Skip to main content
Guidance

NCSC Annual Review 2021

Making the UK the safest place to live and work online

Page 14 of 44

Ransomware: Threat methodology

While there are numerous entry points into a system, device or network, the NCSC has observed threat actors have been increasingly exploiting vulnerabilities in virtual private networks, unpatched software and using phishing emails. The most commonly used attack vectors by ransomware actors targeting the UK include:

  • RDP

    Remote desktop protocol attacks are the most commonly exploited remote access tools used by ransomware hackers. Hackers use insecure RDP configurations collected through phishing attacks, data breaches or credential harvesting to gain initial access to the victim’s environment.

  • VPN

    Since the shift in remote learning and working since the pandemic began, threat actors have been exploiting vulnerabilities present in Virtual Private Networks to take over the remote access.

  • Unpatched devices

    Attackers are targeting unpatched software and hardware devices to gain access to the victim’s network. One example of this is the vulnerabilities in Microsoft Exchange Server that are known to have been used by persistent threat groups.

The NCSC released tools and advice designed to help organisations prevent ransomware attacks. These included guidance on mitigating ransomware attacks; a tool called Early Warning Service, designed to help organisations facing cyber attacks on their network; training for school staff, and a range of Active Cyber Defence services including Web Check - a tool that provides website configuration and vulnerability scanning services. This report will set out how the NCSC is bolstering the resilience of the UK in the next chapter.

In the first four months of 2021, the NCSC handled the same number of ransomware incidents as for the whole of 2020 – which was itself a number more than three times greater than in 2019.

Stage 1: Network Intrusion. Stage 2: Propagate, Exfiltrate, Encrypt. Stage 3: Demand Ransom. Stage 4: Post-payment.

Published

Reviewed

Version

1.0

Written for