Cerber dominates ransomware attacks against businesses

Windows 10 Enterprise customers are able to use threat detection features to locate 'patient zero' machines

The Cerber family contributed to the largest number of ransomware attacks against enterprise systems in 2016, according to Microsoft research.

Of the myriad of ransomware attacks over the course of the year, Cerber accounted for 26% of these, some 2,114 infections on systems using Windows 10 Enterprise operating systems.

Cerber was found to be particularly active in November last year when attackers using the ransomeware strain ran a campaign against businesses taking advantage of the holiday season.

Microsoft has said that thanks to its robust threat protection, Windows 10 Enterprise is able to recognise Cerber attacks before payloads could be delivered, breaking the chain of self-replicating attacks that would normally compromise an entire system.

Advertisement - Article continues below
Advertisement - Article continues below

Through Windows Defender Advanced Threat Protection (Windows Defender ATP), a bundled service which is otherwise a paid extra, enterprise customers are able to locate 'patient zero' machines and stop a ransomware epidemic before it takes hold.

Cerber typically operates by tricking a user into downloading a document to their downloads folder from an email. Once the document is opened, an embedded macro is triggered which launches a PowerShell command, which then connects to a TOR anonymisation website to download a ransomware payload.

In an example test of a customer running the initial macro, Windows Defender ATP was able to identify the PowerShell command and track the source IP address from the TOR site and block it in a firewall.

"Windows Defender ATP generated at least four alerts during the infection process, providing a breadth of detections that helps ensure coverage for changing techniques between Cerber versions, samples, and infections instances," said Tommy Blizard, a researcher on the Windows Defender ATP team.

These alerts are built up using machine learning and extensive research of different ransomware instances and their related families, according to Microsoft.

With the upcoming Creators Update, Microsoft has promised to take "its capabilities one step further" by enabling the network isolation of any machines found to have issued this PowerShell command to receive payloads.

Advertisement - Article continues below

Ransomware families belonging to Genasom and Locky accounted for 14% and 11% of attacks respectively, while lesser-known variants Critroni and Troldesh made up just 6%. 

In August 2016, security research firm Malwarebytes revealed that over 40% of businesses across the UK, US and Canada had been targeted by ransomware, with a 259% increase in exploit kits in the first five months of the year.

Featured Resources

Digitally perfecting the supply chain

How new technologies are being leveraged to transform the manufacturing supply chain

Download now

Three keys to maximise application migration and modernisation success

Harness the benefits that modernised applications can offer

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

The 3 approaches of Breach and Attack Simulation technologies

A guide to the nuances of BAS, helping you stay one step ahead of cyber criminals

Download now



How can you protect your business from crypto-ransomware?

4 Nov 2019
operating systems

Windows PowerToys customisation project returns

10 May 2019
operating systems

How to factory reset Windows 10

26 Mar 2019
Microsoft Windows

The IT Pro Podcast: Farewell Windows 7

17 Jan 2020

Most Popular

public sector

UK gov launches £300,000 SEN EdTech initiative

22 Jan 2020
operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020
mergers and acquisitions

Xerox to nominate directors to HP's board – reports

22 Jan 2020
web browser

Microsoft developer declares it's time to ditch IE for Edge

23 Jan 2020