Ransomware attackers increase use of remote encryption

404

A recent report published by Sophos, a renowned global provider of cybersecurity solutions and services, has revealed that several of the most active and notorious ransomware groups are now intentionally turning on remote encryption for their attacks.

These groups, including Akira, ALPHV/BlackCat, LockBit, Royal, and Black Basta, have been found to be using increasingly sophisticated techniques to encrypt their victims’ data remotely, thereby making it much harder for the victims to recover their files without paying the ransom demanded by the attackers.

In its report titled “CryptoGuard: An Asymmetric Approach to the Ransomware Battle,” Sophos noted that its unique anti-ransomware technology, CryptoGuard, detected a 62% year-over-year increase in intentional remote encryption attacks since 2022.

“Companies can have thousands of computers connected to their network, and with remote ransomware, all it takes is one under-protected device to compromise the entire network. Attackers know this, so they hunt for that one ‘weak spot” – and most companies have at least one. Remote encryption is going to stay a perennial problem for defenders, and based on the alerts we’ve seen, the attack method is steadily increasing,” said Mark Loman, vice president, threat research at Sophos and co-creator of CryptoGuard.

Sophos CryptoGuard is the anti-ransomware technology that Sophos acquired in 2015 and is included in all Sophos Endpoint licenses. CryptoGuard monitors the malicious encryption of files and provides immediate protection and rollback capabilities, including when the ransomware itself never appears on a protected host.

The unique anti-ransomware technology is a last line of defense in Sophos’ layered endpoint protection, only activating if an adversary triggers it later in the attack chain.

In remote encryption attacks, also known as remote ransomware, adversaries leverage a compromised and often under-protected endpoint to encrypt data on other devices connected to the same network.

Since this type of attack involves encrypting files remotely, traditional anti-ransomware protection methods deployed on remote devices don’t “see” the malicious files or their activity, failing to protect them from unauthorized encryption and potential data loss.

Sophos CryptoGuard technology, however, takes an innovative approach to stopping remote ransomware, as explained in the Sophos X-Ops article: analyzing the contents of files to see if any data became encrypted to detect ransomware activity on any device in a network, even if there is no malware on the device.

Also Read: NITDA warns against phishing attacks

In 2013, CryptoLocker was the first prolific ransomware to utilize remote encryption with asymmetric encryption, also known as public-key cryptography. Since then, adversaries have been able to escalate the use of ransomware, due to ubiquitous, ongoing security gaps at organizations worldwide and the advent of cryptocurrency.

“When we first noticed CryptoLocker taking advantage of remote encryption ten years ago, we foresaw that this tactic was going to become a challenge for defenders. Other solutions focus on detecting malicious binaries or execution. In the case of remote encryption, the malware and execution reside on a different computer (unprotected) than the one having the files encrypted. The only way to stop it is watching the files and protecting them. That’s why we innovated CryptoGuard,” Loman said .

He added that CryptoGuard targets files, not ransomware. It employs mathematical scrutiny to detect manipulation and encryption operating autonomously without relying on breach indicators; threat signatures, AI, cloud lookups, or prior knowledge for effectiveness.

“By focusing on the files, we can change the power balance between the attackers and the defenders. We’re increasing the cost and complexity for the attackers to successfully encrypt data, so that they will abandon their objectives. This is a part of our asymmetric defense approach strategy.” Loman said.

The Vice President stated that remote ransomware, notably from attackers like LockBit and Akira, persists due to its efficiency, noting that reading data over a network is slower than from a local disk, prompting strategic encryption of only a fraction of each file.

Loman said Sophos’ anti-ransomware technology targets both remote attacks and those encrypting just 3% of a file, offering comprehensive protection. The information aims to equip defenders against this persistent threat.

Comments are closed.