Windows security warning: Ransomware is growing fastest, and just got harder to tackle
Ransomware is growing fast and could become more difficult to tackle as the criminal ecosystem shifts from a few dominant players to many smaller ones.
Tech security company Bitdefender analysed Windows security threats including ransomware, coin miners, fileless malware, PUAs ('potentially unwanted applications' that can compromise privacy or security), exploits (attacks based on unpatched or previously-unknown vulnerabilities) and banking Trojans.
Bitdefender found that of all these threats, ransomware reports saw the biggest year-on-year increase – 74.2%. Ransomware also ranked first in terms of the total number of reports.
According to the security company, the number of ransomware reports actually dropped during the first half of 2019, largely because the group behind the GandCrab ransomware throttled down their operation.
But since then, ransomware reports climbed again as new ransomware has emerged to fill the void left by GandCrab (it's also possible they have now restarted operations).
While new ransomware such as Sodinokibi (aka REvil or Sodin) have not replaced GandCrab, they are seeing growth.
"The fall of GandCrab, which dominated the ransomware market with a share of over 50 percent, has left a power vacuum that various spinoffs are quickly filling. This fragmentation can only mean the ransomware market will become more powerful and more resilient against combined efforts by law enforcement and the cybersecurity industry to dismantle it," the report said.
Bitdefender said reports of coin miners and fileless malware both declined slightly in the period, although it noted: "With cybercriminals intrinsically motivated by profit – and as a result investing time and effort in building threats that find alternatives ways of providing that – cryptocurrency miners are not likely to go away any time soon."
All this focus on Windows means that malware writers have little time for Macs – or at least those owned by the average computer user. "With Windows remaining a lucrative battlefront, there is little incentive for malware authors to invest time and resources to develop mass-market Mac-centric threats, focusing mostly on advanced and sophisticated threats designed for C-level executives and decision-makers," said the Bitdefender report.
But before Apple fans get too smug, that's not to say Macs are not immune to threats: ransomware may be scarce on macOS, but it has been "easily" targeted by crypto-jacking operations, attacks using known vulnerabilities, and what Bitdefender calls 'potentially unwanted applications' – software that may be useful but may also compromise privacy or security.
In the first half of 2019, some of the most common threats directed at macOS revolved around coin miners, PUAs and exploits, according to Bitdefender telemetry. While most threats involving coin miners leverage compromised websites that "borrow" computing power to manufacture cryptocurrency, some attacks aim to steal user cookies from cryptocurrency wallets that frequently contain login credentials for various cryptocurrency exchanges.
Industry: Cyber Security
- DevSecOpp- Security design / review consultant. SC Clearance. London
CH7838 London £70,000 DevSecOpp- Security design / review consultant. DevSecOpp- Security design / review consultant will ensure that newly created, public facing apps are secure by design and by default by aligning them to current / best practice security policies and standards into the design phases. The individual must have a technical software / application development background with specalist experinece in secure architecture design. (Frameworks, processes, best practice etc) Practical experience translating and ensuring that the OWASP top 10, ISO27001, HMG frameworks requirements are reviewed and embedded into project designs which are implemented is essential. Experience working projects through a full development lifecycle is key. You will work along side the design and project teams to idenitfy and mitigate risks throughout the design phases. This is a permanent role. SC clearance is essential as is the ability to get to the London office. (When appropiate #covid) Security DevSecOps consultant. To arrange a discreet call book via https://calendly.com/chris-holt/devsecopp--security-design-review-consultant
- SPLUNK SOC Analyst level 3, London.
SPLUNK SOC Analyst level 3, Must be able to commute to the City of London. Onsite role. Security clearance needed. The SPLUNK SOC Analyst level 3 must have current experience working within a SOC environment with specific experience using a range of tools and techniques to investigate security incidents. Current experience with Splunk is essential. any additional experience Individuals with Elastic Security SIEM are highly desirable. Any of the following certifications are desirable Splunk Phantom certified admin, Splunk Core Certified Power User / Advanced, Splunk Certified Enterprise Security Admin, etc The role will include, but not be limited to working with sophisticated information security tools, investigating security incidents, incident management, technical escalation, process improvement, research into the latest threats, reporting etc The individual MUST currently be living in the UK and be able to achieve UK security clearance. (SC) This is a permanent role To arrange a call with Chris Holt https://calendly.com/chris-holt/arranged-call-with-chris-holt-elastic-siem-engineer-soc Chris.Holt@dclsearch.com
- ISO 27001 & Business Continuity Security Specialist, End User
- United Kingdom
CH7828 ISO 27001 & Business Continuity Security Specialist, End User, £70,000 United Kingdom ISO 27001 & Business Continuity Security Specialist needed to join a Cyber team within an end user. The ISO 27001 & Business Continuity Security Specialist will have end to end responsibility for the information security and Business Continuity management system. ISMS/BCMS. Both from an information security and technical security perspective working alongside the CISO. Experience must include, but not be limited to; a mix of Information Security standards, frameworks, audit principles, controls / policies and the management and use of the technical tooling to achieve compliance. ISO 22301, ISO 27001, NIST Cybersecurity Framework etc An ideal candidate will be working within an end user environment with a cyber consultancy background. Experience taking a company through accreditation is highly desirable Experience managing internal stakeholders, technical teams and external third parties essential Flexible working, very occasional travel to London office This is an exclusive role to DCL Search & Selection. Looking to interview immediately. https://calendly.com/chris-holt/iso-27001-business-continuity-security-specialis
- PCI- DSS Security Consultant, End User
PCI- DSS Security Consultant needed to join a Cyber team within an end user. The PCI- DSS Security Consultant will have end to end responsibility for PCI - DSS and its continuing certification. Both from an information security and technical security perspective working alongside the CISO. Experience must include, but not be limited to; a mix of Information Security standards, frameworks, audit principles, controls / policies and the management and use of the technical tooling to achieve compliance. PCI objectives / 12 key requirements, OWASP top 10, ISO 27001, NIST Cybersecurity Framework etc An ideal candidate will be working within an end user environment with a cyber consultancy background. PCI Cloud compliance, specifically someone with experience taking PCI-DSS from on premise into the cloud is HIGHLY desired. However, someone with Solid PCI experience with a strong technical background which include Cyber / Secure by design etc would be considered. Experience managing internal stakeholders and external third parties essential. Flexible working, but with the ability to get into London. This is an exclusive role to DCL Search & Selection. 1st stage interviews to happen the week of the 14th September Arrange a call with Chris on https://calendly.com/chris-holt/arrange-a-call-chris-dcl-pci-compliance