NCSC Annual Review 2021
Pages
Page 13 of 44
Ransomware: Ever evolving threat
In the last Annual Review, the NCSC set out how the ransomware model had shifted from not only withholding data but threatening to publish it as well. This year the model has developed further into what is termed Ransomware as a Service, (RaaS) where off-the-shelf malware variants and online credentials are available to other criminals for a one-off payment or a share of profits.
As the business model has become more and more successful, with these groups securing significant ransom payments from large businesses who cannot afford to lose their data to encryption or to suffer the down time while their services are offline, the market for ransomware has become increasingly ‘professional’.
The NCSC has observed that some victims have been offered the services (from the attackers) of a 24/7 help centre to quickly pay the ransom and get back online. Everything is geared to make it as easy as possible to simply pay the ransom and move on.
Organised crime groups spend time conducting in-depth reconnaissance on their targeted victims. They will identify exploitable cyber security weaknesses. They will use spoofing and spearphishing to masquerade as employees to get access to the networks they need. They will look for the business-critical files to encrypt and hold hostage. They may identify embarrassing or sensitive material that they can threaten to leak or sell to others. And they may even research to see if a potential victim’s insurance covers the payment of ransoms.
This process can be painstaking and lengthy, but it means that, when they are ready to deploy, the effect of ransomware on an unprepared business is brutal. Files are encrypted. Servers go down. Digital phone lines no longer function. Everything comes to a halt and business is stopped in its tracks.
But it’s not all bad news. There are many services that organisations can use to protect themselves against ransomware or mitigate the impact of an attack. As well as implementing practical cyber security measures and following advice, an important defence against ransomware is to understand the ever-evolving threat picture and working with others to share information and good practice.
The NCSC’s Cyber Security Information Sharing Partnership (CISP) service provides a secure forum where companies and government can collaborate on threat information. CISP, which also gives access to regular sensitive threat reports, is one of many tools available, as can be seen in the next chapter.
How Active Cyber Defence (ACD) protects against the ever evolving threat of ransomware
The NCSC provides a range of free cyber security tools and services to eligible organisations as part of the Active Cyber Defence (ACD) programme. These initiatives help organisations to find and fix vulnerabilities, manage incidents or automate disruption of cyber attacks. Some of our services are designed primarily for the public sector, whereas others are made available more broadly to private sector or citizens, depending on their applicability and viability.
1. Preventing ransomware getting in
ACD helps organisations secure aspects of their IT that are frequently exploited to deliver ransomware.
-
Phishing and exposed Remote Desktop Protocol
We know that phishing and compromise of exposed Remote Desktop Protocol ports are the main vectors for ransomware
-
Mail Check
Mail Check helps users configure a security protocol called DMARC which protects against phishing that involves spoofing their domains. NCSC’s Synthetic DMARC service does the same for non-existent gov.uk domains.
-
Web Check and Early Warning
Web Check and Early Warning scan users’ web services for exposed ports, such as port 3389 which is used for Remote Desktop Protocol.
-
Software vulnerabilities
Another common vector for ransomware is software vulnerabilities, which HBC, Early Warning, Web Check, the Vulnerability Disclosure Service and Vulnerability Disclosure Toolkit seek to address.
2. Preventing ransomware working
ACD helps to disrupt ransomware that makes it through the first line of defence onto an organisation’s network.
-
Protective Domain Name System
Protective Domain Name System (PDNS) can prevent ransomware from operating by blocking connections to known ransomware domains. The deny-list is drawn from a range of sources including commercial feeds and NCSC intelligence.
-
Suspicious Email Reporting Service
The Suspicious Email Reporting Service (SERS) allows members of the public to report suspicious emails to the NCSC. Any ransomware domains that are identified by SERS are passed to the Takedown service. The Takedown service also receives feeds of malicious domains from other sources and it sends notices requesting the removal of malicious domains to the companies that host them. The Takedown service also adds the malicious domains to safe browsing lists so modern browsers block access to them. As part of our Routing and Signalling work, the SMS SenderID Protective Registry is similar to PDNS but for SMS.
-
Exercise in a Box
The Exercise in a Box service helps organisations practice their response to cyber security scenarios and incidents. These exercises help organisations prepare to limit the impact of cyber attacks, including ransomware.
3. Enabling investigation and incident response
ACD provides data and tools to investigate suspected ransomware and respond to it.
-
PDNS
Even when a ransomware domain is unknown to the PDNS deny-list at the time of the suspicious query, the service records the fact a customer organisation attempted to connect to the domain. These records can be used to identify the presence of ransomware in an organisation after the event, once the domain is identified as suspicious.
-
HBC
HBC can detect threats on customer networks. The software agent is installed widely on OFFICIAL government devices and sends technical metadata to NCSC’s expert analysts who use specialist techniques to identify suspicious activity.
-
HBC and PDNS
HBC and PDNS are complementary. PDNS provides an estimate of which organisations might be affected by ransomware, whereas HBC is well placed to conduct more detailed investigations into activity on specific devices.
-
Early Warning
Early Warning can identify active compromises on customer networks by mapping threat intelligence from a variety of sources to customer IP ranges, ASNs and domain names. The service alerts users to incidents, suspicious network activity, vulnerabilities, and undesirable open ports.