Personalized Ransomware: Price Set by Your Ability to Pay

Smart entrepreneurs have long employed differential pricing strategies to get more money from customers they think will pay a higher price. Cyber criminals have been doing the same thing on a small scale with ransomware: demanding a larger ransom from individuals or companies flush with cash, or organizations especially sensitive to downtime and service disruptions. But now it appears cyber criminals have figured out how to improve their ROI by attaching basic price discrimination to large-scale, phishing-driven ransomware campaigns. So choosing to pay a ransom could come with an even heftier price tag in the near future.

Personalization made easy: no code required
Typically, a ransom payment amount is provided by a command and control server or is hardcoded into the executable. But Malware Hunter Team recently discovered a new ransomware variant called Fantom that uses the filename to set the size of the ransom demand. A post on the BleepingComputer blog explains that this allows the developer to create various distribution campaigns using the same exact sample, but request different ransom amounts depending on how the distributed file is named—no code changes required. When executed, the ransomware will examine the filename and check if it contains certain substrings. Depending on the matched substrings, it will set the ransom to a particular amount.

Businesses beware
The news is salt in the wound for businesses, which have already been targeted by ransomware at a growing pace with higher price demands. A 2016 Symantec survey found that while consumers account for a slight majority of ransomware attacks today, the long-term trend shows a steady increase in attacks on organizations.

Those most vulnerable? Healthcare and financial organizations, according to a 2016 global ransomware survey by Malwarebytes. Both industries were targeted well above the average 39 percent ransomware penetration rate. Over a one-year period, healthcare organizations were targeted the most at 53 percent penetration, with financial organizations a close second at 51 percent.

And while one-third of ransomware victims face demands of $500 or less, large organizations are being extorted for larger sums. Nearly 60 percent of all enterprise ransomware attacks demanded more than $1,000, and more than 20 percent asked for more than $10,000, according to the Malwarebytes survey.

A highly publicized five-figure ransom was demanded of the Los Angeles-based Hollywood Presbyterian Medical Center in February. A ransomware attack disabled access to the hospital’s network, email and patient data. After 10 days of major disruption, hospital officials paid the $17,000 (40-bitcoin) ransom to get their systems back up. Four months later, the University of Calgary paid $20,000 CDN in bitcoins to get its crippled systems restored.

Now with a new price-discrimination Fantom on the loose, organizations can expect to be held hostage for even higher ransoms in the future.

Susan Richardson

[Cloud Security Alliance Blog]

Risks, Benefits of Geolocation Technology

Geolocation technology has become a mainstay in society, utilized for everything from navigation tools to social media platforms and even online gaming.

The recent Pokémon Go craze has shown just how pervasive location-based apps can be. But despite using the technology on a daily basis, many consumers—and even practitioners—do not have a solid understanding of how geolocation technology works. Just how does Yelp offer you a nearby dinner recommendation or RunKeeper track your daily miles?

ISACA set out to demystify geolocation technology with our new infographic, What Is Geolocation and How Does It Work? The infographic describes the types of data that are collected and how they are used to create accurate results. It also discusses the 3 main uses of geolocation technology, which include:

  • Geo-referencing:  finding the physical location of an object relative to a map
  • Geo-coding:  searching available types of objects or services by location
  • Geo-tagging:  embedding geographic data into an object’s metadata for future reference

For many businesses, use of geolocation and mobile technologies is critical to success. The benefits of using geolocation technology can be realized in many industries, such as manufacturing, retail and financial services. Asset management, content customization and fraud detection are just a few areas where businesses are successfully using location-based technologies.

As with any technology, geolocation does come with its own set of risk. Concerns around privacy, safety and security of data abound. Mitigating the risk associated with geolocation requires a two-pronged approach of technology safeguards on the business end as well as increased awareness from users.
For individuals wanting a deeper dive into geolocation technology, including governance and assurance considerations and strategies for addressing risk, see the ISACA Journal Online-Exclusive article Geolocation: Risk and Benefits.

Betsie Estes, Research Resource Manager, ISACA

[ISACA Now Blog]

Cyber Security Tip for CISOs: Beware of Security Fatigue

What’s the most effective thing you can do for cyber security awareness? Stop talking about it, according to a new study that uncovered serious security fatigue among consumers. The National Institute of Standards and Technology study, published recently, found many users have reached their saturation point and become desensitized to cyber security. They’ve been so bombarded with security messages, advice and demands for compliance that they can’t take any more—at which point they become less likely to comply.

Security fatigue wasn’t even on the radar
Study participants weren’t even asked about security fatigue. It wasn’t until researchers analyzed their notes that they found eight pages (single-spaced!) of comments about being annoyed, frustrated, turned off and tired of being told to “watch out for this and watch out for that” or being “locked out of my own account because I forgot or I accidentally typed in my password incorrectly.” In fact, security fatigue was one of the most consistent topics that surfaced in the research, cited by 63 percent of the participants.

