Guarding Against Ransomware

Guarding Against Ransomware

Ransomware has become a major threat for business around the world. Payments to retrieve data stolen by ransomware costs organizations hundreds of millions of dollars every year.

This type of malware works by forcefully encrypting the files on your computer using an encryption key only known to the attackers. They will then contact you and demand a ransom to get the encryption key to decrypt the files.

Ransomware Solutions

We have received many requests in the past for assistance in resolving issues caused by ransomware, but unfortunately once the files are encrypted it is often impossible to recover them without the proper encryption key.

The only truly effective solution to resolve ransomware attacks involves two steps:

  1. Eliminate the actual malware and access to your system that the attackers have. Even if you recover the files, if the attacker still has access to your system they can attack again.
  2. Recover the files from a backup created prior to the encryption. It is important to always maintain backups, especially for business critical data. It is also important to keep off-site backups. Modern cloud-based backup solutions make this easy. For more information about Evo-ERP backups, click here.

How does Ransomware Spread?

Ransomware and other forms of malware often spread via phishing, often in emails. A phishing email is an email designed to look authentic but is actually fake. In extreme cases (often called spear-phishing), the attacker will use personal information of the victim to make the email look even more authentic.

The victim opens the email and might click a link or download an attachment that contains the malware. Once the malware is on the network, it can often spread to other computers.

When you’re opening emails, try to keep these things in mind:

  1. Verify the sender of the email. Often, phishing emails will come from random email addresses that you don’t recognize. However, if someone else is infected, it is possible for the malware to send email on their behalf. If the email is coming from someone you know, does it look like it was written by them?
  2. Are you expecting this email? A common phishing technique is to send an email with a subject like UPS Tracking Info for a fake shipment and the tracking link goes to a malicious website.
  3. Avoid clicking links in emails. Links can have different text than the actual URL. For example, consider this link: https://www.google.com. You can usually mouse over a link to see where it actually goes. If the email is coming from an institution like a bank, it is better to manually go to the institution’s website in your browser from your bookmarks or by the correct URL that you know then finding the page they were trying to link in the email.
  4. Always be careful opening or downloading attachments in emails. Check the actual file extension before opening the attachment. Even if the attachment is a PDF, word document, or image file it’s possible some vulnerability in the software that opens the attachment could cause malware to be installed.

Modern systems are often integrated with other networks or software. It is possible for vulnerabilities in these integrated systems to cause your system to become infected as well.

The bottom line is: ALWAYS HAVE A BACKUP.