Original Release Date: 7/7/2015
TLP: WHITE
The NJCCIC assesses ransomware infections will continue to increase steadily and pose a threat to the public and private sector, as well as home users, as the technical barriers to conduct these cybercrime campaigns continue to drop and the return on investment for cybercriminals remains extremely high. The NJCCIC recommends all organizations and home users familiarize themselves with ransomware tactics and implement the necessary security and backup strategies to mitigate this threat. Ransomware variants are likely to increasingly target mobile devices as users rely more heavily on tablets and smartphones, and also bundle with additional malware designed to steal login credentials and financial information. Moreover, the tactics used to distribute malware through spam emails or compromised websites are becoming more sophisticated, as are anti-forensic capabilities that enable malware to delete themselves after infection in order to avoid detection, extraction, and examination.
Ransomware is a type of malicious software (malware) that attempts to extort money from victims by restricting access to a computer system or files. The most prevalent form of this profit-motivated malware, referred to as crypto-ransomware due to the use of encryption algorithms, is on the rise as many new variants are being developed by hackers and international cybercrime groups. The security firm Symantec reported a 112 percent increase in ransomware attacks in 2014, largely due to a 4,000 percent increase in crypto-ransomware infections. In the first quarter of 2015, ransomware infections rose 165 percent according to McAfee Labs.
Traffic Light Protocol: WHITE information may be distributed without restriction.