The Computer Incident Response Center Luxembourg (CIRCL) has issued a warning against a crypto ransomware campaign that has been on the rise in Luxembourg the past weeks, impacting companies from different industries.
This growing threat affects both Internet users and corporate networks users. The attackers have developed a meticulous and advanced method: they infect a system in order to encrypt all available files locally and remotely for the user. When the encryption is completed, users will not be able to access their files anymore and attackers will ransom them to allow the recovery of these encrypted files.
“We have seen that these attacks have been highly successful and in Luxembourg a number of companies have been impacted. Knowing that within corporate networks, file servers are extensively used, it is a perfect channel and platform for attackers”, explained Alexandre Dulaunoy from CIRCL.
On the same issue, CIRCL previously published a warning in August 2012 regarding the ransomware method with the TR09, and the TR33 in February 2015, analysing the CTB-Locker/Critroni infection.
A number of proactive measures can be taken in order to lessen the impact and the risks associated to a Crypto Ransomware infection. The best defense against Crypto Ransomware are functional backups. In addition, CIRCL has published a list of incident responses companies should/could carry when faced with a Crypto Ransomware infection. For details, see www.circl.lu.