{"id":1457,"date":"2016-06-14T12:34:18","date_gmt":"2016-06-14T16:34:18","guid":{"rendered":"http:\/\/eitnetworks.net\/?p=1457"},"modified":"2016-06-14T12:34:18","modified_gmt":"2016-06-14T16:34:18","slug":"ransomware-adopting-self-replication","status":"publish","type":"post","link":"https:\/\/eitnetworks.net\/index.php\/2016\/06\/14\/ransomware-adopting-self-replication\/","title":{"rendered":"Ransomware Adopting Self-Replication"},"content":{"rendered":"<h3>Although some may have hoped that the threat of ransomware was on the decline, the reality is that it\u2019s quite the opposite. Until now, attacks seemed to be targeted directly at its victims, but Microsoft warns that may no longer be true. With their discovery of self-propagating ransomware it\u2019s vital to fully understand the possible risk of infection.<\/h3>\n<p>&nbsp;<\/p>\n<p>Ransomware, the malware that locks up infected systems and demands payment to return access to users, has been steadily increasing its infection rate over the course of this year. Enigma Software reported that, \u201cAfter staying steady for the last six months of 2015, ransomware detection has begun to climb; February saw a 19 percent increase over January, while March had almost a 10 percent increase over February. Then, in April, infections more than doubled.\u201d<\/p>\n<p>&nbsp;<\/p>\n<p>And as if that wasn\u2019t frightening enough, Microsoft announced last week that a recently detected ransomware software was found copying itself onto USB and network drives. The ransomware, titled ZCryptor, disguises itself as either an Adobe Flash installer or a Microsoft Office file to trick users into opening it.<\/p>\n<p>&nbsp;<\/p>\n<p>Once opened, it displays a prompt that says \u201cThere is no disk in the drive. Please insert a disk into drive D:\u201d. If you see this after opening a suspicious file, it is most likely ZCryptor trying to distract you while it works in the background to add a registry key that buries itself deep in your system and begins to encrypt your files.<\/p>\n<p>&nbsp;<\/p>\n<p>Although previous ransomware iterations like Alpha Ransomware had the ability to find and encrypt files on shared network drives, security experts believe this is the first time a ransomware variant has included self-replication via removable drives into its framework.<\/p>\n<p>&nbsp;<\/p>\n<p>When it was first detected in May, Microsoft found ZCryptor singling out 88 different file types for encryption. However, later on a security expert analyzed the ransomware and found 121 targeted file types \u2014 inferring that creators of the malware were continuing to develop its source code.<\/p>\n<p>&nbsp;<\/p>\n<p>It\u2019s commonplace for ransomware to demand payment to be made in Bitcoins as they\u2019re an almost totally untraceable online currency. ZCryptor is no different, demanding 1.2 Bitcoins (500 USD) unless payment is more than four days after infection \u2014 then it increases to five Bitcoins (2,700 USD).<\/p>\n<p>&nbsp;<\/p>\n<p>Compared to other more complex security threats, ransomware is still relatively easy to avoid. Always verify the source of email attachments and website downloads before opening files, disable macros in Microsoft Office programs, maintain regular backups and update your security software.<\/p>\n<p>&nbsp;<\/p>\n<h3>Still concerned about security at your SMB? It doesn\u2019t have to be as difficult and draining as you may think. Contact us today for advice on keeping your network protected around the clock. Reach us at 1-866-BIT-WISE or sales@eitnetworks.net<\/h3>\n","protected":false},"excerpt":{"rendered":"<p>Although some may have hoped that the threat of ransomware was on the decline, the reality is that it\u2019s quite the opposite. Until now, attacks seemed to be targeted directly at its victims, but Microsoft warns that may no longer be true. With their discovery of self-propagating ransomware it\u2019s vital to fully understand the possible [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1459,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[37,39,23],"tags":[98,99],"class_list":["post-1457","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-antivirus","category-malware","category-security","tag-ransomware","tag-zcryptor"],"jetpack_featured_media_url":"https:\/\/eitnetworks.net\/wp-content\/uploads\/2016\/06\/ransomware-kav.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/eitnetworks.net\/index.php\/wp-json\/wp\/v2\/posts\/1457","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/eitnetworks.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/eitnetworks.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/eitnetworks.net\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/eitnetworks.net\/index.php\/wp-json\/wp\/v2\/comments?post=1457"}],"version-history":[{"count":0,"href":"https:\/\/eitnetworks.net\/index.php\/wp-json\/wp\/v2\/posts\/1457\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/eitnetworks.net\/index.php\/wp-json\/wp\/v2\/media\/1459"}],"wp:attachment":[{"href":"https:\/\/eitnetworks.net\/index.php\/wp-json\/wp\/v2\/media?parent=1457"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/eitnetworks.net\/index.php\/wp-json\/wp\/v2\/categories?post=1457"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/eitnetworks.net\/index.php\/wp-json\/wp\/v2\/tags?post=1457"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}