SamSam Ransomware is back with New Variant - PowerPoint PPT Presentation

About This Presentation
Title:

SamSam Ransomware is back with New Variant

Description:

Considered as the most infamous and well-known ransomware today, which alone stole over $325,000 in just 4 weeks since its first appearance last January, SamSam ransomware is back with a new plot in mind. Now it asks for the attacker's password first before infection. – PowerPoint PPT presentation

Number of Views:38
Slides: 8
Provided by: phishingsolutions
Category:

less

Transcript and Presenter's Notes

Title: SamSam Ransomware is back with New Variant


1
SamSam Ransomware is Back with New Variant
www.izoologic.com
2
SamSam Ransomware
Considered as the most infamous and well-known
ransomware today, which alone stole over 325,000
in just 4 weeks since its first appearance last
January, SamSam ransomware is back with a new
plot in mind. Now it asks for the attacker's
password first before infection.
www.izoologic.com
3
SamSam Ransomware is Back
  • Researchers found this particular malware strain
    which uses modules and behaves differently than
    its previous version.
  • At first thought, making a ransomware with
    password-protected activation method does not
    substantially increase its firepower, but at a
    deeper glance, it protects itself against
    security researchers by not letting it activate
    automatically.
  • This, in turn, impedes and greatly restrict the
    researchers from figuring out the blueprint of
    SamSam.

www.izoologic.com
4
SamSam Ransomware is Back with New Variant
  • Nonetheless, researchers identified five main
    components of SamSam ransomware, the last of
    which is the manual password request from the
    attacker.
  • It contains a setting that needs to be executed
    directly and is running in .NET exe, purposely
    for decrypting an encrypted file via the
    attacker's command-line.

www.izoologic.com
5
SamSam Ransomware is Back with New Variant
  • It is also speculated that the newer SamSam was
    designed this way to target more valuable victims
    than simply spreading the strain to ordinary
    civilians.
  • After all, this particular ransomware handpicked
    several local government agencies in Atlanta and
    managed to breach and subsequently lock their
    data.
  • Afterwards, the attackers ransomed them for
    6,800 per PC, or 51,000 for the whole network.

www.izoologic.com
6
SamSam Ransomware is Back with New Variant
  • It's not new for information security personnel
    to develop ways against the increasing threat of
    malware evolution.
  • Simply reviewing essential IT security methods
    would have made a better message at not giving
    the attackers what they want, or at least to
    block off certain system vulnerabilities that
    they commonly exploit.
  • A good system monitoring and network segmentation
    set in place usually dictate how easily a
    ransomware will pass through, unmitigated.
  • Lastly, company policies should reflect
    information security awareness well enough for
    lower chances of system breaching.

www.izoologic.com
7
Contact Us
14 Hanover Street, W1S 1YH City of Westminster,
London UNITED KINGDOM
44 20 3734 2726
info_at_izoologic.com
www.izoologic.com
Write a Comment
User Comments (0)
About PowerShow.com