A locked computer and a ransom demand. Losing access to personal information on a computer or mobile device scares everyone. Intimate data and access to personal finances or identity are increasingly being attacked by hackers in our region.
The seriousness of the situation and the resulting risks depend mainly on the type of device that was attacked. A corporate computer can threaten a large financial scale. On the other hand, corporate software tends to be more resistant and better protected.
Attacks on personal devices are unpleasant in terms of intimacy. In addition to the loss of privacy, the scariest thing is the idea that an attacker will steal your identity or “whitewash” your bank accounts.
Ransom or expert
Similar attacks do happen. The most common type is ransomware. This is a type of malicious software that a hacker or a “software robot” created by the hacker blocks a computer system or encrypts the data stored in it.
The attacker then demands a ransom from the victim to restore access. A message with information about the ransom is usually displayed on the infected computer - after payment, the victim is provided with a password or other key to decrypt the data.
Companies and hospitals
Another problem is that the attacker cannot be trusted. Even paying the ransom often does not mean that the system will be unlocked and the data will not be misused. Often, the victim is dragged into a long-term or even causes further damage in the meantime. Another virus is often installed with ransomware, which creates the possibility for the attacker to return. It is therefore still better to deal with the matter immediately with experts.
The first ransomware samples were discovered in Russia in 2005-2006, created by Russian organized criminals and targeting mainly Russian victims living in neighboring Russian-speaking countries such as Belarus, Ukraine and Kazakhstan.
Its forms and modifications are increasingly occurring in the rest of the world. For example, the large-scale WannaCry ransomware attack from May 2017 is well-known, which attacked more than 150 countries. It targeted the business environment. In England, it also affected hospitals and their technical equipment, directly endangering the lives of patients. In addition to the impact on the lives of citizens, the attack also had an economic impact. Companies and institutions suffered direct and indirect damages of more than 4 billion US dollars.
Slovakia and the Czech Republic also
The malicious code exploited a hole in the Windows system, which was also used for its purposes by the National Security Agency in the USA - NSA. Its name is EternalBlue. The exploit was carried out by hackers from the Shadow Brokers group, who stole NSA hacking tools and made them available.
Microsoft also knew about the existence of this flaw. It therefore released an update to Windows 10 and removed the hole. However, it was too late. The attack was confirmed by a hospital in Nitra, for example. The entire system was down for several days, which had to be replaced by information exchanged on paper. This slowed down procedures and jeopardized patient treatment.
According to cybersecurity expert Aleš Špidla, a similar attack that also affected public institutions of civic amenities occurred in the unprepared health system in the Czech Republic in 2013-2014. The accompanying phenomenon was that the personal data of thousands of Czech citizens disappeared from public databases.
Some types of ransomware also spread without an internet connection, for example via SMS, which triggers the virus after the device is subsequently connected to the network.
Prevention and professional protection
A common mutation of ransomware is also a combination with “displayscreen”. This is a procedure where the hacker displays a “fake display” of the display on the device. The user thinks that he is clicking on items other than in reality and the hacker directs him to the desired options.
The best protection against these attacks is sufficient prevention. The logical protection is regular updates of the operating system, a quality general antivirus program, avoiding suspicious files and websites. Never respond to unsolicited email and multimedia messages. Also be vigilant when allowing remote access and using the Internet on public wifi networks.
Professionals, as well as laypeople, are increasingly using specialized protection applications and programs. These sophisticated solutions for protection against ransomware attacks, which can protect companies and institutions, are offered, for example, by the Slovak ANASOFT.