Showing posts with label Ransomware. Show all posts
Showing posts with label Ransomware. Show all posts

Thursday, 27 October 2016

There is a lot of variations in evil e-mail the last couple of days.

I yearn for the days when evil e-mail was so easily identified "becuse it wuz ritten in, gud, inglish wit grate spellhng an pun.tation". ðŸ˜ƒ

In the last couple of days, the evil doers have been varying their scam e-mails fairly wildly and it's bound to catch out some people.

I'll run through three sneaky methods that have been attempted on others over the last 48 hours.

Thursday, 29 September 2016

Using the Internet Safely. Training from L2 Cyber Security Solutions.

Human Error
Did you know that evil software gets past commercial anti-virus and e-mail filtering products on a worryingly regular basis.

Firewalls and Anti-virus packages lure people into a false sense of security. While they do provide protection up to a point, if somebody opens an e-mail attachment that contains new Malware, these protections are effectively useless.

Cyber incidents, most notably Ransomware attacks have seen massive increases recently. 93% of phishing e-mails in Quarter 1 2016 have carried a Ransomware payload (source - PhishMe Q1 2016 Malware review). 30% of people that receive phishing e-mails open them and 12% of those that do, then open attachments or click on links (source - Verizon 2016 Data Breach Investigations Report).

These statistics highlight the fact that a significant weak link in any organisation, where it comes to using the internet and e-mail, are THE STAFF, but it's not their fault.

The best protection to cover this gap are staff that are aware of what the threats are and how they manifest themselves. Once they are armed with the knowledge of what to look out for, they will be much less likely to cause a security breach.

The training that L2 Cyber Security Solutions delivers is comprehensive, yet simple for all to follow.

Using the Internet Safely

Course Outline

Lecture / Workshop


Duration:

1 day


Audience:

People who have access to and utilise the internet and e-mail, whether for personal or business purposes, as part of their day. 


Prerequisites:

A basic understanding of internet browsing and e-mail usage is a prerequisite.


Programme Aim:

This training will give the attendees an understanding of the risks and threats associated with using the internet and e-mail.


Learning Outcome:

The participants will know how they can take some simple steps to avoid being adversely affected by the various risks presented to them. They will also learn how to create unique and strong passwords.


Course Content:

  1. Malware (incl. Ransomware)
  2. Spam
  3. Social Engineering
  4. Phishing and Spear-Phishing (incl. CEO Fraud)
  5. Safe Web Browsing
  6. Good Security Practices
  7. Mobile Security
  8. Creating a unique and strong password

Call us on 087-436-2675 or e-mail info@L2CyberSecurity.com to discuss your requirements and get a quotation.

Friday, 23 September 2016

Snail mail delivers USB keys ... WTF?


I find I'm writing a second article about Evil USBs within a week. At least these ones don't destroy your equipment, but they might infect you with nasty software that does things that you really wouldn't want it doing.

In this case, in Victoria, Australia, Evil Doers were dropping USB drives into people's mailboxes. The report from Victoria Police stated:
Upon inserting the USB drives into their computers victims have experienced fraudulent media streaming service offers, as well as other serious issues.
The USB drives are believed to be extremely harmful and members of the public are urged to avoid plugging them into their computers or other devices.

Wednesday, 31 August 2016

Repeat after me ... Microsoft do NOT e-mail out system updates!


More evil e-mail is coming to scramble all the files on your computer and then demand you to pay your hard earned cash in order to get back access to same. In other words you are being held to Ransom and so we get the term Ransom Software or Ransomware for short.

Tuesday, 9 August 2016

"Attack" on Garda systems is likely a Ransomware incident.

Now that the dust is settling after the IT Security incident, which caused the Garda Síochána (the Irish Police force) to shut down access to their systems late last week, it would appear that it wasn't quite as nefarious an incident as was being portrayed in the media.

Headlines such as "Mob target Garda computers" were wildly speculative and likely wildly wrong. 

According to Brian Honan, a respected IT Security expert, quoted in an article in today's Irish Times, "his 'best guess' was that the Garda systems had been hit by ransomware. From reading what’s available, this does not seem to me to be a targeted attack."