The biases tied to security fatigue
When people are fatigued, they’re prone to fall back on cognitive biases when making decisions. The study uncovered three cognitive biases underlying security fatigue:

  • Users are personally not at risk because they have nothing of value—i.e., who would “want to steal that message about how I made blueberry muffins over the weekend.”
  • Someone else, such as an employer, a bank or a store is responsible for security, and if targeted, they will be protected—i.e., it’s not my responsibility
  • No security measures will really make a difference—i.e., if Target and the government and all these large organizations can’t protect their data from cyber attacks, how can I?

The repercussions of security fatigue
The result of security fatigue is the kind of online behavior that keeps a CISO up at night. Fatigued users:

  • Avoid unnecessary decisions
  • Choose the easiest available option
  • Make decisions driven by immediate motivations
  • Behave impulsively
  • Feel a loss of control

What can you do to overcome employee security fatigue?
To help users maintain secure online habits, the study suggests organizations limit the number of security decisions users need to make because, as one participant said, “My [XXX] site, first it gives me a login, then it gives me a site key I have to recognize, and then it gives me a password. If you give me too many more blocks, I am going to be turned off.”

The study also recommends making it simple for users to choose the right security action. For example, if users can log in two ways—either via traditional username and password or via a more secure and more convenient personal identity verification card—the card should show up as the default option.

Susan Richardson, Manager/Content Strategy, Code42

[Cloud Security Alliance Blog]

11 Cyber Threat Intelligence Tips

To remain in ignorance of the enemy’s condition simply because one grudges the outlay of a hundred ounces of silver…is the height of inhumanity. Thus what enables the wise sovereign and the good general to strike and conquer…is foreknowledge. – excerpt from Sun Tzu’s Art of War

Background
Cyber Threat Intelligence (CTI), simply put, is timely, accurate and actionable threat, vulnerability and incident information that highlight indicators of compromise to the consumer. The objective of a CTI strategy should be to improve your overall cyber security posture through situational awareness of, and targeted response to, security threats including:  malware, insider threat, espionage, hacktivism, cybercrime and other emerging threats.

What Challenges Do Organizations Face With CTI?
On paper, most chief information security officers (CISOs) understand the need for a CTI strategy. In practice however, real-world challenges exist with implementing such a strategy. Frequently asked questions include:

  • How do I select the best threat intelligence vendors for my organization?  As simple as it sounds, the answer depends on your organization’s threat landscape. Working out your key threat actors (e.g., internal threats vs. nation-states) and threat vectors beforehand will point you towards the type of CTI feeds you need. Before purchasing, challenge vendors on the breadth, depth and industry relevance of their intelligence feeds.
  • How do I make sense of CTI without drowning in a sea of data? With the volume of information available from threat intelligence sources, including open source intelligence (OSINT), vendors, and public and private sharing platforms, employing the use of big data analytics and visualization techniques is expedient.
  • Do we have the right skills in-house to analyse all those data? Organizations often make the mistake of thinking that CTI is only needed at the technical level. In reality, the right mix of CTI skills should include both technical (e.g., SOC analysts responsible for tactical security incident response) and nontechnical skills (i.e., analysts who understand business priorities and are able to use CTI for strategic risk management).

Below is a summary of some best practices around CTI which auditors and security executives can use as a conversation starter.

CTI Dos:

  • Have a documented risk-based CTI strategy—Understand your cyber threat landscape and determine what CTI feeds you need on that basis. Additionally, document how CTI will be obtained, how frequently it will be collected, who will consume it and what they are expected to do with it.
  • Establish communication channels between CTI and business intelligence functions—Do not lose sight of the operating environment when collecting and analyzing threat intelligence. External business factors could provide additional insight into cyber threats and could help shape your CTI strategy.
  • Expect to pay for good threat intelligence—Paraphrasing the words of Sun Tzu, when winning matters to you, “do not begrudge the outlay of a hundred ounces of silver for foreknowledge about your enemy.”
  • Have a management-approved process for sharing your intelligence with peers, regulators, industry groups and law enforcement—When it comes to CTI, the growing refrain is “one for all and all for one.” No one is an island these days.
  • You cannot buy institutional knowledge—The best CTI resources are often those who already understand how your business works and who can bring that knowledge to bear on the analysis of CTI. Consider upskilling internal resources before hiring externally.

CTI Don’ts:

  • Don’t collect threat intelligence for the sake of collecting it—To get the best answers from CTI, we must first ask the right questions of the data. Establishing CTI requirements upfront and anticipating changes to those requirements are important aspects of any strategy.
  • Don’t expect to make sense of it all immediately—Achieving the right balance between collection, analysis and delivery of actionable intelligence will take time.
  • Don’t forget that your third-party IT suppliers complement your CTI strategy—Every technology provider you use is part of your CTI strategy.

In a recent global survey of security executives,1 36% of respondents stated that they did not have a threat intelligence program, with a further 30% only having an informal approach, while only 5% said that their organization had achieved an advanced threat intelligence function. Having a clear CTI strategy could improve these stats and help organizations improve their anticipation and response to threats.

