6 ms·
I wonder when ransomware will get smart enough to detect backups and insinuate themselves into them to foil the "just restore from backups" strategy.
by VectorLock 7y ago
I wonder when ransomware will get smart enough to detect backups and insinuate themselves into them to foil the "just restore from backups" strategy.
- mkagenius 7y agoMost likely they already do that if its on the same computer. Details aren't out yet, but I would guess the backups came from other computers.
- AnIdiotOnTheNet 7y agoThere are many known cases of ransomware attacks that have deleted backup repositories.
- LoveKebabble 7y agoThey already do, I worked a case last week where that happened. Trickbot for example will be on a machine for 2-5 months so that it's in your backups, and is commonly followed by Ryuk ransomware. So if you get hit with Ryuk and just restore from backups without re-mediating anything you will likely be hit with Ryuk again.
- emmp 7y agoYes. They are often targeting IT providers of SMBs by phishing/otherwise compromising their credentials, and deleting backups before encrypting. It works sometimes, 2FA hygiene and secondary site redundancy are usually good enough to protect you.
- ev0lv 7y ago2FA is so overrated. You can so easily do a sim swap to get access to a particular phone number and bypass 2FA.
- therealrootuser 7y agoThe problem isn't with 2FA, the problem is with SMS-based 2FA.
- bonestamp2 7y agoTrue, and that's why you shouldn't use SMS 2FA. The unfortunate part is when that's the only method offered.
- parliament32 7y agoTOTP and HOTP 2FA are unbreakable and supported by literally everyone. Who still does SMS 2FA anymore?
- out_of_protocol 7y agoLots, unfortunately. With no way to opt out
- i_cant_speel 7y agoIf you inject the ransomware into a system that is subsequently backed up and wait a significant period of time, you could potentially lock all backups as they are restored. Then people have to decide between paying up or restoring to a time before the ransomware was injected. I'm not sure if it's feasible to have ransomware lock backups as they're restored, however.