Sunday, January 24, 00:53
Home security Industrial control systems are the new target of Ransomware

Industrial control systems are the new target of Ransomware

Lately, it seems that malicious agents have turned the attacks on ransomware they carry on systems industrial control (ICS). Security researchers say malicious file encryption software to infect computer networks that control functions in manufacturing environments and utility applications is something that has only recently been observed.

Such as he says Cyber-Security Dragos, the ransomware called Ekans (also known as Snake), first appeared in December 2019 and is designed to attack systems Windows used in industrial environments.

Of course there have been some malware that targets ICS in the past. But the researchers concluded that Ekans appears to be the work of a government criminal group involved in the area and that it represents "a unique and specific risk to industrial companies that has not previously been seen in ransomware malware."

Researchers have found that Ekans contains a list of commands and processes related to various functions of the industrial control system designed to disrupt these functions.

The encrypted files are renamed to a random five-character file extension, and a prompt appears ransom with a contact email address to negotiate the amount with the victim.

The attackers behind Ekans may need to infect the network before executing the ransomware attack. This follows the same procedure as ransomware variants such as Ryuk and Megacortex. Dragos reports also note that Ekans may be related to ransomware Megacortex.

Some reports have linked Ekans to Iran, but after analyzing the malware, Dragos concluded that there was no "strong or indisputable evidence" linking this campaign to its strategic interests. Iran.

At present it is not certain how Eksans is distributed to victims, but to protect them from ransomware attacks, it is recommended to isolate ICS systems from the rest of the network, so even if a standard Windows machine is hacked, an attacker will not be able to move to systems that control it infrastructure.

Organizations should also ensure that they keep backups that are stored offline. Backups must include the latest known configuration data to ensure its fast recovery.

LEAVE ANSWER

Please enter your comment!
Please enter your name here

Absent Mia
Absent Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

LIVE NEWS

Instagram: How to enable notifications for specific profiles

There are some profiles on Instagram where you want to see the content they publish as soon as possible - it can be a news ...
00:01:55

NASA's historic launch pad is to be demolished

NASA's famous Mobile Launcher Platform-2 launch platform, which has been linked to the Apollo and Space Shuttle missions, ...
00:02:12

Elon Musk: Gives $ 100 million for best CO2 capture technology

https://www.youtube.com/watch?v=Y0iUZc30vj4 Ο Elon Musk δήλωσε χθες, στο λογαριασμό του στο Twitter, ότι σκοπεύει να δώσει 100 εκατομμύρια...

How can you unblock sites and services using a VPN?

The Internet is free and open to all. However, there are some sites and services whose content is blocked, which ...

Google Chrome: How to manage your extensions?

Google Chrome extensions can be very useful, as they improve your productivity when using the browser.

Intel CPUs Review: Core i7-10700 vs Core i7-10700K!

Over the years, the Intel series of processors (CPUs) introduced the series of overclocking models "K" and more recently the series ...

The DeLorean can return as an electric car

The DMC DeLorean has been out of production for almost 40 years, but it looks like the iconic vehicle will return as an electric car.

Windows RDP servers are used to support DDoS

Cybercrime gangs are abusing Windows Remote Desktop Protocol (RDP) systems to reinforce the unwanted ...

SEPA: He refused to pay a ransom and thousands of files were leaked

Thousands of stolen files of the Scottish Environmental Protection Agency (SEPA) have been published by hackers, after the organization refused to pay the ransom ...

Fines at Valve, Capcom and Zenimax for geo-exclusion of games

Following a European Commission investigation, a group of video game publishers was fined € 7,8 million following allegations of geo-exclusion practices. In...