Cerber dominates ransomware attacks against businesses

Windows 10 Enterprise customers are able to use threat detection features to locate 'patient zero' machines

The Cerber family contributed to the largest number of ransomware attacks against enterprise systems in 2016, according to Microsoft research.

Of the myriad of ransomware attacks over the course of the year, Cerber accounted for 26% of these, some 2,114 infections on systems using Windows 10 Enterprise operating systems.

Cerber was found to be particularly active in November last year when attackers using the ransomeware strain ran a campaign against businesses taking advantage of the holiday season.

Advertisement - Article continues below

Microsoft has said that thanks to its robust threat protection, Windows 10 Enterprise is able to recognise Cerber attacks before payloads could be delivered, breaking the chain of self-replicating attacks that would normally compromise an entire system.

Through Windows Defender Advanced Threat Protection (Windows Defender ATP), a bundled service which is otherwise a paid extra, enterprise customers are able to locate 'patient zero' machines and stop a ransomware epidemic before it takes hold.

Cerber typically operates by tricking a user into downloading a document to their downloads folder from an email. Once the document is opened, an embedded macro is triggered which launches a PowerShell command, which then connects to a TOR anonymisation website to download a ransomware payload.

In an example test of a customer running the initial macro, Windows Defender ATP was able to identify the PowerShell command and track the source IP address from the TOR site and block it in a firewall.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

"Windows Defender ATP generated at least four alerts during the infection process, providing a breadth of detections that helps ensure coverage for changing techniques between Cerber versions, samples, and infections instances," said Tommy Blizard, a researcher on the Windows Defender ATP team.

These alerts are built up using machine learning and extensive research of different ransomware instances and their related families, according to Microsoft.

With the upcoming Creators Update, Microsoft has promised to take "its capabilities one step further" by enabling the network isolation of any machines found to have issued this PowerShell command to receive payloads.

Ransomware families belonging to Genasom and Locky accounted for 14% and 11% of attacks respectively, while lesser-known variants Critroni and Troldesh made up just 6%. 

In August 2016, security research firm Malwarebytes revealed that over 40% of businesses across the UK, US and Canada had been targeted by ransomware, with a 259% increase in exploit kits in the first five months of the year.

Featured Resources

Staying ahead of the game in the world of data

Create successful marketing campaigns by understanding your customers better

Download now

Remote working 2020: Advantages and challenges

Discover how to overcome remote working challenges

Download now

Keep your data available with snapshot technology

Synology’s solution to your data protection problem

Download now

After the lockdown - reinventing the way your business works

Your guide to ensuring business continuity, no matter the crisis

Download now
Advertisement

Recommended

How to factory reset Windows 10
operating systems

How to factory reset Windows 10

4 Mar 2020
How can you protect your business from crypto-ransomware?
Security

How can you protect your business from crypto-ransomware?

4 Nov 2019
How to move Windows 10 from your old hard drive to SSD
operating systems

How to move Windows 10 from your old hard drive to SSD

3 Aug 2020
How to boot Windows 10 in Safe Mode
Software

How to boot Windows 10 in Safe Mode

27 Jul 2020

Most Popular

How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

3 Aug 2020
How to use Chromecast without Wi-Fi
Mobile

How to use Chromecast without Wi-Fi

4 Aug 2020
UN report points to a 350% rise in phishing websites at start of 2020
phishing

UN report points to a 350% rise in phishing websites at start of 2020

7 Aug 2020