COVID-19 Changes Ransomware Tactics
COVID-19 hasn't had much direct effect on the world of malware, but it may be why ransomware scams are getting scarily efficient. So says Microsoft in its latest "Digital Defense Report."
The report is based on Microsoft's experiences through its built-in and standalone security measures on consumer and business devices and networks. It covers the year from July 2019 though June 2020. (Source: microsoft.com)
Microsoft suggests COVID-19 itself hasn't made much difference to most forms of malware. That's something of a surprise given more people are working from home and thus sending potentially sensitive data across the Internet.
Ransomware Speeds Up
Instead, Microsoft concluded that the pandemic has led ransomware attackers to change tactics. Previously, they were highly targeted and would often involve finding a high value victim, infiltrating a system and then waiting until they were best placed to launch a successful attack.
Now it seems the scammers have concluded that businesses are much more vulnerable to losing access to data and thus are more likely to pay up quickly in the hope of getting back to action.
That's led the ransomware attackers to concentrate on speed rather than accuracy, aiming for lots of quick hits even if that lowers the chance of any one attack succeeding. Indeed, Microsoft cited some cases where it took less than 45 minutes between the attackers finding a way to access a computer to having encrypted an entire network and issued the ransom demand. (Source: zdnet.com)
Usernames Targeted
The report also detailed an increase in several specific cyber attack techniques. One is "password spraying" to try to break into accounts. It's an alternative to the brute force attack, which simply tries every possible combination of characters in a password. Password spraying instead takes a common password and then tries matching it with every possible username.
Also on the rise is complex spear phishing. Whereas phishing simply involves generic bogus messages aimed at tricking users into handing over login details and other sensitive data, complex spear phishing is a targeted technique. For example, the bogus message might appear to be an internal email from one staff member asking another for specific details.
What's Your Opinion?
Have you spotted a change in the type of attempted cyber scam in the past year? If you've started or increased remote working, how confident are you in the security measures? Is it useful for Microsoft to publish such reports?
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.