Swiss info security body warns of ransomware attacks against businesses

Maria Nikolova

Over the recent weeks, MELANI/GovCERT dealt with more than a dozen ransomware cases.

Switzerland’s Reporting and Analysis Centre for Information Assurance (MELANI) today issued a warning regarding a high number of ransomware attacks against Swiss businesses over the past weeks.

In recent weeks, MELANI / GovCERT has dealt with more than a dozen ransomware cases in which unknown perpetrators encrypted the systems of Swiss SMEs and large companies and rendered them unusable. The attackers made ransom demands of several tens of thousands of Swiss francs, in some cases even millions.

A technical analysis of the incidents revealed that the IT security of the companies affected was often incomplete and the usual best practices (Information security checklist for SMEs) were not fully observed. Furthermore, warnings from the authorities were not heeded.

During the analysis of the incidents in recent weeks, certain weaknesses were identified as the gateway for cyberattacks, such as ignoring the warning messages from antivirus software that malware had been found on servers (e.g. domain controllers). In some cases, remote connections to systems, so-called Remote Desktop Protocols (RDP), were protected with a weak password and the input was only set to the default (standard port 3389) and without restrictions (e.g. VPN or IP filter).

If systems have been encrypted by ransomware, MELANI advises against making a ransom payment. As a general rule, MELANI does not recommend paying because the money will support the hacker’s infrastructure. It should also be noted that even if a ransom is paid, there is no guarantee that the blackmailer will decrypt the data.

If a ransom payment is nevertheless being considered, it should be noted that although systems and data might be decrypted, the underlying infection from malware such as “Emotet” or “TrickBot” will remain active. As a result, the attackers still have full access to the affected company’s network and can, for example, reinstall ransomware or steal sensitive data from it.

MELANI is aware of cases in Switzerland and abroad where the same companies have been victims of ransomware several times within a very short period of time.

Let’s note that, about a week ago, the UK National Cyber Security Center issued an advisory regarding Trickbot. Trickbot is an established banking trojan used in cyber attacks against businesses and individuals. Trickbot attacks are designed to access online accounts, including bank accounts, in order to obtain personally identifiable information (PII). In some cases, Trickbot is used to infiltrate a network. Once inside it can be used to deploy other malware, including ransomware and post-exploitation toolkits.

Read this next

Institutional FX

Tradeweb pulls in $408.7 million in Q1 revenue amid record trading volumes

Tradeweb Markets Inc. (NASDAQ: TW) has just announced its financial results for the first quarter of 2024, which showed a robust performance for the three months through March.

Institutional FX

BGC Group valued at $667 million following investment by major banks

BGC Group announced that its exchange platform, FMX Futures, is now valued at $667 million after receiving investments from a notable consortium of financial institutions.

blockdag

Transforming a Bankrupt Investor into a Cryptocurrency Giant; Can BlockDAG Replicate Ethereum’s Meteoric Rise With 30,000x Predictions?

The realm of cryptocurrency investing presents a thrilling blend of challenges and opportunities. The legendary gains by early Ethereum investors serve as a powerful lure for those seeking the next major breakthrough.

Digital Assets

SEC delays decision on spot bitcoin options ETFs

The U.S. Securities and Exchange Commission (SEC) has postponed its decision on whether to authorize options trading on spot bitcoin ETFs, extending the review period by an additional 45 days. The new deadline for the SEC’s decision is now set for May 29, 2024.

Market News, Tech and Fundamental, Technical Analysis

Solana Technical Analysis Report 25 April, 2024

Solana cryptocurrency can be expected to fall further toward the next support level 130.00, target price for the completion of the active impulse wave (i).

Digital Assets

Morgan Stanley to sell bitcoin ETFs to clients

Morgan Stanley may soon allow its 15,000 brokers to recommend bitcoin ETFs to their clients, as reported by AdvisorHub.

Digital Assets

Masa Announces Comprehensive AI Developer Ecosystem with 13 Dynamic Partners Focused on Leveraging Decentralized Data and Large Language Models

In a groundbreaking development, Masa, the global leader in decentralized AI and Large Language Models (LLMs), proudly announces the launch of its AI Developer Ecosystem, partnering with 13 visionary projects.

Financewire

Kinesis Mint becomes the official partner for the House of Mandela

Kinesis Mint, the certified independent precious metals mint and refinery of Kinesis, the monetary system backed by 1:1 allocated gold and silver, has been appointed the exclusive coin producer for the House of Mandela.

Chainwire

Kadena Announces Annelise Osborne as Chief Business Officer

Kadena, the only scalable Layer-1 Proof-of-Work blockchain, expands its leadership team by onboarding Annelise Osborne as Kadena’s new Chief Business Officer (CBO).

<