the site nor the advertiser are aware of the code that redirects users to a malicious server. According to the Center for Internet Security, “The software could allow the attacker to perform a number of actions including,

  • allowing full access to the computer
  • exfiltrating financial or sensitive information
  • locking the system and holding it ransom via ransomware, or
  • adding the system to a botnet so it can be used to perform additional attacks.

This entire process occurs behind the scenes, out of sight of the user and without any interaction from the user.” Because all of this activity takes place “behind the scenes” and because internet ads are changed at a rapid pace, malvertising is unusually difficult to combat. The New York Times and NFL websites have already been malvertising victims.

The best practices for guarding your technology against malvertising are to ensure that all of your software and extensions are up-to-date, disable the automatic use of Flash, and close windows not currently in use when connected to the internet.

Tech Sentries is always on duty helping you “GUARD YOUR TECHNOLOGY” at all hours of the day and night. Don’t wait. Contact us today. (843-282-2222).

ransomware Myrtle Beach

Cerber Ransomware Kicks Into High Gear During Post-Holiday Shopping

ransomware Myrtle BeachAfter a relatively calm period, the researchers at Microsoft are warning that the ransomware known as Cerber has resurfaced stronger than ever. The target audience? Holiday and post-holiday shoppers. It also targets the data files of enterprise businesses.

Most of us are a little more aware of the need for cyber security during the holidays, but the need is equally important after the holidays! The Malware Protection Center at Microsoft has reported that the cyber attackers have amped up their game during this post-holiday season. One reason is the number of online shoppers looking for great deals after Christmas.

Top security researchers are now aware of a couple of new campaigns and spam that pinpoints all the consumer transaction during the post-holiday season. Cerber ransomware is constantly changing, causing user files to be encrypted while holding them for ransom. Just in the last several weeks the authors of Cerber ransomware are now attacking critical applications of major business files.

The newest version of this ransomware has been programmed to target the database files of Microsoft Acess, Oracle and MySQL. It’s not unusual for these files to be shut down as they are encrypted by malware.

As with so many other viruses, attackers are going straight for your inbox and flooding them with malicious links and downloadable attachments. As soon as you click on the link, the virus moves in, installing the ransomware. What’s worse is that it creates what looks like zip files that are password protected. The body of the email often contains the password, making this another huge red flag for malware. It usually states that order and delivery details are in the email.

Vulnerabilities found in previous Adobe Flash websites can also be used to exploit Cerber. If a person happens to be on this site, they will unknowingly download the malware to their computer. What’s more, any information on the version of Cerber ransomware has been scrubbed, which makes it even harder to track.

Unfortunately, an even wider net has been cast by Cerber and it’s now targeting dozens more types of files. Executing .exe, .cmd, and .msi files is now happening for the first time with Cerber ransomware.

Cyber criminals have to constantly be changing and updating their versions of ransomware in order to go undetected by antivirus software programs. Ramping up the malware complexities tells us how determined these criminals are to destroy and attack your personal files. Don’t become a victim—never click on unfamiliar links in your email! Use common sense and close out any ads or emails with suspicious links.

For more information on cyber criminals and how to stay safe from ransomware, call Tech Sentries today! (843) 282-2222.

ransomware statistics

Alarming Statistics About Ransomware

For some inexplicable reason, each of us tends to believe that we are immune to catastrophic events, including diseases, natural disasters, and crimes. Unfortunately, we carry that same naivete over to guarding our technology. Just as we think that no harm will befall us personally, even though it does, we believe that are computers are also immune – even though we have no reason to believe that they are.

Eye-opening Ransomware Statistics

ransomware statisticsSome people are motivated by statistics that evidence growing vulnerability. Others become motivated when disaster strikes someone they know. Still others do nothing until they have become infected or affected. We hope the following statistics will increase your awareness of the reality that you can become a victim of a ransomware attack.

  • There are more than 4,000 ransomware attacks reported every day.
  • It is estimated that less than 25% of attacks are report.
  • 30,000 to 50,000 digital devises are infected with ransomware each month.
  • The amount of money paid in ransom increased dramatically from 2015 to 2016.

 

Year Ransom Paid
2015 $24 million
2016 $850 million

 

Year Average Paid
2015 $294
2016 $679

More Convincing Statistics

Ransom paid is only part of the problem. Ransomware attacks cause expensive downtime for businesses.

  • 63% of business attacked by ransomware suffered downtime.
  • 34% lost money as a result of the downtime alone.
  • 20% were forced to close permanently.

Small Business Are Not Immune

Myth: “My business is too small for anyone to bother attacking.”

Fact: A recent survey reported that, on average, small businesses lose an aggregate of $8,500 per downtime hour. That is an annual total of $75 billion.

These statistics may not alarm you. They should. You need to take the necessary precautions to protect your business and your home computers from ransom attacks.

Yes, you should be concerned about your computer system security, but you should also know that you are not alone and defenseless in the computer world. Tech Sentries is always on duty. Contact us today to learn how we can help you “GUARD YOUR TECHNOLOGY” (843-282-2222).

ransomware money

Five Things You Probably Did NOT Know About Ransomware

ransomware moneyOur mission at Tech Sentries is to help you “Guard Your Technology.” Part of helping you to “Guard Your Technology” is to keep you informed about threats to your computer system, like ransomware. We believe that keeping you informed is part and parcel of our commitment to you. We found this insightful information in a recent article in an online tech site.

Ransomware Lesson #1

It can be much easier to steal your business or personal information and hold it ransom than to kidnap someone in your family.

Holding information for ransom may be less lucrative per instance, but the crime can be perpetrated a virtual plethora of times with the potential capability of accumulating a great deal of ill-gotten gain from multiple sources. Although some criminals may take the short path to large sums of cash, the opportunity is now open to treacherous techies who are willing to commit the crime numerous times on a smaller scale.

Just because you are not a big business or personally wealthy does not exempt you from ransomware attempts.

Ransomware Lesson #2

Ransomware is not a virus. The computer term “virus” was coined because, like a live virus, it infects your computer files. Ransomware locks your files so that you cannot access them.

Ransomware Lesson #3

You do not have to click on anything in particular to be the victim of a ransomware attack. Although phishing is a method used in some ransomware attacks, it is not, by any stretch of the imagination, the only method of attack.

We always strongly advise our clients to be careful what you click. Understand, however, that this may not make you immune to a ransomware attack. It is, nonetheless, a good habit to develop to guard your technology.

 

Ransomware Lesson #4

You do not have to visit questionable websites to become a victim of ransomware. Although that may make you more vulnerable to attack, the masters of the ransomware craft tend to use the most innocuous of sites to carry out their schemes. Their whole point is to catch the innocent unaware.

Ransomware Lesson #5

You can guard your technology against ransomware. Although traditional antivirus software has yet to provide foolproof protection against ransomware, whitelisting has come to the forefront as one of the best defenses available. Read our recent blog post about whitelisting here. You will understand in more detail why whitelisting is so successful and why you should use it.

 

You should be concerned about ransomware, but you are not alone and defenseless in the computer world. Tech Sentries is always on duty. Contact us today to learn how we can help you “GUARD YOUR TECHNOLOGY” (843-282-2222).

1 2 3