3. 3
• A malware that encrypts the victim’s files and
is controlled by the attacker
• Victim is usually an organization but could be
an individual as well
• The attacker “WILL” demand a payment to
decrypt the files
• The attacker might
• Copy victim data before encryption
• Threaten to publish said data (a.k.a. Cyber
Extortion)
• Publish a portion of the data as ‘proof of life’ (to
prove they have your data)
@rohit11|@sccs1300
What is Ransomware?
4. 4
Anatomy of a Ransomware attack
Attacker
Malware comes mostly via
• email
• RDP
• Drive by downloads
Attackers makes a copy of file
(In many cases)
Encrypts the files Demands for ransom
If ransom is paid,
Attacker “MAY” share the
keys to decrypt
@rohit11|@sccs1300
15. 15
Protecting against Ransomware - Advance
@rohit11|@sccs1300
If you MUST have Remote Desktop enabled
Ensure “Remote Desktop with Network Level Authentication”
is enabled
Right click on My PC > Properties > Advanced System Settings
> Remote > Select “Allow Connections only from computers
running Remote Desktop with Network Level Authentication
Also configure firewall to allow only from limited set of IP address
2. Disable Remote Desktop
16. 16
Protecting against Ransomware - Advance
@rohit11|@sccs1300
Right click on My PC > Properties > Advanced System Settings
3. Disable Remote Assistance
18. 18
Other General Measures
Few other important measures one should consider
• Disable RDP access (port 3389) from the outside world.
• If required allow only from limited IPs, not anyone in the world.
• Disable SMB access (port 139) from the outside world.
• Make sure passwords are strong enough.
• Disable SMB v1
• Disable hidden shares/admin shares etc.
If you still MUST keep RDP open to the world and still want to be secure,
we are just a tweet away…
@rohit11|@sccs1300
19. 19
Should the victim pay the ransom?
@rohit11|@sccs1300
NO
OK. Theoretically, NO
However, it has been seen in past that some medical institutions have paid to ensure life saving systems are working
unaffected.
Remember paying ransom will
fuel their economy and who
knows fuel many other crime in
background…