Ever thought about what all the ransomware complain is about? You’ve found out about it at the workplace or read about it in the news. Perhaps you have a spring up on your PC screen right currently cautioning of a ransomware contamination. All things considered, in case you’re interested to get familiar with everything to think about ransomware, you’ve gone to the opportune spot. We’ll inform you regarding ransomware’s various structures, how you get it, where it originated from, who it targets, and what to do to secure against it.
WHAT IS RANSOMWARE???
As the name suggests, ransomware is a sort of malware that requests some type of installment from the unfortunate casualty so as to recuperate control of their PC and additionally information. Inside that expansive definition, there are a couple of exciting bends in the road that are significant.
To start with, there are variations as to precisely what the injured individual is being held to emancipate for. Regularly, the assailant scrambles documents on the unfortunate casualty’s PC so that they can’t be opened except if the injured individual has a decoding key. Access to the decoding key is the thing that the assailant
RANSOMWARE EXAMPLES:
WannaCry
WannaCry is ransomware attack that spread across 150 countries in 2017.
Designed to exploit a vulnerability in Windows, it was allegedly created by the United States National Security Agency and leaked by the Shadow Brokers group. WannaCry affected 230,000 computers globally.
Bad Rabbit
Bad Rabbit is a 2017 ransomware attack that spread using a method called a ‘drive-by’ attack, where insecure websites are targeted and used to carry out an attack.
Drive-by attacks often require no action from the victim, beyond browsing to the compromised page. However, in this case, they are infected when they click to install something that is actually malware in disguise. This element is known as a malware dropper.
Ryuk
Ryuk ransomware, which spread in August 2018, disabled the Windows System Restore option, making it impossible to restore encrypted files without a backup.
Ryuk also encrypted network drives.
CryptoLocker
CryptoLocker is ransomware that was first seen in 2007 and spread through infected email attachments. Once on your computer, it searched for valuable files to encrypt and hold to ransom.
This allowed them to control part of the criminal network and grab the data as it was being sent, without the criminals knowing. This action later led to the development of an online portal where victims could get a key to unlock and release their data for free without paying the criminals.
GandCrab
GandCrab is a rather unsavory ransomware attack that threatened to reveal victim’s porn watching habits.
Claiming to have highjacked users webcam, GandCrab cybercriminals demanded a ransom or otherwise they would make the embarrassing footage public.
HOW DO RANSOMWARE REALLY WORKS?
The good news is that ransomware does not usually appear on its own. It must be activated in order to deliver its payload, usually through a malicious link or attachment in an email.
There are generally five steps required for ransomware to achieve its objective:
The Victim Is Notified
For the ransom to be paid, the user must be aware of the demands of the criminals. At this point, they will usually receive notification on the screen explaining the demands and how they can regain access.
The Malware Takes Control
Once the malware has taken control of the system, certain file types will be encrypted and access will be denied to users.
The Ransom Is Paid
Once they have system access, attackers will either identify and encrypt certain file types or deny access to the entire system.
Full Access Is Returned
In the majority of cases, attackers return full control to the victim. It is in their interest to do this; failure to do so would mean few organizations would be willing to pay if they didn’t believe their data would be restored.
The System Is Compromised
The majority of ransomware attacks start life as a social engineering exercise, usually in the form of an attachment or malicious link. The aim is to entice the user to click on these objects in order to activate the malware.
Some tips on how to MINIMIZE or PREVENT this RISK of ATTACK:
Use multi-factor authentication (MFA)
Use complex passwords, managed through a password manager
Limit access rights; give user accounts and administrators only the access rights they need and nothing more
Make regular backups, and keep them offsite and offline where attackers can’t find
Patch early and patch often. Ransomware like WannaCry and NotPetya relied on unpatched vulnerabilities to spread around the globe
Lock down your RDP. Turn off RDP if you don’t need it, and use rate limiting, 2FA, or a VPN if you do
Ensure tamper protection is enabled – Ryuk and other ransomware strains attempt to disable your endpoint protection
Hacking is an attempt to exploit a computer system or a private network inside a computer. Simply put, it is the unauthorised access to or control over computer network security systems for some illicit purposes. This type of cyber attack is common among social media accounts and platforms requiring personal accounts over networks.
Ethical Hacking – Hacker Types
White Hat Hackers – White Hat hackers are also known as Ethical Hackers. They never intent to harm a system, rather they try to find out weaknesses in a computer or a network system as a part of penetration testing and vulnerability assessments.
Black Hat Hackers – Black Hat hackers, also known as crackers, are those who hack in order to gain unauthorized access to a system and harm its operations or steal sensitive information.