Editor’s note:  October is Cyber Security Awareness Month in many countries around the world. ISACA is a 2016 Champion sponsor organization of the National Cyber Security Alliance’s (NCSA) National Cyber Security Awareness Month. For more information click here.

1 EY, “2015 Global Information Security Survey (GISS),” www.ey.com/GL/en/Services/Advisory/ey-global-information-security-survey-2015-1

Omo Osagiede, Director and Independent Security Consultant, Borderless-I Consulting Limited

[ISACA Now Blog]

Krebs: Ransomware Getting More Targeted, Expensive

Editor’s note:  The following is an excerpt of a recent blog by Brian Krebs that first appeared in KrebsonSecurity.com. Krebs is an investigative journalist, founder of Krebs on Security, and a former Washington Post reporter with a passion for computer security. He will be the opening keynote speaker at CSX 2016 North America, which takes place in Las Vegas 17-19 October. Krebs will share unique insights gained from years of research and writing, as well as his unprecedented access to some of the smartest and most innovative cyber minds on the planet. He shares how it is important to take risks, make mistakes and learn from them. After the presentation, Krebs will autograph copies of his bookSpam Nation, a New York Times best seller.

I shared a meal not long ago with a source who works at a financial services company. The subject of ransomware came up and he told me that a server in his company had recently been infected with a particularly nasty strain that spread to several systems before the outbreak was quarantined. He said the folks in finance didn’t bat an eyelash when asked to authorize several payments of $600 to satisfy the Bitcoin ransom demanded by the intruders: After all, my source confessed, the data on one of the infected systems was worth millions — possibly tens of millions — of dollars, but for whatever reason the company didn’t have backups of it.

This anecdote has haunted me because it speaks volumes about what we can likely expect in the very near future from ransomware — malicious software that scrambles all files on an infected computer with strong encryption, and then requires payment from the victim to recover them.

What we can expect is not only more targeted and destructive attacks, but also ransom demands that vary based on the attacker’s estimation of the value of the data being held hostage and/or the ability of the victim to pay some approximation of what it might be worth.

In an alert published today, the U.S. Federal Bureau of Investigation (FBI) warned that recent ransomware variants have targeted and compromised vulnerable business servers (rather than individual users) to identify and target hosts, thereby multiplying the number of potential infected servers and devices on a network.

“Actors engaging in this targeting strategy are also charging ransoms based on the number of host (or servers) infected,” the FBI warned. “Additionally, recent victims who have been infected with these types of ransomware variants have not been provided the decryption keys for all their files after paying the ransom, and some have been extorted for even more money after payment.”

According to the FBI, this recent technique of targeting host servers and systems “could translate into victims paying more to get their decryption keys, a prolonged recovery time, and the possibility that victims will not obtain full decryption of their files.”

Today there are dozens of ransomware strains, most of which are sold on underground forums as crimeware packages — with new families emerging regularly. These kits typically include a point-and-click software interface for selecting various options that the ransom installer may employ, as well as instructions that tell the malware where to direct the victim to pay the ransom. Some kits even bundle the HTML code needed to set up the Web site that users will need to visit to pay and recover their files.

To some degree, a variance in ransom demands based on the victim’s perceived relative wealth is already at work. Lawrence Abrams, owner of the tech-help site BleepingComputer, said his analysis of multiple ransomware kits and control channels that were compromised by security professionals indicate that these kits usually include default suggested ransom amounts that vary depending on the geographic location of the victim.

“People behind these scams seem to be setting different rates for different countries,” Abrams said. “Victims in the U.S. generally pay more than people in, say, Spain. There was one [kit] we looked at recently that showed while victims in the U.S. were charged $200 in Bitcoin, victims in Italy were asked for just $20 worth of Bitcoin by default.”

In early 2016, a new ransomware variant dubbed “Samsam” (PDF) was observed targeting businesses running outdated versions ofRed Hat‘s JBoss enterprise products. When companies were hacked and infected with Samsam, Abrams said, they received custom ransom notes with varying ransom demands.

“When these companies were hacked, they each got custom notes with very different ransom demands that were much higher than the usual amount,” Abrams said. “These were very targeted.”

Which brings up the other coming shift with ransomware: More targeted ransom attacks. For the time being, most ransomware incursions are instead the result of opportunistic malware infections. The first common distribution method is spamming the ransomware installer out to millions of email addresses, disguising it as a legitimate file such as an invoice.

Editor’s note:  To read the entire blog at KrebsonSecurity.com, click here. For more on CSX 2016 North America click here. There will be two additional CSX conferences this year, including the inaugural CSX 2016 Europe conference 31 October-2 November in London, and the inaugural CSX 2016 Asia Pacific conference 14-16 November in Singapore.

REGISTER NOW

Brian Krebs, Investigative Journalist, Author, Krebs on Security

[ISACA Now Blog]

English
Exit mobile version