3 ms·
Afaik that's exactly what these cryptolockers often do: after infecting a system they start encrypting things while sitting between the user and the OS to trans
by solstice 6y ago
Afaik that's exactly what these cryptolockers often do: after infecting a system they start encrypting things while sitting between the user and the OS to transparently forward file access. This also goes for any accessible network drives and external disks that are connected. Then, after a certain time has elapsed (or whatever other metric the malware author has chosen) the cryptolocker stops forwarding file access and holds you ransom.
In that scenario, if your backup drive is writeable from your infected machine, your backups are potentially fucked.
One way to guard against this would be for example a raspberry pi on your network that periodically connects to your (possibly infected) main machine and makes incremental copies over the network to an external HD connected to the Pi. (Meaning the Pi reads and determines what is new, what's is old and how to make the incremental backup.) This of course needs to be coupled to some sort of smart versioning scheme and regular inspection of the backups by the user.