A ransomware campaign launched on September 18th, 2017 features a new phishing technique that tricks users into opening what looks like a scanned document from an internal printer. This new phishing technique delivers ransomware that experts at Comodo Threat Research Lab have dubbed “IKARUS”. However, don’t let the new name fool you, IKARUS is the third generation of already wide-spread Locky ransomware. The key is that this variant of Locky works through an email attachment. The hacker will send an email to a user disguised as a printer output which contains a script inside an archived file. This alone may not be enough to register the malicious email as a phishing attempt. In fact, this new delivery channel will bypass some of the defensive/technical controls that businesses currently have in place, making it extremely hard to catch before a user has been exploited.
This story is another example of the ongoing war between offensive and defensive cyber tactics. Defensive techniques for the first two versions of Locky had been developed and dispersed, so a new attack method has been adopted. This is an important thought to keep in mind and re-emphasizes the importance of training employees to have security awareness. A technical control may not recognize that a user did not scan a document from an internal printer, but a user would know that. Therefore, it is important that end users are trained to recognize abnormal activity and respond accordingly.
For more information about the Locky ransomware or to speak with a GraVoc employee about the security of your business, contact us below.
On May 8th, 2018 GraVoc’s Nate Gravel and Michael Kannan will be presenting at the Great New England Credit Union Show taking place at DCU Center in Worcester.read more
The Internal Revenue Service is warning taxpayers of an unusual phishing scheme that is going around this tax season. Using stolen data obtained by tax professionals, criminals are filing fraudulent tax returns and depositing them into actual taxpayers’ bank accounts.read more
The United States Securities and Exchange Commission (SEC) has revised and released cybersecurity guidance for publicly traded companies.read more