Sophos Investigative Report Lists India among Top 10 Countries to be Susceptible to SAMSAM Ransomware
On the 1st of August (2018) Sophos, a global leader in network and endpoint security had released a detailed investigative whitepaper on the SamSam ransomware attacks that first appeared in December 2015. The paper titled SamSam: The (Almost) Six Million Dollar Ransomware aimed to provide a comprehensive understanding of this unique ransomware attack by summarizing key findings about the attacker’s tools, techniques and protocols.
According to Peter Mackenzie, Global Malware Escalations Manager at Sophos, “Most ransomware is spread in large, noisy and untargeted spam campaigns using simple techniques to infect victims and demand relatively small sums in ransom. What sets SamSam apart is that it’s a targeted attack tailored to cause maximum damage and ransom demands are measured in the tens of thousands of dollars. The attack method is surprisingly manual, and more cat burglar than smash-and-grab. As a result, the attacker can employ countermeasures to evade security tools and if interrupted can delete all trace of itself immediately, to hinder investigation.”
Furthermore, unlike most ransomware, SamSam is a thorough encryption tool, rendering not only work data files unusable but any program that is not essential to the operation of a Windows computer, most of which are not routinely backed up. If the process of encrypting data is interrupted, the malware is capable of comprehensively erasing all trace of itself immediately, hindering any investigation. Furthermore, recovery from the attack may require reimaging and/or reinstalling software as well as restoring backups. As a result, many victims were not able to recover sufficiently or quickly enough to ensure business continuity, and had to pay the ransom.
SamSam’s relentless attack methodology combined with the growth in Ransomware-as-a-Service and the anticipation of the ever evolving threat landscape emphasizes the need for a layered and synchronized cybersecurity approach for businesses of all sizes. Thus Mackenzie further added, “SamSam is a reminder to businesses that they need to actively manage their security strategy. By deploying a defense-in-depth approach, they can ensure their network is less visible and open to attack to avoid being the low hanging fruit the hacker is searching for. We recommend IT managers follow security best practices, including hard-to-crack passwords and rigorous patching.”
“Our recently conducted ‘The State Of Endpoint Security Survey’ revealed that 90% of the businesses in India have been either hit or expected to hit by ransomware and more than 90% of Indian IT decision makers surveyed, were running up to date endpoint protection at the time of attack, confirming that traditional endpoint security is no longer enough to protect against today’s evolving ransomware threats. This is an attack pattern we’re likely to see an increase in India and it is time for Indian business and individuals to synchronize their cybersecurity posture to defend against such attacks,” concludes Mackenzie.
Sophos recommends top four security measures to Restrict access to port 3389 (RDP) by only allowing staff who use a VPN to be able to remotely access any systems, utilize multi-factor authentication for VPN access, ensure complete regular vulnerability scans and penetration tests across the network, activate multi-factor authentication for sensitive internal systems even for employees on the LAN or VPN and Create back-ups that are offline and offsite, and develop a disaster recovery plan that covers the restoration of data and whole systems.