Grey Hat Hackers – Grey hat hackers are a blend of both black hat and white hat hackers. They act without malicious intent but for their fun, they exploit a security weakness in a computer system or network without the owner’s permission or knowledge.
5 easy ways to avoid being hacked online
By Donna Freydkin
Keep changing your password and updating your accounts.
You can check to see if you’ve been part of a data breach by using a site like this one.
Don’t use the same email address that you use for watching movies as you do for your investments or your banking activities. Keep them very separate to create silos that can help protect personal data.
Be leery of those personality tests you see online because they can ask too much personal information that can be used against you.
When creating your online profile, don’t reveal the real street you grew up on, or your mother’s maiden name. Use the information of a person you know, or make up the answer with a response you will remember.
Things to Do Right Now if You’ve Been Hacked
Change Your Passcode
Use a Passcode Manager
Turn on Two-factor Authentication
Tell your Friends
Delete Any Sensitive Data from The Hacked Account
De-Authorize Apps on Facebook, Twitter, Google, etc
Phishing is a type of social engineering attack often used to steal user data, including login crzedentials and credit card numbers and also involves attempts by Internet fraudsters to access and obtain personal and sensitive information, such as usernames, passwords.It occurs when an attacker, masquerading as a trusted entity, dupes a victim into opening an email, instant message, or text message. The recipient is then tricked into clicking a malicious link, which can lead to the installation of malware, the freezing of the system as part of a ransomware attack or the revealing of sensitive information. For years, it continues to affect many users who still fall prey to tactics used to bait victims into disclosing personal identities and login credentials.here are several reasons why this type of threat is so dangerous. First of all, it is fairly inexpensive and easy to carry out. Phishing is a means of tricking e-mail recipients into opening an attachment that masquerades as being legitimate and urgent or into clicking on a malicious link that opens a website that is actually infected with malware.
Through this crime many people are affected and many business are on danger,but mostly of them are people that is part of a company that have big names or rank in their company. But we must be aware that phishers can target anyone to gain knowledge or personal information that can be used as a bait to you. Phishers target those people that have high profit in their companies or have high salary to their jobs. And the fact that most of the cyber crimes like this have the purpose to hacked and steal lots of money from people that is clueless of what they are doing or what they are clicking without even knowing or having the knowledge about phishing.
There are many ways in preventing or protecting yourself to phishing attacks:
1. Investigate every link’s final destination
We’re all email marketers here. Links, UTMs and redirects are sprinkled throughout every email we send. Same with emails that we receive. Just because a link is typed out and looks like a normal hyperlink doesn’t mean the destination is authentic.
To find out if a link is real, hover over it with your mouse and look at the link’s destination in the lower left corner of your browser. This is the real destination, regardless of what the text says.
2. Be cautious with shortened links
Scammers are like chameleons. They know how to mask their tactics by resembling actions that consumers are already familiar with… like shortening links.
Everyone’s clicked on a Bitly or Linktree link at some point—most likely on social media. Link shortening tools are popular for brands and users since they save character count and look cleaner than a long, messy slug.
Phishers are hip to this trend and employ it themselves. Watch out for shortened links anytime you’re tempted to click, as they might lead to a fake landing page.
3. Take “urgent” deadlines with a grain of salt
No legitimate company will ever ask for your personal data via email. If you see a message that’s trying to get you to take “urgent” action (aka, sending your personal info), call the company directly and ask. When it comes to your data, you’d rather be safe than sorry.
Always make account updates yourself or call the company using the number you find on their website (not the number the email provides—that could be fake too).When you know it’s a phisher, mark that b.s. as spam and send it to the trash where it belongs.
4. Look for the “s” in (https://)
Some websites start with http://and others with https://. The “s” in the latter stands for secure and will show a little lock icon next to it. Those websites are safest for browsing and purchasing. Stick to secure websites whenever possible.
5. Change your passwords frequently
We know, we know. This can be a pain in the butt. “Don’t use the same password more than once,” they say. “Change them often,” they harp. Unless you work in IT or Security, you most likely use the same password, like your street name and kid’s birthday. The truth is, having a unique password for each account has never been easier.
There are reputable platforms available you can use to create strong passwords and store them for safekeeping, such as LastPass. Platforms like this one are seamless and reliable for keeping data secure.
6. Don’t allow remote access to your computer
Yep, it happens. Someone reaches out pretending to be from a well-known security firm and wants to help you install software protection on your computer.
1. Don’t install anything from an unverified source.
2. Especially don’t give that unverified source direct access to your computer. That’s a hard no-no.
7. Set up two-factor authentication
Many organizations offer two-factor authentication for an extra layer of security. Take advantage of this whenever possible so no one else can log in without needing your device.
