Hackers Use Remote Desktop Services For Ransomware

As crazy as it may seem, hackers use remote desktop services for ransomware. Ransomware continues to be the weapon of choice for hackers around the world, but their distribution methods are evolving.  Recently, a new strain of the ransomware known as CryptoMix was found in the wild, sporting a new distribution methodology.

Hackers are beginning to target publicly exposed remote desktop services and installing their poisoned software manually.

In the case of the remix of CryptoMix, once installed, the malware appends the .DLL extension to all encrypted files and predictably demands a ransom from the victim to get his or her files back. Despite the evolving delivery method, the threat remains the same, so perhaps it’s time for a review.

Here are several things your staff can do to minimize your risk of being taken offline by a ransomware attack:

  • Back your data up religiously. This isn’t so much a prevention strategy as it is an insurance policy.  It should go without saying, but too many SMBs don’t do this, so we wanted to list it first.
  • Make sure your employees are absolutely phobic when it comes to opening attachments from people they don’t know and trust. Even in cases where they recognize the sender, it’s always best to take the step of phone verification before actually opening the file.
  • All attachments should be scanned with a robust antivirus tool before opening
  • Be sure your people know not to connect Remote Desktop Services directly to the internet. Everyone using such services should do so via a VPN.
  • Make sure all Windows updates and security patches are installed in a timely fashion. Many a problem can be avoided simply by keeping your software up to date.
  • If you’re not using some type of security software that relies on behavioral detection or white list technology, you’re not doing your company any favors.

None of these things (even taken together) will absolutely ensure that you don’t fall victim to a determined hacker, but they will dramatically reduce your risk.

Get managed IT services for your business.

Managed IT services are an effective means of network security and protecting your business from cyberattacks. It allows businesses to allocate resources elsewhere and maintain productivity without the worry of having their operations interrupted. When you need IT network management services for your Orange County business, consider C3 Tech. We’ll manage all of your IT services and keep them at peak operation for a flat-rate fee, so you can focus your efforts on spurring your revenues to grow. Let us give you the peace of mind you deserve today with C3 Tech’s managed services for small and medium-sized businesses.

Used with permission from Article Aggregator