Cybersecurity threats are becoming more sophisticated, targeted, and potentially catastrophic. This is particularly true of the most dominant form of cyberattack – ransomware.
Rather than a mass opportunistic, shotgun approach to distributing ransomware campaigns, today’s cyber criminals are being highly strategic in how they direct attacks, as seen in the recent coordinated ransomware attack against 23 towns in Texas. In their field of view are organizations in possession of lucrative data, such as healthcare, government, utilities, financial, and professional services sectors. Hackers are also honing in on organizations with known vulnerabilities, such as open ports and unpatched systems.
But a disturbing new strategy is rapidly changing the hackers playbook. A study from researchers at security firm Vectra reveals that, in the search for bigger payoffs from victims, cybercriminals are setting their sights on shared files stored on-premises, in data centers, and in the cloud.
Discriminating criminals see rewards in network-centric attacks
Traditionally, criminals have propagated ransomware by targeting isolated endpoints and holding local files hostage. As the Vectra study states: “The most effective weapon in carrying out a ransomware attack is the network itself...When the infected computer has access to documents in network share volumes – with their high capacity data storage – that single host can lock access to documents across several departments in a targeted organization.”
This mode of attack becomes far more devastating when it scales to cloud infrastructures. Organizations can find themselves locked out of their cloud-hosted business systems without any warning that a ransomware attack has taken place. Data loss is bad enough, but without access to key files or the ability to access cloud-based productivity apps and email, the outcome can be devastating. This scenario occurred earlier this year when a ransomware strain impacted two cloud service providers: DataResolution.net and iNSYNQ. More than 30,000 customers were unable to access their cloud-based services.
Ironically, many of these file shares and cloud providers are used to store files to maintain proper backup in the event of a cyberattack – making recovery a challenge.
“It’s an efficient, premeditated criminal threat with a rapid close and no middleman,” – ominous words from Vectra’s researchers.
Think like a cybercriminal, see what they see
As cybercriminals become increasingly adept at understanding where common vulnerabilities are and use new tactics, techniques and procedures (TTPs) to exploit them at scale, organizations must do everything they can to ensure their security postures are as robust as possible.