ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

SME Toolkit

Watch out — your data may be kidnapped

Tom Espiner ZDNet.co.uk

Published: 24 Jul 2006 17:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Small and medium-sized companies are being advised to back up data if they want to avoid the risk of ransomware — the use of malicious code to hijack user files, encrypt them and then demand payment in exchange for the decryption key.

Security specialist Kaspersky Labs on Monday warned that the encryption algorithms used by cybercriminals are becoming increasingly complicated, foxing antivirus companies.

"There's a potential situation where antivirus companies won't be able to decrypt the files," said David Emm, senior technology consultant at Kaspersky UK. "Within a corporation, the IT department normally backs up files. The danger is where attacks are launched at smaller businesses [without IT departments] and individuals."

Trojan horse programs can be sent out as spam or hidden on malicious sites. Once a machine is infected, files are either encrypted individually or grouped together and locked in a password-encrypted folder.

Strong algorithms such as RSA public key encryption, one of the most popular technologies, are increasingly being used by criminals to foil the decryption techniques used by antivirus companies. Since January, Kaspersky has seen an increase in the strength, from 56 to 660bit keys, of the encryption being used by hackers to lock files. "Virus writers' attitude to date is that encryption only needs to be strong enough. It's alarming that we're now getting onto the level of serious encryption," said Emm.

Kaspersky claims to have seen an increase in the amount of ransomware, but says it has not seen an epidemic."It seems to have been escalating, but it's just one weapon within their arsenal," said Emm.

Antivirus vendor Sophos said that businesses should not have a problem with ransomware, as their files will have been backed up.

"If your data is backed up, you can recover," said Graham Cluley, senior technology consultant for Sophos.

For Sophos, a bigger problem is "filenapping". Once a machine is infected, all files and information are copied and wiped from the original system. A victim must then pay a ransom to recoup their filenapped data.

Sophos said it was not seeing "a tidal wave of activity", but confirmed that encyption algorithms used are getting more sophisticated.

Last month Greater Manchester Police decided not to pursue the criminals who used a Trojan horse program called Archiveus to lock a Rochdale woman's files and demand a ransom to release them.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
130 out of 232 people found this useful



Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Visual C++ Developer MFC OOP Multithreaded Algorithms

Huxley Associates has an exciting new opportunity for a Software engineer to join our client for a 6-month contract in the Thames Valley. We are ...

C++ Software Engineer, Dream Developer Job, Algorithms, Bristol

If you are an experienced Algorithm designer with Strong C++ skills, send me your CV. This is an interesting project and a technically challenging ...

NHS Safeboot (encryption) Consultant

Are you an experienced user of SafeBoot management Center? Have you used it within the NHS Connecting for Health Project? If your answers to the ...

Vista Upgrade Blog

The game's up for Vista

I got an interesting invite last night to the media launch of a dedicated gaming centre housed in an HMV store in central London. Resplendent with around 80 Quad core PCs and Dual... More

1 comment

Windows Driver Updates

Because of my recent adventures with Windows Vista on my Lifebook, I've had to learn about and deal with the differences between Vista and XP in third-party device driver distribution... More

2 comments

Windows XP SP3 Installed

I have downloaded and installed Service Pack 3 for Windows XP Professional on my Fujitsu Lifebook S6510. Everything went smoothly, and it seems to work just fine. I don't see anything... More

Post a comment

Discussions

Tezzer Tezzer

Telescopic oversight

Saturday 17 May 2008, 1:21 PM

4 comments
61320 61320

Bletchley Park

Saturday 17 May 2008, 9:28 AM

5 comments