Endpoint

9/7/2017
04:00 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Microsoft: Ransomware Decline Reversed in March 2017

Researchers discovered 71 new ransomware families in the first half of 2017, when attacks picked up after several months of decline.

Ransomware encounters consistently declined from August 2016 through March 2017, when the trend reversed and attacks became more frequent and complex, Microsoft researchers found.

Microsoft's Security Intelligence Report, which summarizes the threat landscape for the first quarter of 2017, highlighted a global increase in ransomware. In a new, second report released this week the the company, researchers take a deeper dive into the evolution of ransomware and explore how attacks became more complex in the first half of this year.

New ransomware families are being released at a faster rate and contributed to the March turnaround. In the first half of 2017, researchers discovered 71 new ransomware families, an increase from the 64 new families uncovered during the same timeframe in 2016.

"From a timeline perspective, around March and April, major ransomware families, like Locky, which were dormant early in the year came back with some major campaigns, contributing to the turnaround," says Microsoft security expert Tanmay Ganacharya.

Several new families stand out for their complexity, using techniques that had never been used in previous families, or had been improved on. Spora, for example, overtook established ransomware operation Cerber as the most common ransomware family during the first half of 2017. Researchers attribute the growth to its ability to spread via network drives and removable drives.

The report contains details on global ransomware outbreaks WannaCry and new variant of Petya, which was frequently called NotPetya in the aftermath of the attack. Both attacks wreaked havoc on Windows users in May and June 2017.

"WannaCrypt and Petya defied the trend of more targeted and localized attacks and became the first global malware attacks in quite a while," writes Microsoft in a blog post. "They generated worldwide mainstream interest. Interestingly, this attention might have added more challenges for attackers," who could not access their monitored Bitcoin wallets.

NotPetya, WannaCry, Spora, and other new ransomware variants incorporate complex techniques that enable a faster and more dangerous spread than earlier forms of malware.

New forms of ransomware use exploits to move laterally, as demonstrated in Spora's ability to spread via network drives. WannaCry exploited the EternalBlue vulnerability (CVE-2017-0144), and NotPetya expanded on this by abusing both EternalBlue and EternalRomance (CVE-2017-0145) to affect out-of-date systems. Both exploits were addressed in earlier security updates.

Other complex techniques include credential theft, which NotPetya did by stealing from Credential Score or using a credential dumping tool. Credential theft poses a security challenge to networks where users log in with local administrative privileges and have active sessions open on several machines. In case of NotPetya, stolen login data could provide the same level of access that users have on other devices.

"The Petya outbreak is testament to the importance of credential hygiene," the researchers wrote. "Enterprises need to constantly review privileged accounts, which have unhampered network access and access to corporate secrets and other critical data."

Ransomware can also spread via network scanning; NotPetya, for example, scanned infected networks to connect with other machines. When it found them, it tried to transfer copies of malware using stolen credentials, and scanned for network shares to try and grow further.

WannaCry used a different strategy and scanned IP addresses to seek computers vulnerable to the EternalBlue exploit. This technique allowed it to spread outside the network to machines that hadn't been updated with the necessary patch.

"We expect that cybercriminals will continue to use threats like ransomware because history has shown people will pay to unlock their devices," Ganacharya says. Based on the current climate, it's possible there could be twice as many ransomware attacks in 2017 than in 2016.

"Specifically, we expect to see a combination of mass-targeted, low-sophistication ransomware families and some highly sophisticated targeted ransomware attacks, especially against older platforms that don’t have the security robustness of the modern operating systems," he says.

Related Content:

Kelly Sheridan is Associate Editor at Dark Reading. She started her career in business tech journalism at Insurance & Technology and most recently reported for InformationWeek, where she covered Microsoft and business IT. Sheridan earned her BA at Villanova University. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
tcritchley07
50%
50%
tcritchley07,
User Rank: Strategist
9/8/2017 | 4:43:01 PM
Ransomeware Upsurge in 2017
I now neglect to worry about what type of malware is causing havoc. The problem is simple (not necessarily the solution); the internet is full of holes, like a sieve, and the need is to tackle the holes and not the individual shape of the holes (type of malware). Even the old vintage malware methods still work today which must tell the intelligent person that the 'patch, watch, pray and hope' methods aren't working. What is needed is a review  of all flaky products which fuel the internet and make them fit a new, secure architecture or be replaced. Governments and large companies can enforce this new regime as a condition of purchase; no fit new standard, no buy. It is done in other IT areas. There are too many people making good livings out of the status quo, for example, people in the know selling security services to gullible companies in the knowledge that their income is  safe in the current status of cybersecurity, sometimes relying on the old standby of FUD.
Researchers Offer a 'VirusTotal for ICS'
Kelly Jackson Higgins, Executive Editor at Dark Reading,  1/16/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The Year in Security: 2017
A look at the biggest news stories (so far) of 2017 that shaped the cybersecurity landscape -- from Russian hacking, ransomware's coming-out party, and voting machine vulnerabilities to the massive data breach of credit-monitoring firm Equifax.
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.