With reporters throwing around phrases like "Advanced Persistent Threat" (APT) and "Targeted Attack" like snuff at a wake, it's no wonder the headlines were sensational.

While full details are still not available, if this had been the result of a genuine Advanced Persistent Threat, then its quite likely that the evil doers were inside Garda systems for quite some time (that's what the "persistent" bit of this term means). In this case I wouldn't think they would have been able to restore access to their systems quite as quickly as they did. Hence a simple ransomware incident is quite likely.

Edit: Those fun guys over at Waterford Whispers News (a satirical website) had a different view:
http://waterfordwhispersnews.com/2016/08/09/we-tried-installing-windows-10-gardai-reveal-reason-behind-it-shutdown/

Thursday, 14 July 2016

Evil doers just being evil ... news at 11!

The good folk over at Cisco's Talos Threat Intelligence Organisation have been looking at a new piece of "apparent" Ransomware called Ranscam.

The reason I use "apparent" is because it doesn't hold any of your data to ransom, quite simply because it's deleted it already! That doesn't stop it trying to get you to pay them good money, and even if you did pay up, you'll get nothing in return.

As we covered in Commandment IV of our Ten Commandments, if you have a good backup set up, then you need not concern yourself with whether Ransomware has or has not locked away your data. You simply wipe your equipment of the nasty malware and restore your data.

Ranscam isn't too widely spread at the moment and Talos reckon it was cobbled together rather quickly to try to cash in on this Ransomware market.

You can read the Talos report here:

If you want to get your staff to learn what steps they can take to reduce the risk of your business being affected by Ransomware, then check out the Security Awareness Training that is available from L2 Cyber Security.

Monday, 11 July 2016

Security Awareness Training by L2 Cyber Security Solutions.

Cyber incidents, most notably Ransomware attacks have seen massive increases recently. 93% of phishing e-mails in Quarter 1 2016 have carried a Ransomware payload (source - PhishMe Q1 2016 Malware review). 30% of people that receive phishing e-mails open them and 12% of those that do, then open attachments or click on links (source - Verizon 2016 Data Breach Investigations Report).

These statistics highlight the fact that a significant weak link in any organisation, where it comes to using the internet and e-mail, are THE STAFF, but it's not their fault.

Firewalls and Anti-virus packages lure people into a false sense of security. While they do provide protection up to a point, if somebody opens an e-mail attachment that contains new Malware, these protections are effectively useless.

The best protection to cover this gap are staff that are aware of what the threats are and how they manifest themselves. Once they are armed with the knowledge of what to look out for, they will be much less likely to cause a security breach.


The training that L2 Cyber Security Solutions delivers is comprehensive, yet simple for all to follow.

Security Awareness Training

Course Outline

Lecture / Workshop


Duration:

1 day


Audience:

People who have access to and utilise the internet and e-mail, whether for personal or business purposes, as part of their day. 


Prerequisites:

A basic understanding of internet browsing and e-mail usage is a prerequisite.


Programme Aim:

This training will give the attendees an understanding of the risks and threats associated with using the internet and e-mail.


Learning Outcome:

The participants will know how they can take some simple steps to avoid being adversely affected by the various risks presented to them. They will also learn how to create unique and strong passwords.


Course Content:

  1. Malware (incl. Ransomware)
  2. Spam
  3. Social Engineering
  4. Phishing and Spear-Phishing (incl. CEO Fraud)
  5. Safe Web Browsing
  6. Good Security Practices
  7. Mobile Security
  8. Creating a unique and strong password


Call us on 087-436-2675 or e-mail info@L2CyberSecurity.com to discuss your requirements and get a quotation.

Wednesday, 29 June 2016

Microsoft Office 365 users hit by massive Ransomware phishing campaign.

It is estimated that 57% of customers using Microsoft's Office 365 platform received at least one copy of the Cerber Ransomware. They will have received a word document attachment which, if it were opened, would appear as follows:


Note the big banner with red text asking for the "Enable Content" button to be clicked. No reputable document would contain such a request.

So if you have not adhered to Commandment V and have opened a document from a stranger - don't click Enable Content or any other button other than the X in the top-right-corner of the Word Window and delete the e-mail that contained the document.

Full details from the company that detected the attack is here.