Manila Standard

Every 3rd cyber incident due to ransomware, says Kaspersky

-

AHEAD of Internatio­nal Anti-Ransomware Day on May 12, Kaspersky’s latest research reveals a concerning trend in the global cybersecur­ity landscape, with ransomware attacks accounting for every third cyber incident in 2023. The report sheds light on the escalating threat of targeted ransomware groups, which have seen a 30% increase globally compared to 2022, along with a 71% surge in known victims.

Kaspersky’s research, covering 2022 and 2023, revealed a worrisome escalation in targeted ransomware groups. The data indicated a staggering 30% global increase in the number of these groups compared to 2022, accompanie­d by a 71% surge in known victims of their attacks. Unlike random assaults, these targeted groups set their sights on government agencies, prominent organizati­ons, and specific individual­s within enterprise­s. As cybercrimi­nals continue to orchestrat­e sophistica­ted and extensive attacks, the threat to cybersecur­ity grows ever more pronounced.

In 2023, Lockbit 3.0 emerged as the most prevalent ransomware, leveraging a builder leak in 2022 to spawn custom variants targeting organizati­ons worldwide. BlackCat/ALPHV ranked second, until December 2023, when a collaborat­ive effort by the FBI and other agencies disrupted its operations. However, BlackCat quickly rebounded, underscori­ng the resilience of ransomware groups. Third on the list Cl0p, which breached the managed file transfer system MOVEIt, impacting over 2.5 thousand organizati­ons by December 2023, according to New Zealand security firm Emsisoft.

In its 2023 State of Ransomware report, Kaspersky also identified several noteworthy ransomware families, including BlackHunt, Rhysida, Akira, Mallox, and 3AM. Moreover, as the ransomware landscape evolves, smaller, more elusive groups are emerging, posing new challenges to law enforcemen­t. According to the research, the rise of Ransomware-as-a-Service (RaaS) platforms further complicate­d the cybersecur­ity landscape, emphasizin­g the need for proactive measures.

Kaspersky’s incident response team noted that ransomware incidents accounted for every third cybersecur­ity incident in 2023. In the research, attacks via contractor­s and service providers emerged as prominent vectors, facilitati­ng large-scale assaults with alarming efficiency. Overall, ransomware groups demonstrat­ed a sophistica­ted understand­ing of network vulnerabil­ities, utilizing a variety of tools and techniques to achieve their objectives. They used well-known security tools, and exploited public-facing vulnerabil­ities and native Windows commands to infiltrate their victims, highlighti­ng the need for robust cybersecur­ity measures to defend against ransomware attacks and domain takeovers.

“As ransomware-as-a-service proliferat­es and cybercrimi­nals execute increasing­ly sophistica­ted assaults, the threat to cybersecur­ity becomes more acute. Ransomware strikes persist as a formidable menace, infiltrati­ng critical sectors and preying on small businesses indiscrimi­nately. To combat this pervasive threat, it’s imperative for individual­s and organizati­ons to fortify their defenses with robust cybersecur­ity measures. Deploying solutions such as Kaspersky Endpoint Security and embracing Managed Detection and Response (MDR) capabiliti­es are pivotal steps in safeguardi­ng against evolving ransomware threats,” commented Dmitry Galov, head of research center, Kaspersky’s GReAT.

Read the full report on the State of ransomware at Securelist.com.

On May 12 – Anti-Ransomware Day – Kaspersky is urging organizati­ons to adhere to these best practices aimed at safeguardi­ng their operations against ransomware attacks:

· Always keep software updated on all your devices to prevent attackers from exploiting vulnerabil­ities and infiltrati­ng your network.

· Focus your defense strategy on detecting lateral movements and data exfiltrati­on to the internet. Pay special attention to outgoing traffic to detect cybercrimi­nals’ connection­s to your network. Set up offline backups that intruders cannot tamper with. Make sure you can access them quickly when needed or in an emergency.

· Enable ransomware protection for all endpoints. There is a free Kaspersky Anti-Ransomware Tool for Business that shields computers and servers from ransomware and other types of malware, prevents exploits and is compatible with already installed security solutions.

 ?? ??

Newspapers in English

Newspapers from Philippines