Select your language

Strategies to Prevent the Next Big Ransomware Attack

ransomware

International. Due to the magnitude of their attacks, dozens of companies in the region are losing the battle against ransomware, and cybercriminals have become sophisticated enough to use ransomware to penetrate large companies, public administrations, global infrastructures or public health organizations, and paralyze them.

As of 2022, the average cost of a single data breach across all industries in the world was around $4.35 billion. This was found to be more costly in the health sector, with each leak reportedly costing the affected party $10.1 million. The financial segment followed closely, each default resulting in a loss of approximately $6 million, $1.5 million more than the global average.

According to Patricio Villacura, Enterprise Security Specialist for Akamai, there are many variants of ransomware. However, looking for specific Vulnerability Indicators or IoCs based on suspicious domain names, IP addresses, and file hashes associated with known malicious activity can help learn more about the origin of the attack and how to respond.

The expert explained that the methodology used by cybercriminals to carry out a ransomware attack usually obeys the following five steps:

- Publicidad -

1) Break the perimeter. Through some of the existing techniques such as brute force attacks, vulnerabilities, phishing, etc., the attacker seeks to access the systems.

2) Gain privileges at the administrator level. It is at this point when the attacker seeks to capture credentials of users of high privileges to be able to make modifications in the configurations of the systems and applications with the sole purpose of preventing the correct operation of the services.

3) Move laterally. The attacker moves laterally in order to recognize the surrounding infrastructure, potentially vulnerable services and detect the existence of the backup data repository.

4) Infection. Once the environment is understood, it is sought to advance to the fourth step, which is to continue with the infection of these servers either by attacking potentially vulnerable protocols such as RDP, SMB or SSH that are precisely easy to present in the normal operation of the systems or the execution of malicious tools such as EthernalBlue, Zerologon, among others.

5) Encrypt. Everything that can be encrypted such as system files, sensitive user data, libraries with system configuration details including permissions, among other data that are vital for the normal day-to-day operation of companies and institutions.

Patricio Villacura stressed that the specific controls that can be established in each of these stages are varied to detect and stop each of them, but it is Microsegmentation that can, from an early stage, prevent not only can critical infrastructure and the services that support it be protected, but also reduce the attack surface.

Here's How Microsegmentation Helps Prevent Ransomware
Micro-segmentation is the fastest way to visualize and segment assets across the data center, cloud, or hybrid cloud infrastructure. The software-based segmentation element of Microsegmentation separates security controls from the underlying infrastructure and gives organizations the flexibility to extend protection and visibility anywhere.

According to the expert, it is important to understand how a Microsegmentation solution would act in the face of a cyberattack, for this he exposed a very famous example that could be avoided with a strategy using this tool.

- Publicidad -

The executive reported that on May 8, 2022, the president of Costa Rica, Rodrigo Chaves, was forced to declare a state of national emergency due to the exfiltration of approximately 700GB of sensitive information of citizens, affecting eight government agencies due to the attack produced by the Conti Ransomware group.

Attackers exploited application source code gaps and gaps in validating public access to government services' SQL databases; They then executed an encryption of the sensitive information of the citizens and then asked for a payment for the ransom of the information before it was disclosed.

According to Patricio Villacura, a Microsegmentation solution could have prevented the expansion of this attack on the operation of the services of the ministries by controlling the communication routes of the tools used by Conti, then by the ability to restrict access to file shares that store sensitive information of citizens and finally, by limiting access to databases and backup servers.

Duván Chaverra Agudelo
Duván Chaverra AgudeloEmail: [email protected]
Editor Jefe
Jefe Editorial en Latin Press, Inc,. Comunicador Social y Periodista con experiencia de más de 13 años en medios de comunicación. Apasionado por la tecnología.

No comments

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Security becomes a technological platform

Security becomes a technological platform

Mexico. Security is moving from a set of standalone systems to an integrated technology platform that combines artificial intelligence, video analytics, sensors, access control, and data platforms....

Security industry in Mexico and Latin America continues its expansion and professionalization

Security industry in Mexico and Latin America continues its expansion and professionalization

International. The security industry in Mexico and Latin America maintains a growth trend driven by digital transformation, the increase in physical and cyber risks, as well as the need to protect...

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

United States. Veeam Software today announced the launch of Agent Commander, a solution aimed at helping organizations detect risks associated with artificial intelligence, protect AI-based systems...

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

In industries where every minute counts, efficient asset and resource management has become a strategic factor to ensure operational continuity, safety, and productivity. By: Héctor Meléndez,...

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Puerto Rico. A centralized monitoring operation developed by Genesis Security was able to significantly reduce the volume of false alarms in its security systems, thanks to the integration of...

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Türkiye. An open-ocean fish farming farm in Turkey implemented a smart surveillance system based on Dahua solar cameras, thermal monitoring, and wireless data transmission to improve safety and...

 The Hidden Security Gap in Data Centers

The Hidden Security Gap in Data Centers

Imagine the journey of an authorized technician inside a data center. When he arrives, he presents his credential and enters the premises, and before entering the server corridor he needs a key to...

Digital fraud increased at Christmas

Digital fraud increased at Christmas

Colombia. During the holiday season, as e-commerce and digital transactions intensified, online fraud attempts also increased. Fake promotions, impersonation of businesses and messages that...

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Mexico. Milestone Systems, a leading provider of open platform video management software (VMS), hosted the Milestone XPerience Days Mexico 2025 event, a gathering that brought together industry...

Hikvision Mexico launches the third edition of

Hikvision Mexico launches the third edition of "Hikvision Women"

Mexico. Hikvision Mexico announced the launch of the third edition of its "Hikvision Women" program, an initiative aimed at strengthening the participation and professional development of women in...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter