RANSOMWARE IN ANZ Noushin Shabab Senior Security Researcher at - - PowerPoint PPT Presentation

ransomware in anz
SMART_READER_LITE
LIVE PREVIEW

RANSOMWARE IN ANZ Noushin Shabab Senior Security Researcher at - - PowerPoint PPT Presentation

RANSOMWARE IN ANZ Noushin Shabab Senior Security Researcher at Global Research and Analysis Team ANZ 1 We believe that everyone from home computer users through to large corporations and governments should be able to protect what


slide-1
SLIDE 1

1

RANSOMWARE IN ANZ

Noushin Shabab

Senior Security Researcher at Global Research and Analysis Team ANZ

slide-2
SLIDE 2

2

We believe that everyone – from home computer users through to large corporations and governments – should be able to protect what matters to them most. Whether it’s privacy, family, finances, customers, business success or critical infrastructure, we’ve made it our mission to secure it all.

Eugene Kaspersky, chairman and CEO, Kaspersky Lab

slide-3
SLIDE 3

3

EXPERTISE

Our Global Research and Analysis Team of security experts constantly explore and fight the most advanced cyberthreats.

1/3

  • f our employees

are R&D specialists

325,000

new malicious files detected by Kaspersky Lab every day

40

world-leading security experts –

  • ur elite group
slide-4
SLIDE 4

4

We participate in joint operations and cyberthreat investigations with the Global IT security community, international organisations such as INTERPOL and Europol, law enforcement agencies and CERTs worldwide

We hold regular training courses for INTERPOL and Europol officers and the police forces of many countries, e.g. City of London Police We provide expert speakers at conferences around the globe, e.g. World Economic Forum in Davos We host the annual Kaspersky Lab Security Analyst Summit which brings together the world’s best IT security experts

OUR ROLE IN THE GLOBAL IT SECURITY COMMUNITY

Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

slide-5
SLIDE 5

5

AGENDA

  • What is ransomware?
  • History
  • Classifications of ransomware
  • Propagation and Acceleration
  • Ransomware in ANZ
  • How to prevent ransomware?
  • No more ransom!
slide-6
SLIDE 6

6

WHAT IS RANSOMWARE?

slide-7
SLIDE 7

7

Ransomware is a type of malware that attempts to extort money from a user by infecting and taking control of the victim's machine or the files or documents stored on it. Typically, ransomware will either lock the computer to prevent normal usage or encrypt the documents and files on it to prevent access to saved data

WHAT IS RANSOMWARE?

slide-8
SLIDE 8

8

HISTORY OF RANSOMWARE.

slide-9
SLIDE 9

9

FIRST RANSOMWARE

slide-10
SLIDE 10

10

AIDS Trojan (also known as "PC Cyborg")

Academic paper: “Cryptovirology: Extortion-based Security Threats and Countermeasures”

Gpcode Ransomware imitating Windows Product Activation Start spreading via Exploit Kit A MacOS X-specific Ransomware 1989 1996 2006 2011 2013 2013 NOW Multiple variants on multiple platforms causing major damage

slide-11
SLIDE 11

11

  • Encryption Ransomware
  • Mobile device

Ransomware(Android)

  • Ransomware

encrypting web servers

  • Screen Locker

TYPES OF RANSOMWARE

slide-12
SLIDE 12

12

PROPERGATION AND ACCELERATION

slide-13
SLIDE 13

13

  • Infected websites
  • Malvertising
  • Emails
  • Instant Message
  • Social Networks

PROPERGATION METHODS

slide-14
SLIDE 14

14

EMAIL WITH MS OFFICE DOCUMENT ATTACHMENT

slide-15
SLIDE 15

15

TRICKS TO MAKE USERS ENABLE DOCUMENT MACROS

slide-16
SLIDE 16

16

EMAIL WITH ARCHIVED EXECUTABLE

slide-17
SLIDE 17

17

EXAMPLES IN AUSTRALIA AND NEW ZEALAND

slide-18
SLIDE 18

18

SCAM EMAIL HEADLINES IN AUSTRALIA

slide-19
SLIDE 19

19

SCAM EMAILS ON THE FEDERAL COURT

slide-20
SLIDE 20

20

SCAM EMAILS ON THE ANZ POST

slide-21
SLIDE 21

21

Links Malicious Resources Injected into website

Compromised websites

Malicious Files

Attackers websites Scam emails

INFECTION VECTOR

slide-22
SLIDE 22

22

STATISTICS ON RANSOMWARE

slide-23
SLIDE 23

23

  • The overall number of cryptor modifications in our malware collection to-date is

at least 26,000. 21 new cryptor families and 32.091 new modifications were detected in Q3 2016.

  • In Q3 2016, 821,865 unique users were attacked by cryptors – 2.6 times more

than in the previous quarter.

Number of new cryptor samples in our collection Number of users attacked by ransomware

RANSOMWARE IN Q3

slide-24
SLIDE 24

24

TOP 10 CRYPTORS Q3

slide-25
SLIDE 25

25

MAP OF AUSTRALIA AND NEW ZEALAND

slide-26
SLIDE 26

26

HOW TO PREVENT RANSOMWARE?

  • Always Make Backups
  • Keep all software updated
  • Improve User Awareness
  • Use Reliable Antivirus solution
  • DON’T PAY THE RANSOM!
slide-27
SLIDE 27

27

NO MORE RANSOM

slide-28
SLIDE 28

28

NO MORE RANSOM

slide-29
SLIDE 29

29

NO MORE RANSOM MOVEMENT

slide-30
SLIDE 30

30

HOW CAN WE HELP?

slide-31
SLIDE 31

31

  • Work through typical scenarios and situations
  • Gain greater knowledge and understanding of potential

threats and how to deal with them

  • Skills Assessment
  • Measurable education plan

KASPERSKY’S CYBER SECURITY TRAINING

slide-32
SLIDE 32

32

  • If suspicious application attempts to open users personal files,

it makes a local protected back up copy

  • If is found to be crypto-malware, automatically rolls back

unsolicited changes to system files.

  • Detects encryption algorithm from endpoint to file server
  • Severs connection so no further encryption can occur

KASPERSKY’S SYSTEM WATCHER KASPERSKY’S ANTI CRYPTOR FOR FILE SERVER

slide-33
SLIDE 33

33

REMEMBER, DON’T PAY THE RANSOM!

slide-34
SLIDE 34

34

LET’S TALK?

Kaspersky Lab HQ 39A/3 Leningradskoe Shosse Moscow, 125212, Russian Federation Tel: +7 (495) 797-8700 www.kaspersky.com