Media Alert: Sophos Reports on the Realities of Ransomware
Multi-Part Series Examines Escalating Detection Evasion Techniques and 5 Early Warning Signs Organizations are About to be Hit by Ransomware
Rapidly Changing Attacker Behaviors and Remote Working Signals Urgent Need to Future-Proof and Layer Security
OXFORD, United Kingdom, Aug. 04, 2020 (GLOBE NEWSWIRE) -- , a global leader in next-generation cybersecurity, today published a multi-part research series on the , including an industry-first detailed look at new detection evasion techniques in that leverage the Windows Cache Manager and memory-mapped I/O to encrypt files. A complementary article examines the , providing a months-long review of how cybercriminals have been escalating and markedly changing evasion techniques, tactics and procedures (TTPs) since in December 2019.
The article series also breaks down the and .
“The reality is, ransomware is not going away. At Sophos, we’ve seen gangs like WastedLocker taking evasive tactics to a new level and now even finding ways to bypass behavioral anti-ransomware tools. This is the latest example of attackers getting their hands dirty, using new maneuvers to manually disable software as a precursor to a full blown ransomware attack. Other stealthy activities like exfiltrating data and disabling backups are also precursors. The longer attackers are in the network, the more damage they can inflict,” said Chester Wisniewski, principal research scientist, Sophos. “This is why human intelligence and response are critical security components to detect and neutralize early indicators that an attack is underway. Organizations need to know about escalating trends and harden their perimeter by disabling remote access tools like RDP whenever possible to prevent crooks from gaining access to the network, a common denominator in many ransomware attacks that Sophos analyses.”
The combination of these changing attacker behaviors and remote and/or hybrid working environments due to the global COVID-19 pandemic is signaling an urgent need for organizations to prioritize IT security. Businesses also need to future-proof security implementations in anticipation of always-adapting adversaries, disintegrating boundaries and the expanded attack surface caused by COVID-19.
The Lineup of Sophos Research Includes
Immediate Advice for Defenders
- Shut down internet-facing remote desktop protocol (RDP) to deny cybercriminals access to networks
- If you need access to RDP, put it behind a VPN connection
- Use layered security to prevent, protect and detect cyberattacks, including endpoint detection and response (EDR) capabilities and managed response teams who watch networks 24/7
- Be aware of the to stop ransomware attacks
Researchers from SophosLabs and Sophos Managed Threat Response contributed to the series. For additional information, please reference and .
Additional Resources
- Read about additional ransomware and security news on
- Learn about the threat landscape and trends in 2020 in the
- Connect with Sophos on , , , , and
Sophos Resources Related to Cybersecurity During The COVID-19 Crisis
- has uncovered a variety of different malicious email campaigns connected to COVID-19, as detailed in the . Follow the SophosLabs Twitter feed for breaking SophosLabs discoveries:
- provides tips and free resources as people navigate the work-from-home tech/security gauntlet:
- provided security tips on remote working, safe video conferencing and more, plus the latest industry news. Click for easy access to all
About Sophos
As a worldwide leader in next-generation cybersecurity, Sophos protects more than 400,000 organizations of all sizes in more than 150 countries from today’s most advanced cyber threats. Powered by SophosLabs – a global threat intelligence and data science team – Sophos’ cloud-native and AI-powered solutions secure endpoints (laptops, servers and mobile devices) and networks against evolving cyberattack techniques, including ransomware, malware, exploits, data exfiltration, active-adversary breaches, phishing, and more. Sophos Central, a cloud-native management platform, integrates Sophos’ entire portfolio of next-generation products, including the Intercept X endpoint solution and the XG next-generation firewall, into a single “synchronized security” system accessible through a set of APIs. Sophos has been driving a transition to next-generation cybersecurity, leveraging advanced capabilities in cloud, machine learning, APIs, automation, managed threat response, and more, to deliver enterprise-grade protection to any size organization. Sophos sells its products and services exclusively through a global channel of more than 53,000 partners and managed service providers (MSPs). Sophos also makes its innovative commercial technologies available to consumers via Sophos Home. The company is headquartered in Oxford, U.K. More information is available at .
Press Contacts: Lesley Sullivan, Sophos Hanah Johnson