8. Trust your gut instincts
If an email looks or feels off to you (even if you have very little reason to think so), trust your instincts. You’ve likely seen a garbage phishing email at some point, littered with typos and grammatical errors, unprofessional imagery, and just not a clean, crisp experience like you’d normally expect.
When an email or other interaction feels off to you, save yourself a potential headache and trust your gut.
9. Finally, use good judgement
This goes without saying, but it’s perfectly true. The best thing you can do to protect yourself against phishing attacks is plain and simple common sense.
Avoid the unknown. Don’t:
Click unknown links
Download unknown files or files from unknown sources
Open attachments (even on social media) from untrusted sources
10. Report phishing attempts
In email, this is as easy as forwarding the poorly executed attempt to get your personal information to the proper authorities.
If You Think You’ve Been Scammed
Change your passwords immediately—email accounts, financial institutions, your computer login, Facebook, everything. The sooner you can lock them out and slow their progress, the better.
If you think your banking information is at stake, call your bank and let them know asap. They’ll be on high alert for odd account activity.
Use a trusted security software to scan and scrub malware from your computer.
According to Besley (2004), cyber bullying involves the use of information and communication technologies to support, deliberate, repeated, and hostile behavior by an individual or group that is intended to harm others.
As of today, almost all of the people are just a keyboard a way to post what they think and feel about certain subjects. It is indeed scary to think that we are not that secured anymore about our personal lives especially if someone holds a grudge about you. We are living in an era wherein we are being monitored by almost everyone and being judged by almost all of them. Ans what’s worse is that, they are using the online environment to fire bullets on you. The social media is an example of that deadly weapon they are using as of now to bully and degrade you.
What are the reasons of a cyber bully to do such act?
1. Cyberbullies Are Motivated by Revenge
When kids have been bullied, they often seek revenge instead of coping with the situation in healthier ways. The motivation for these victims of bullying is to retaliate for the pain they have experienced. When this happens, these kids are often referred to as bully-victims.
Bully-victims feel justified in their actions because they, too, have been harassed and tormented.
They want others to feel what they have felt and feel justified in doing so. By cyber bullying others, they also may feel a sense of relief and vindication for what they experienced. These kids will sometimes even go after the bully directly. Other times, they will target someone whom they perceive to be weaker or more vulnerable than them.
2. Cyberbullies Believe the Victim Deserves It
Bullying often revolves around a person’s social status at school. And some kids will cyberbully others based on the school’s perceived social ladder. For instance, a mean girl might get cyber bullied by an anonymous group of girls who are hoping to bring her down a notch or two.
Or, by contrast, a mean girl might cyberbully a girl who excels academically because she is jealous of her success. Other times, one girl might cyberbully another girl because she believes she stole her boyfriend. Whatever the reason, kids sometimes feel their cyber bullying behaviors are warranted and deserved. Consequently, they usually do not feel remorse or guilt for cyber bullying.
3. Cyberbullies Are Power Hungry
Cyber bullying can be a manifestation of social status. Kids who are popular often make fun of kids who are less popular. Likewise, kids who are attractive might single out others they feel are unattractive. They use the Internet to perpetuate relational aggression and mean girl behavior. They also will spread rumors and gossip and may even ostracize others through cyber bullying. Meanwhile, kids who are trying to climb the social ladder at school or gain some social power will resort to cyber bullying to get attention. They also might cyberbully to diminish the social status of another person.
Cyberbullies have a range of different motivations, but the general goal is to increase their own power by reducing the power of someone else.
4.Cyberbullies Cave Under Peer Pressure
Sometimes kids will cyberbully to fit in with a group of friends or a clique. As a result, these kids succumb to peer pressure in order to be accepted at school, even if it means going against their better judgment. They are more concerned with fitting in than they are worried about the consequences of cyber bullying. Other times, groups of friends will cyberbully because there is a false sense of security in numbers.
5. Cyberbullies Lack Empathy
Most kids who cyberbully believe it isn’t a big deal. Because they do not see the pain that they cause, they feel little to no remorse for their actions. In fact, several studies have found that a large number of students who engaged in online bullying reported not feeling anything for the victims after bullying online. Instead, many kids reported that online bullying made them feel funny, popular, and powerful.
