On CBS.com: HD may burn your eyes
BNET Business Network:
BNET
TechRepublic
ZDNet

By ZDNet UK Staff
Posted on ZDNet News: Jul 24, 2006 7:03:00 PM

Smaller companies should back up their data if they want to avoid being held to ransom by hackers, a security company has warned.

Hackers are using sophisticated ransomware, which is malicious code, to hijack a company's user files, encrypt them and then demand payment in exchange for the decryption key, Kaspersky Labs said on Monday. The security specialist said that the encryption algorithms used by cybercriminals are becoming increasingly complicated, foxing antivirus companies.

"There's a potential situation where antivirus companies won't be able to decrypt the files," said David Emm, senior technology consultant at Kaspersky U.K. "Within a corporation, the IT department normally backs up files. The danger is where attacks are launched at smaller businesses (without IT departments) and individuals."

Trojan horse programs can be sent out as spam or hidden on malicious sites. Once a machine is infected, files are either encrypted individually or grouped together and locked in a password-encrypted folder.

Strong algorithms such as RSA public key encryption, one of the most popular technologies, are increasingly being used by criminals to foil the decryption techniques used by antivirus companies.

Since January, Kaspersky has seen an increase in the strength, from 56-bit to 660-bit keys, of the encryption being used by hackers to lock files. "Virus writers' attitude to date is that encryption only needs to be strong enough. It's alarming that we're now getting onto the level of serious encryption," Emm said.

Kaspersky claims to have seen an increase in the amount of ransomware, but says it has not seen an epidemic. "It seems to have been escalating, but it's just one weapon within their arsenal," Emm said.

Antivirus vendor Sophos said businesses should not have a problem with ransomware, as their files will have been backed up.

"If your data is backed up, you can recover," said Graham Cluley, senior technology consultant for Sophos.

For Sophos, a bigger problem is "filenapping." Once a machine is infected, all files and information are copied and wiped from the original system. A victim must then pay a ransom to recoup their filenapped data.

Sophos said it was not seeing "a tidal wave of activity," but confirmed that encyption algorithms used are getting more sophisticated.

Last month, the U.K.'s Greater Manchester Police decided not to pursue the criminals who used a Trojan horse program called Archiveus to lock a Rochdale woman's files and demand a ransom to release them.

Tom Espiner of ZDNet UK reported from London.

  • Talkback
  • Most Recent of 14 Talkback(s)
RE: Beware of ransomware, firm warns
I am disappointed by the fact that so many people can't spell "dissapointed" (Read the rest)
Posted by: elt10@... Posted on: 08/14/08 You are currently: Logged In | Log out
Casting a suspicious eye Chad_z   | 07/24/06
exactly what they'd have to do with Windows voska   | 07/24/06
well our linux server just got hacked stevey_d   | 07/24/06
You know that what you said did not happen... michael_t   | 07/24/06
I'd say your being nieve voska   | 07/25/06
I am dissapointed, as I thought U could think a little prior to reply. michael_t   | 07/25/06
Not Linux' fault; admin/user to blame here buran   | 07/24/06
I find that running ssh on swoopee   | 07/25/06
Rootkit as unprivileged user? Unpatched machine. 4:2:2   | 07/25/06
Pretty suspect scenario TripleII   | 12/13/06
More "reasons" to switch to Vista :-) michael_t   | 07/24/06
yeah and still yet not of this world   | 07/24/06
I'd like to see them sue under the DMCA buran   | 07/24/06
RE: Beware of ransomware, firm warns elt10@...   | 08/14/08

What do you think?