FBI Alert: CryptoWall Ransomware Damage $18 Million

cryptowall14.jpg

The most used vector are phishing emails that have a zipped attachment that claims to be a resume.

The latest version 3.0 of CryptoWall, descendant of the infamous CryptoLocker, is the most advanced and most damaging ransomware in the wild at the moment, specifically targeting US businesses and individuals. We have been sounding the alarm about CryptoWall in CyberheistNews since last year, and its magnitude is now confirmed by law enforcement.

The FBI, through their Internet Crime Complaint Center (IC3), released an alert on June 23, 2015 that between April 2014 and June 2015, the IC3 received 992 CryptoWall-related complaints, with victims reporting losses totaling over $18 million. And that is only the reported part as the estimate is that the actual infections are at least two or three times more. Going by the reported incidents only, it's a $70 million per year criminal enterprise, but in reality it looks more like $200 million, which is unbelievable.

Some quick math shows $18,145 in costs per victim, caused by network mitigation, network countermeasures, loss of productivity, legal fees, IT services, and/or the purchase of credit monitoring services for employees or customers. As you can see, the total costs of a ransomware infection goes well above just the ransom fee itself, which is usually around $500 but can go up to $10,000.

The four infection vectors sorted by frequency:

  •     Phishing email with infected attachment
  •     Phishing email with malicious URL
  •     User clicks on infected ad
  •     User visits infected website

    
By far the most used vector at the moment is phishing emails that have a zipped attachment that claims to be the resume of a girl. Open it up and unzip it, and a page opens up with a link to another zipped file, which contains the payload. This tactic bypasses all antivirus engines and relies on social engineering your end user. 

A few months ago they used poisoned help-file attachments, and they continue to innovate fast to stay ahead of the spam filters. You probably know that defending a workstation against another workstation that has been compromised has a relatively good chance of success. However, defending a workstation against a malicious server is very difficult. This gang also uses malicious URLs which when clicked drive the user to a compromised website with an exploit kit. These exploit kits scan for known vulnerabilities in hundreds of applications that may not have been patched and can own the workstation in literally less than one second.

That is what infection vectors 2, 3 and 4 ultimately use, drive users to that compromised website and infect the workstation and/or network that way. It can go through a URL that drops the user onto that site, or an ad that redirects the user that way, or they compromise a site the user visits regularly and that is how they get infected. It's a nasty business, and it's growing. You are dealing with a criminal hybrid of very high quality coding, used for sophisticated digital hijacking, and supported by commercial-grade "customer service" which makes sure they can generate cash from their malware. Ironically, these gangs are concerned with their reputation in the market. If word goes out they do not decrypt, their revenue stream dries up because of bad word-of-mouth.

What To Do About It

IBM recently warned against spear phishing attacks using the Dyre Trojan for cyber heists of more than $1 million at a time, and suggested policy and procedures to block these attacks. Obviously things like having recent backups, excellent patching discipline and good filters at the network edge are a given. Their recommendations are on the mark:

Organisations will remain only as strong as their weakest link. Proactive end-user education and security awareness training continue to be critical in helping prevent incidents like the one described in this advisory.

Train employees on security best practices and how to report suspicious activity.

 Consider conducting periodic mock-phishing exercises where employees receive emails or attachments that simulate malicious behavior. Metrics can be captured on how many potential incidents would have happened had the exercise been a real attack. Use these findings as a way to discuss the growing security threats with employees.  

Offer security training to employees to help understand threats and measures they can take to protect the organization.
    
Provide regular reminders to employees on phishing and spam campaigns and that they shouldn’t open suspicious attachments or links from both work and personal emails.
    
Train employees in charge of corporate banking to never provide banking credentials to anyone. The banks will never ask for this information.
    
New school security awareness training, which combines web-based on-demand training by a social engineering expert, combined with frequent simulated phishing attacks is a must these days to protect your organisation against these kinds of attacks.

KnowB4:

 

« Naresh Singh : Freelance Ethical Hacker
The Double-Edged Sword of Cyber Warfare »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

ZenGRC

ZenGRC

ZenGRC (formerly Reciprocity) is a leader in the GRC SaaS landscape, offering robust and intuitive products designed to make compliance straightforward and efficient.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

National Cyber Security Centre (NCSC) - United Kingdom

National Cyber Security Centre (NCSC) - United Kingdom

The NCSC acts as a bridge between industry and government, providing a unified source of advice, guidance and support on cyber security, including the management of cyber security incidents.

ManagedMethods

ManagedMethods

ManageMethods Cloud Access Monitor is the only Cloud Access Security Broker (CASB) that can be deployed in minutes, with no special training, and with no impact on users or networks.

6cure

6cure

The 6cure Threat Protection solution eliminates malicious traffic to critical services in real time and protects against DDoS attacks.

Cygilant

Cygilant

Cygilant is a SOC2 certified service provider that combines MSSP and Incident Detection and Response (IDR) capabilities managed by global SOCs staffed with trained security engineers.

Dual Layer IT Solutions

Dual Layer IT Solutions

Dual Layer offer a full range of IT Services and Solutions for businesses from IT infrastructure design to cloud/hosted solutions, cybersecurity, disaster recovery and IT training.

Symantec

Symantec

Symantec delivers data-centric hybrid security for the largest, most complex organizations in the world – on devices, in private data centers, and in the cloud.

Seavus Accelerator

Seavus Accelerator

Seavus Accelerator's goal is to create an enabling and stimulating environment for start-ups growth and provide continuous high quality acceleration and investment support.

MISP Project

MISP Project

The MISP threat sharing platform is a free and open source software helping information sharing of threat intelligence including cyber security indicators.

Parameter Security

Parameter Security

Parameter Security is a provider of ethical hacking and information security services.

Revere Technologies

Revere Technologies

Revere Technologies is a pure-play cyber security solutions and services provider in Sub-Saharan Africa.

Saepio Solutions

Saepio Solutions

Saepio promote an all-encompassing approach to cybersecurity, ensuring the appropriate balance of budget and resource across Policy, Product and People.

OwnBackup

OwnBackup

OwnBackup proactively prevents you from losing mission-critical data and metadata with automated backups and rapid, stress-free recovery.

Custard Technical Services

Custard Technical Services

Custard provide Network Security for all types of businesses across many industries, helping to keep them safe and secure.

Bastion Networks

Bastion Networks

Bastion are a security-focussed managed solution provider and consultancy. We work with advanced cyber security vendors to produce managed security solutions to protect from online threats.

Black Duck Software

Black Duck Software

Black Duck (formerly the Synopsys Software Integrity Group) is the market leader in application security testing (AST).

Crisis24

Crisis24

Crisis24 is a leading integrated risk management, crisis response, consulting, and global protective solutions firm.