Business
Notorious ransomware groups now targeting companies with remote encryption
New Delhi, Dec 26
Some of the most active ransomware groups are deliberately switching on remote encryption for their cyber attacks, infiltrating deeper into companies and crippling their operations, a report showed on Tuesday.
In remote encryption attacks, also known as remote ransomware, adversaries leverage a compromised and often underprotected endpoint to encrypt data on other devices connected to the same network.
Sophos, a global leader in delivering cybersecurity as a service, has detected a 62 per cent (year-over-year) increase in intentional remote encryption attacks since 2022.
Some of the most prolific and active ransomware groups, including Akira, ALPHV/BlackCat, LockBit, Royal, and Black Basta, are deliberately switching on remote encryption for their attacks, the report mentioned.
"Companies can have thousands of computers connected to their network, and with remote ransomware, all it takes is one underprotected device to compromise the entire network," said Mark Loman, Vice President, threat research at Sophos, and the co-creator of CryptoGuard anti-ransomware technology.
"Attackers know this, so they hunt for that one 'weak spot' — and most companies have at least one. Remote encryption is going to stay a perennial problem for defenders, and, based on the alerts we’ve seen, the attack method is steadily increasing," Loman added.
Since this type of attack involves encrypting files remotely, traditional anti-ransomware protection methods deployed on remote devices don’t "see" the malicious files or their activity, failing to protect them from unauthorised encryption and potential data loss.
CryptoGuard does not hunt for ransomware; instead, it zeroes in on the primary targets — the files.
"It applies mathematical scrutiny to documents, detecting signs of manipulation and encryption. Notably, this autonomous strategy deliberately does not depend on indicators of breach, threat signatures, artificial intelligence, cloud lookups, or prior knowledge to be effective," according to the company.
"Given that reading data over a network connection is slower than from a local disk, we have seen attackers, like LockBit and Akira, strategically encrypt only a fraction of each file," said Loman.
6 hours ago
Trump, Mamdani bonhomie an unusual photo-op in Oval Office, but how long will truce last?
6 hours ago
Trump Jr grooves with Ranveer Singh at lavish Udaipur wedding as JLo, Bieber join celebrations
9 hours ago
BAPS, United Nations celebrate 30 years of transformative partnership for global harmony
12 hours ago
Ayan Mukerji says 'Love you & Miss you' as he remembers dad Deb Mukherjee on his birth anniversary
12 hours ago
Urmila Matondkar introduces her 'bestest winter essential'
12 hours ago
Tharoor cites Trump-Mamdani interaction to underline need for political cooperation
12 hours ago
ISI steps up effort to build white-collared modules by targeting Indian students abroad
12 hours ago
Prez Murmu participates in Sri Sathya Sai Baba’s birth centenary celebrations in Andhra
12 hours ago
Ready to meet PM Modi to explain Coimbatore, Madurai metro projects: CM Stalin
12 hours ago
No need to do politics on Mandir–Masjid: Former Babri mosque litigant on Trinamool MLA’s remark
12 hours ago
Navy Day 2025 to feature grand operational display of maritime power on Dec 3
12 hours ago
Delhi: AGS arrests accused wanted in attempt-to-murder case in Timarpur
12 hours ago
Govt to ensure uniform safety and health standards for workers
