Swiss info security body warns of ransomware attacks against businesses

Maria Nikolova

Over the recent weeks, MELANI/GovCERT dealt with more than a dozen ransomware cases.

Switzerland’s Reporting and Analysis Centre for Information Assurance (MELANI) today issued a warning regarding a high number of ransomware attacks against Swiss businesses over the past weeks.

In recent weeks, MELANI / GovCERT has dealt with more than a dozen ransomware cases in which unknown perpetrators encrypted the systems of Swiss SMEs and large companies and rendered them unusable. The attackers made ransom demands of several tens of thousands of Swiss francs, in some cases even millions.

A technical analysis of the incidents revealed that the IT security of the companies affected was often incomplete and the usual best practices (Information security checklist for SMEs) were not fully observed. Furthermore, warnings from the authorities were not heeded.

During the analysis of the incidents in recent weeks, certain weaknesses were identified as the gateway for cyberattacks, such as ignoring the warning messages from antivirus software that malware had been found on servers (e.g. domain controllers). In some cases, remote connections to systems, so-called Remote Desktop Protocols (RDP), were protected with a weak password and the input was only set to the default (standard port 3389) and without restrictions (e.g. VPN or IP filter).

If systems have been encrypted by ransomware, MELANI advises against making a ransom payment. As a general rule, MELANI does not recommend paying because the money will support the hacker’s infrastructure. It should also be noted that even if a ransom is paid, there is no guarantee that the blackmailer will decrypt the data.

If a ransom payment is nevertheless being considered, it should be noted that although systems and data might be decrypted, the underlying infection from malware such as “Emotet” or “TrickBot” will remain active. As a result, the attackers still have full access to the affected company’s network and can, for example, reinstall ransomware or steal sensitive data from it.

MELANI is aware of cases in Switzerland and abroad where the same companies have been victims of ransomware several times within a very short period of time.

Let’s note that, about a week ago, the UK National Cyber Security Center issued an advisory regarding Trickbot. Trickbot is an established banking trojan used in cyber attacks against businesses and individuals. Trickbot attacks are designed to access online accounts, including bank accounts, in order to obtain personally identifiable information (PII). In some cases, Trickbot is used to infiltrate a network. Once inside it can be used to deploy other malware, including ransomware and post-exploitation toolkits.

Read this next

blockdag

Crypto News: BlockDAG’s X30 Miner Excels in Crypto Mining While Ethereum & XRP Prices Fall

Learn how BlockDAG’s X30 Miner remains a solid investment despite Ethereum’s price volatility and XRP’s declining trends.

Digital Assets

SEC seeks $5.3 billion fine for Terraform and co-founder Do Kwon

Federal regulators are pursuing a fine of $5.3 billion against Terraform Labs and its co-founder Do Kwon for defrauding investors, following a recent verdict that found them liable for a multi-billion-dollar fraud.

Digital Assets

El Salvador’s Bitcoin wallet hacked by CiberInteligenciaSV

El Salvador’s official Bitcoin wallet, Chivo, has faced another security setback as the hacker group CiberInteligenciaSV released parts of the wallet’s source code on the black hat hacking forum BreachForums.

blockdag

BlockDAG’s $19.8M Presale & Moon Keynote Teaser Place It Above KANG, SOL, & ARB as the Top Crypto Investment in 2024

Uncover the success behind BlockDAG’s $19.8M presale and learn what’s making it a more compelling investment than KangaMoon, Solana, and Arbitrum.

Fintech

Revolut to share user interactions data with ad agencies

Fintech giant Revolut is exploring new revenue streams by planning to share customer data with advertising partners.

Chainwire

Zircuit Staking Soars Past $2B TVL In Only 2 Months

Zircuit, a ZK rollup with parallelized circuits and AI-enabled security, today announced that its staking program has soared past $2B in TVL in only 2 months. 

Retail FX

PrimeXBT joins Financial Commission’s membership roster

The Financial Commission, an independent external dispute resolution (EDR) body, today announced the addition of cryptocurrency trading firm PrimeXBT as its latest member effective March 6, 2024.

Digital Assets

Ripple wants to reduce SEC’s $2 billion penalty to $10 million

Ripple Labs has responded to the U.S. Securities and Exchange Commission’s (SEC) recent demand for $2 billion in penalties, arguing that the amount should be substantially reduced to $10 million. The legal stance was disclosed in a court document filed late Monday.

blockdag

Analysts Go Bullish On BlockDAG After Its Surge to $0.005 And Unique Developer Platform That Goes Beyond Ethereum & BONK

Discover how BlockDAG’s unique low-code and no-code platforms offer more adaptability than Ethereum’s bull run and BONK’s fluctuating prices.

<