Ransomware – What is it, and how do I protect myself?

Following the highly-publicised Ransomware attack that the NHS have fallen victim to, along with many, many, others (although they don’t make as emotive headlines), various people have been in touch asking what essentially boils down to 3 questions:

1)     What is ransomware?

2)     How do I protect myself from it?

3)     How do I recover from it?

I’m going to be focusing this very much from a normal person’s point of view, because I know the details are pretty boring unless you’re a bit Nerdy. If you would like to know a bit more about this particular attack, or anything else I mention, please feel free to get in touch, either via LinkedIn or any of the contact details on here.

So, in order then:

What is “Ransomware”?

Ransomware is an attack approach that a computer virus, more commonly referred to as malware (from shortening malicious software), takes. Basically, a ransomware attack locks up all your files so you can’t access them, and it demands a ransom for the key needed to unlock them.

Until the WannaCrypt variant (the one that hit the NHS), the ransoms were normally around £2000 – £5000 and allegedly would unlock all the files. WannaCrypt ransoms are reportedly £200 – £500, but are per-PC that get attacked.

The payment is usually demanded in BitCoins, which is an anonymous crypto-currency (an electronic currency not tied to a traditional currency like $ USD, or £ GBP). It’s untraceable through it’s very design, so is great for demanding ransoms.

I say allegedly because I would never entertain the idea of paying the ransom. You are, after all, dealing with anonymous criminals who cannot be trusted.

How do I protect myself (or my business) from it?

This sounds like a really simple question, but the answer has multiple layers:

Please note: These tips apply to all computers, be that Windows, Apple Mac’s or even Linux. This is because all of the platforms are becoming targets now as more and more people use them.

Ensure you have a good backup & you do test restores regularly

A backup isn’t a backup unless you test it! Also, the key is to have multiple copies of your critical files.

Cloud storage providers (like DropBox & OneDrive) have their role to play in the wider backup and disaster recovery (DR) planning, but they aren’t a complete backup solution by themselves, especially if that’s where you store your “working” version of a file.

Apply the regular updates to your computer

This particular attack relies on vulnerabilities that were fixed in March with Windows Updates. I know the updates can be annoying, but in this case a gram of prevention far out-weighs a kilo of cure.

Install a reputable anti-virus software

The “next-gen” anti-virus offerings are a lot better at picking up on attacks as they start to appear in the world due to how they work behind the scenes. We’ve partnered with Webroot because we think they do an amazing job. They’re not the only one, but they are the one we work with.

Use a trusted 3rd party DNS provider

DNS translates domain names, like www.bbc.co.uk, in to the language the computers speak in. A good DNS provider will be able to filter out any requests to sites that are known to be malicious & also be able to stop any communications from the attackers to a compromised computer by “black-holing” the command & control communications.

Webroot are rolling out a DNS platform that we’re trialling with some customers. We’ve found it to be really good and are really impressed. Again, there are others, but we choose to work with Webroot.

How do I recover from it?

If you’ve been attacked, there is really only one course of action to take:

1.      Disconnect your computer from ALL network connections

2.      Get rid of the infection

3.      Restore your files from your backups

As I said earlier, I would never even entertain the idea of paying the ransom; after all, dealing with anonymous criminals who cannot be trusted.

Thanks for reading, if you have any questions, please feel free to get in touch.

Owen

Sources

https://www.theregister.co.uk/2017/05/13/wannacrypt_ransomware_worm/

http://www.bbc.co.uk/news/technology-39901382

https://www.microsoft.com/security/portal/threat/encyclopedia/Entry.aspx?Name=Ransom:Win32/WannaCrypt