Ransomware attacks quadrupled in Q1 2016
Full article697 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Ransomware has taken off in 2016, already eclipsing the number of attacks observed in a recently published threat report from Symantec.
Ransomware has taken off in 2016, with attacks in the first quarter coming at quadruple the rate seen last year, according to figures from a leading security vendor.
Kevin Haley, the director of product management at Symantec Security Response, said his group has seen an average of over 4,000 ransomware attacks per day since Jan. 1, a 300-percent increase over the approximately 1,000 attacks per day in 2015 the company highlighted in its recent Internet Security Threat Report.
During a media roundtable Thursday, Haley said the spike is due to the success attackers are having in targeting a broad variety of business sectors and the ease with which attacks can be carried out.
“It’s really profitable, there is very little risk, and you don’t have to resell the data anywhere,” Haley said. “It’s pure profit.”
Haley said his company saw a spike once Hollywood Presbyterian Medical Center announced it paid $17,000 to hackers in February after it was hit with a ransomware attack.
Earlier this month, Columbia, Maryland-based MedStar Health was hit with a similar attack, where hackers asked for $19,000 to decrypt the company’s data.

A timeline chart of discovered ransomware. (Symantec)
Haley said the gangs using ransomware have honed their social engineering efforts to target the right people for spear phishing emails. The malware is packaged in a phony email attachment, often a phony invoice.
“If I send you something that says ’Here is a bill and you owe money on this,’ you are going to click through,” Haley said.
Attackers are also growing more sophisticated with how they deploy the malware once they gain access to a system. The responsible parties often wait a week to encrypt data so when an IT department uses a restore point, their malware remains in the system.
Haley recommended that to avoid this, security specialists should be deploying backups of operating systems instead of reverting to restore points.
Over the past year and a half, Haley said his company has seen thousands of unique malware variants used in various ransomware campaigns, which target different operating systems, web servers and internet-connected devices.
For the company’s threat report, Haley’s team found a way to install an Android-based ransomware known as Simplocker onto a smartwatch and internet-connected TV. While Symantec has yet to see that type of attack used by real-life criminals, Haley said there is “no reason it couldn’t be done.”
Android is more likely to be targeted than Apple iOS due to the closed nature of Apple’ App Store and the faster distribution of updates that close vulnerabilities. The nature of the Android eco-system, where phone owners are dependent on carriers and handset manufacturers to distribute system updates, means “there is a much greater chance you are going to see an old version of Android out in the wild than Apple iOS,” Haley said.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ransomware-attacks-quadrupled-in-q1-2016/