Swiss info security body warns of ransomware attacks against businesses

Maria Nikolova

Over the recent weeks, MELANI/GovCERT dealt with more than a dozen ransomware cases.

Switzerland’s Reporting and Analysis Centre for Information Assurance (MELANI) today issued a warning regarding a high number of ransomware attacks against Swiss businesses over the past weeks.

In recent weeks, MELANI / GovCERT has dealt with more than a dozen ransomware cases in which unknown perpetrators encrypted the systems of Swiss SMEs and large companies and rendered them unusable. The attackers made ransom demands of several tens of thousands of Swiss francs, in some cases even millions.

A technical analysis of the incidents revealed that the IT security of the companies affected was often incomplete and the usual best practices (Information security checklist for SMEs) were not fully observed. Furthermore, warnings from the authorities were not heeded.

During the analysis of the incidents in recent weeks, certain weaknesses were identified as the gateway for cyberattacks, such as ignoring the warning messages from antivirus software that malware had been found on servers (e.g. domain controllers). In some cases, remote connections to systems, so-called Remote Desktop Protocols (RDP), were protected with a weak password and the input was only set to the default (standard port 3389) and without restrictions (e.g. VPN or IP filter).

If systems have been encrypted by ransomware, MELANI advises against making a ransom payment. As a general rule, MELANI does not recommend paying because the money will support the hacker’s infrastructure. It should also be noted that even if a ransom is paid, there is no guarantee that the blackmailer will decrypt the data.

If a ransom payment is nevertheless being considered, it should be noted that although systems and data might be decrypted, the underlying infection from malware such as “Emotet” or “TrickBot” will remain active. As a result, the attackers still have full access to the affected company’s network and can, for example, reinstall ransomware or steal sensitive data from it.

MELANI is aware of cases in Switzerland and abroad where the same companies have been victims of ransomware several times within a very short period of time.

Let’s note that, about a week ago, the UK National Cyber Security Center issued an advisory regarding Trickbot. Trickbot is an established banking trojan used in cyber attacks against businesses and individuals. Trickbot attacks are designed to access online accounts, including bank accounts, in order to obtain personally identifiable information (PII). In some cases, Trickbot is used to infiltrate a network. Once inside it can be used to deploy other malware, including ransomware and post-exploitation toolkits.

Read this next

Executive Moves

Scope Markets promotes James Hughes to head of marketing

Belize-based FX and CFDs brokerage Scope Markets has promoted James Hughes, who until recently was its head of brand, to take on an expanded role as the company’s global head of marketing.

Retail FX

Fraudsters clone Financial Commission’s website, two ex-members under suspicion

The Financial Commission, an industry-specific dispute resolution service that caters to the financial services industry, today announced that it believes a clone website has been impersonating its membership roster.

Retail FX

CMC Markets warns of operational challenges in Q1

CMC Markets PLC (LSE:CMCX) said in a trading update for the fiscal year 2023 that February and March posed a more challenging environment with lower equity volumes and a higher proportion of lower margin institutional trading activity.

Interviews

Why Is Digital PR So Important for Financial Service Providers? Buzz Dealer’s CEO Uri Samet with the Answers

Digital PR is all about spreading your message faster, wider, and stronger in the online world, through proper SEO, link-building, and organic and paid social media work.

Inside View

Why And How Are Virtual Cards Disrupting The Finance Industry

Virtual cards have the potential to revolutionize the finance industry by providing faster and more secure payments, wider acceptance, and eco-friendliness.

Interviews

Sweat Economy’s Oleg Fomenko on upcoming launch of Move-to-Earn app in the US

With the crypto winter’s biggest hurdles seemingly behind us as the prices of Bitcoin et al. climb the charts again, the Web3 economy is preparing for the next phase.

Industry News

OptionMetrics acquires Woodseer to add dividend forecast data for equities

“The addition of Woodseer’s product suite will enhance our ability to serve financial market stakeholders and academic institutions in their analysis of equity market performance and risk.”

Digital Assets

Metacade raises over $14.7M as presale set to close in 72 hours

Metacade, one of the most exciting GameFi ventures of 2023, has now raised over $14.7m as the presale goes into its final hours. With over 90% sold, the project expects to sell out ahead of their scheduled closing time, set for Friday 31st March at 23:59 Pacific Time. 

Digital Assets

Coinme launches Circle’s USDC on Stellar network

“By enabling USDC on Stellar in the Coinme wallet, anyone with cash can now utilize the Stellar blockchain to access a fully-backed dollar digital currency. People can now swap their cash for USDC on Stellar and send it in seconds for the cost of a penny.”

<