EFFECTS OF CYBER BULLYING TO THE VICTIMS
There is a massive effect on the victim’s life once he/she is a victim of cyber bullying and some of those effects are the following:
Low self-esteem
Withdrawal from family and spending a lot of time alone
Reluctance to let parents or other family members anywhere near their mobiles, laptops etc
Finding excuses to stay away from school or work including school refusal
Friends disappearing or being excluded from social events
Losing weight or changing appearance to try and fit in
Fresh marks on the skin that could indicate self-harm and dressing differently such as wearing long sleeved clothes in the summer to hide any marks
A change in personality i.e. anger, depression, crying, withdrawn
WAYS ON HOW TO PREVENT CYBER BULLYING
There are numerous ways on how to prevent cyber bullying or how to prevent yourself becoming a victim of such hideous crime. These are the following:
Don’t reply to any form of cyber bullying. Bullies are often craving attention and can back down if ignored.
Talk to an adult you trust like your parents, your school principal or guidance counselor, or another grown-up. The best defense against the demand for secrecy is sharing the secret with someone who has more power than the bully.
Keep an offline diary. Print emails, take screenshots of text or social media messages, and take notes about the days, times, and people involved in the bullying incidents. If you don’t know their real name, note the fake names they use.
Block or mute cyberbullies. Most social platforms, online forums, and mobile devices have methods for blocking unwanted messages. Blocking is the best option but if you’re afraid of retaliation, muting can be a good strategy. Muting protects you from seeing their messages but, unlike blocking, a muted person usually doesn’t know they’ve been muted. If you don’t know how to block and mute, ask an adult.
Put down your devices. Spending less time on the internet gives you more time to make friends and have fun away from people who are hurtful.
“PULLING SOMEONE DOWN WON’T HELP YOU REACH THE TOP” so please stop cyber bullying.
From infiltrations on infrastructure, data breaching, to contagious malwares and firewall infringement. Online attacks are prevailing, typical on modern times and never discriminate on choosing a target nor have the ability to be restricted and contained.
You’ve likely heard of stories and news on cyber attacks and issues on media. But what are exactly cyber threats? Is it a matter of security? What are the different types of cyber issues and attacks? Can someone prevent a cyber attack? What are the best practices to prevent a cyber attack? To truly understand this concept, let’s dig deep into the background of cyber security.
“It takes 20 years to build a reputation and minutes of cyber-incident to ruin it. ” D.Yuson
Cyber attack criminal spy concept. Cartoon illustration of cyber attack criminal spy vector concept for web
Table of Contents
Definition of cyber attack and issue
Types of cybersecurity threats
Best practices for cyber defense and protection
What is a Cyber attack?
As mass users of today’s information and communication technology, we are presented with a magnitude and multitude of innovated media and technology. These are well presented such as laptops, mobile gadgets and phones, digital library, tablets, and desktop computers which gives us the power to gain and have access in the world wide web and the internet. Making mundane and tedious archaic works on gaining information and access of a person in just a click. However as digital access is evolving, threats and attacks are coming as a consequences to these technological advancements.
Cyber attack and cyber issue are the two common notion often used in digital territory to inhabit and determine threats such as scam, phishing, DDoS attacks in various and diverse situations. Using accurate and precise definition, according to the dictionary, cyber attack is an attack in computers and computer networks in any attempt to expose, alter, disable, destroy, steal or gain unauthorized access to or make unauthorized used of an asset. On the other hand, cyber issue is defined on the cyberspace world as, a classification of cyber attack, one of which is harmful on the recipient’s experience by stealing or attacking a person’s digital representation. It may be on the form of theft identity, website hacking, credit card scams, phishing and such. These variables are the main working principle of cyber space in the modern times as modern times greatly depend and highly influence on the use of technology itself.
Invented in 1989, the world wide web is home to around 2 billion websites today. This unthinkable expansion of the digital has brought thousand and thousands of world geographical scale to be shrunk into bits and bits of smaller global village. Able to connect, transfer and communicate with the use and utilization of internet. As the world shifts from a physical into a digital landscape, security threats have also changed from physical to cyber.
Cyber crimes, attacks and issues are accounted for trillion and billions of dollars in losses. In a recent Juniper research the amount of loss in 2019 only rose up into $2 trillion. With such vulnerabilities, particularly on online scams it is estimated that by 2027, global spending on cyber security on some company will reach $10 billion. Statistics show that, half of all cyber attacks are targeted on small businesses. As small business owners do not pay attention to cyber security. This is an important concept to be understood. As cyber attacks mainly performs its attack on small – scale population may it be an organization, a group of people or a single person. As it successfully performed its attack, it replicates its actions, evolving, making the attack more oblique and harder to identify as well as prevented on competent authorities. This makes cyber threats and attacks a harder and difficult anomaly to be combat at due to its evolving nuances and practices. As per Forbes, an estimated amount of $6 trillion damages will be cost on cyber attacks only making much more damage than all of the natural disasters in a year.
Types of cyber security threats
There are several and different types of cyber attacks and threats varying from simple scam to website hacking to identify theft. Here are the common, cyber security threats on going in the digital world.
I. Denial-of-service (Dos) and distributed denial-of-service (DDoS) attack
A denial-of-service attack hijacks a system’s resources and network in order for the network of online machines and systems to be immobilize so that the network can no longer respond to any service requests. This type of attack is common among, websites, student and university portals, online platforms and online banking. The attack is launched from a large scale numerous machines that are infected by malware (malicious software) controlled by the attacker.
II. Man-in-the-middle (MitM) attack
A MitM attack only occurs when a hacker inserts itself between the communication of a client and a server. This type of attack seizes the communication and negotiation going through the server and the client. This type of attack is highly dangerous as the client never had the idea or isn’t aware of the “man in the middle” intercepting the server and the client. This attack is common among BPO industries, online banking, online marketing and workplaces and systems that require customer services.
III. Phishing and spear phishing attack
Phising attack is a type of attack that sends email to a recipient which the email appears to be from trusted sources with the goal of gaining personal information or influencing users to do something. This type of attack is the most common and dominant in fields as users today are mainly connected through the use of instant messaging apps, electronic mails (e-mails) and online social media accounts. The email sent by the attack to the receiver involves an attachment of a malware that directly loads on to your computer or gadget you’re using, a link to a illegitimate website that automatically downloads malware or handling personal information such as credit card and banking information, personal identity and such.
IV. Drive-by attack
Drive by attack is a type of attack that are common among websites which are of low to medium security in an attempt to spread malware. Hackers (persons who launch these attacks) look for an insecure area of a website and plant a malicious script on to the directory of the websites. Websites are mainly compromised of computer languages such as HTML, Java and etc. into the HTTP or PHP code of one of the pages. The inserted script (identified as a malware) may download a malicious file on the gadget you are using, re-direct a victim on to a site controlled by hackers or steal personal information. This type of attack is common among, advertisements on websites, marketing websites, digital libraries, and accounting and market generating-profit websites.
V. Password attack
Password attack is a type of attack that uses network (internet take in for example) to infiltrate a person’s account. As password are the common mechanism to authenticate an information system, hackers deliberately “sniff” the connection of a user to a server using a network to acquire unencrypted passwords, credit card information and banking information with the use of social engineering and/or outright guessing. This type of attack is common on i connected networks such as low-quality vpns, banking and marketing websites and online social media platforms.
Best practices for cyber defense and protection
We now have learned the definition of cyber attack and issue and its effect to the digital landscape of the world. As threats are getting far more serious, dangerous, cyber security should be our topmost priority when dealing in the cyberspace being a netizen of that imaginary landscape. In a recent statistical analysis of business world, the Philippines moved up to fifth place from ninth year earlier in Kaspersky Lab’s global list of countries with most online threats detected in the second quarter of 2019 only. It is then essential for us especially Filipinos and with utmost significance and importance to protect ourselves from these cyber threats.
It can be scary for business owners ranging from micro-small and medium enterprises to huge industrial business owners who are susceptible about cyber threats, attacks and issues. Without proper manifestation of maintaining quality controlled security system, threats on these fields are increasingly potent and frequent. As a business owner or an aspiring business owner, enterprises or businesses best practice for defense for cyber threats include basic but extremely countermeasures like patching system, systems security officer, and or a competent information and communication technology individual. Worry not as a host of new technologies and services are coming onto the market that make it easier to mount a robust defense against these cyber threats. These include: outsourced security services, collaborative systems between security team members, continual attack simulation tools and point solutions for anti-phishing and secure browsing. Maintaining these principles and quickly identifying these attacks could greatly improve a business security over to these threats.
On the other hand, individuals with the capability to access digital cyberspace in any means should also have cyber defense countermeasures. These preventive measures include and not limit to, password hygiene, this include routinely changing of password of one’s personal account to avoid direct phishing and “sniffing” of an attacker, downloading an anti- virus software, to keep your system up-to-date with automated and scheduled scans for imminent and potential danger of attacks and, lastly, caution against phishing attacks. Phishing attacks are attacks that are most prominent and common among individuals as these attacks send attachments from individuals with monetary gain, lottery win and travel with an all out expense while bringing the name of a legitimate organization while the attacker operates illegally.
As a reader, you now have identified, visualized this threat as well as ideas to countermeasure it. It would be an honorary tribute to yourself to expand and share your knowledge about this topic to your friends, families and neighbors verbally or digitally. Remember that it takes years to build a reputation and minutes of cyber incident to ruin it. Share and subscribe, productive, informative, proficient!