NCSC Annual Review 2021
Pages
Page 14 of 44
Ransomware: Threat methodology
While there are numerous entry points into a system, device or network, the NCSC has observed threat actors have been increasingly exploiting vulnerabilities in virtual private networks, unpatched software and using phishing emails. The most commonly used attack vectors by ransomware actors targeting the UK include:
-
RDP
Remote desktop protocol attacks are the most commonly exploited remote access tools used by ransomware hackers. Hackers use insecure RDP configurations collected through phishing attacks, data breaches or credential harvesting to gain initial access to the victim’s environment.
-
VPN
Since the shift in remote learning and working since the pandemic began, threat actors have been exploiting vulnerabilities present in Virtual Private Networks to take over the remote access.
-
Unpatched devices
Attackers are targeting unpatched software and hardware devices to gain access to the victim’s network. One example of this is the vulnerabilities in Microsoft Exchange Server that are known to have been used by persistent threat groups.
The NCSC released tools and advice designed to help organisations prevent ransomware attacks. These included guidance on mitigating ransomware attacks; a tool called Early Warning Service, designed to help organisations facing cyber attacks on their network; training for school staff, and a range of Active Cyber Defence services including Web Check - a tool that provides website configuration and vulnerability scanning services. This report will set out how the NCSC is bolstering the resilience of the UK in the next chapter.
In the first four months of 2021, the NCSC handled the same number of ransomware incidents as for the whole of 2020 – which was itself a number more than three times greater than in 2019.
