Thursday, February 18, 2016

Locky Ransomware on the Loose

It appears the Dridex Crew has expanded their Cyber Crime Portfolio from the stealing of login credentials to your favorite Financial Institution... to Ransomware.  Case in point:

- M$ Word Documents with malicious macros are being distributed via email attachments (sound familiar).

First Question - Will your users allow you to block all inbound Microsoft Word attachments?  Likely not...

Second Question - Are your spam prevention techniques 100% effective?  Ummm... no.

Third Question - Should we therefore feel confident that your Anti Virus Solution has your back and will detect the file at the gateway or desktop?  PLEASE!!!

- Thankfully, the Forcepoint File Sandboxing feature will detect this Ransomware.  On the other hand, if you are using an inferior solution, you are likely seeing Help Desk Tickets describe something looking like this:


- Anyone care to know the current AV Detection Rate?  Currently only 5 of 54 AV Engines are detecting the file properly.  How long do you think it will take before McAfee and Symantec get their act together?



In summary, this is the same crew who took down the Hollywood Presbyterian Medical Center over the weekend.  Do you wish to stay out of the news?  Need help from an organization who performed over 600 Security Projects in 2015??  Contact ESPO Systems here.

1 comment: