Daily Bulletin

Business Mentor

.

  • Written by Kaspersky

Kaspersky expert shares how enterprises and public entities can keep targeted ransomware gangs at bay

14 December 2020. Global cybersecurity company Kaspersky recently revealed in a virtual conference that 2020’s cybersecurity “disease” is targeted ransomware. Also dubbed as “Ransomware 2.0”, this type of attack goes beyond kidnapping a company’s or an organisation’s data. These groups are now utilising the increasingly valued digital reputation to force their preys to pay hefty ransom.

Vitaly Kamluk, Director of Global Research and Analysis Team (GReAT) for APAC at Kaspersky, revealed that at least 61 entities from the region were breached by a targeted ransomware group in 2020. Australia and India logged the highest number of incidents across APAC.

In terms of industries, Kaspersky’s data shows that the following segments were compromised:

  • * Light Industry - includes the manufacturing of clothes, shoes, furniture, consumer electronics and home appliances

  • * Public service

  • * Media and Technology

  • * Heavy Industry – includes oil, mining, shipbuilding, steel, chemicals, machinery manufacturing

  • * Consulting

  • * Finance

  • * Logistics

Targeted ransomware has been a problem for many Asian enterprises. Over 61 companies were breached this way in Asia alone. In some cases, Maze ransomware gang claimed responsibility and published stolen data from the compromised companies,” said Kamluk.

Maze group stands out as the most active and the most damaging of all. Formed in summer 2019, it took them about half a year to prepare and launch full scale campaign against many businesses. The first victims appeared in November 2019, when they leaked 700MB of victim’s internal data online.

Many other cases followed and within a year Maze breached at least 334 companies and organisations. This is one of the first groups which started the use of “pressure tactic”. This refers to cybercriminals threatening victims that they will publicly leak most sensitive data stolen from their compromised systems via the group’s own website.

Pressure tactic is a serious threat to public and private organisations. This attack plays on companies’ digital reputation as it threatens to divulge data of a breached entity, compromising its security and its name at the same time,” he added.

Kamluk noted that digitalisation has birthed different pressure points for a company. Before, enterprises’ main concerns only included business continuity and, depending on the industry, government regulation. Now, surviving in the era of digital reputation economy means that they should also be aware of business trust – with their partners and customers – as well as public opinion.

A recent survey conducted by Kaspersky proved Vitaly’s points. Results showed that 51% of users in APAC agree that a company’s online reputation is essential. Almost half (48%) also admitted that they avoid companies who were involved in a scandal or had received negative news coverage online.

Maze group just announced that they are closing down, but this gang just triggered the beginning of this trend. A successful targeted ransomware attack is a PR crisis which can damage an organisation’s reputation, online and offline. Financial toll aside, fixing one’s name is quite a harder task to take which is why we urge public and private entities to take their security seriously,” adds Kamluk.

To remain protected against these threats, Kamluk suggests enterprises and organisations to:

  • * Stay ahead of your enemy: make backups, simulate attacks, prepare action plan for disaster recovery.

  • * Deploy sensors everywhere: monitor software activity on endpoints, record traffic, check hardware integrity.

  • * Never follow demands of the criminals. Do not fight alone - contact Law Enforcement, CERT, security vendors like Kaspersky.

  • * Train your staff while they work remotely: digital forensics, basic malware analysis, PR crisis management.

  • * Follow the latest trends via premium threat intelligence subscriptions, like Kaspersky APT Intelligence Service.

  • * Know your enemy: identify new undetected malware on premises with Kaspersky Threat Attribution Engine.

About Kaspersky

Kaspersky is a global cybersecurity company founded in 1997. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative security solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection and a number of specialised security solutions and services to fight sophisticated and evolving digital threats. Over 400 million users are protected by Kaspersky technologies and we help 250,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com.au.

How to Get the Best Value When Buying Cardboard Boxes

Cardboard boxes have become an indispensable part of daily life, whether for moving houses, shipping products or simply for storage purposes. The key to making the most out of these versatile contai...

Daily Bulletin - avatar Daily Bulletin

BYD Expands in Australia: Introducing Chinese Dealerships and Pioneering Innovative Operations

Recently, BYD has been generating significant buzz with the launch of its two new stores in Melbourne and Sydney, revealing some exciting developments. Notably, BYD’s Chairman, Wang Chuanfu, graced ...

Daily Bulletin - avatar Daily Bulletin

Deciphering the Intricacies of Scrap Copper Prices in Melbourne: A Comprehensive Analysis

Introduction In the bustling metropolis of Melbourne, where innovation meets industry, the scrap copper market forms an integral part of the city's economic landscape. From the scrapyards scattered...

Daily Bulletin - avatar Daily Bulletin

Empowering Your Brand: The Integral Role of User-Generated Content in Social Media Marketing

In the ever-evolving landscape of digital marketing, brands constantly seek innovative strategies to connect authentically with their audience. Among these strategies, User-Generated Content (UGC) h...

Daily Bulletin - avatar Daily Bulletin

DIY Panel Beating Tips for Car Enthusiasts: A Beginner’s Guide

Welcome to the world of car maintenance and repair, where enthusiasts and DIYers converge to breathe new life into their beloved vehicles. Today, we’re diving into an essential skill for anyone look...

Daily Bulletin - avatar Daily Bulletin

The Perfect Extension: A 7 Point Checklist for Your Domain Name

The perfect domain name is imperative to your online success. It may not seem like much, but your extension is the first impression customers experience when they come across your brand. And in th...

Daily Bulletin - avatar Daily Bulletin

Tomorrow Business Growth