ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Kaspersky: Ransomware is key threat

Graeme Wearden in San Francisco ZDNet.co.uk

Published: 07 Feb 2007 10:56 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Online criminals are turning away from threatening companies with massive cyberattacks in favour of encrypting a victim's data and demanding money to release it, an antivirus expert claimed on Tuesday.

Eugene Kaspersky, head of antivirus research at Russia's Kaspersky Labs, told the RSA Conference in San Francisco that the use of so-called "ransomware Trojans" is a key trend for 2007.

This malware infects a PC, encrypts some data, and then displays an alert telling the victim to send money to get the decryption key needed to access their data again. Such malware isn't new. Early examples include Cryzip, discovered in March 2006, and GPCode, discovered in May 2005.

Cryzip and GPCode didn't cause massive damage, but Kaspersky believes that cybercriminals will refine their use of ransomware Trojans this year. The final version of GPCode used a 660-bit encryption key, which should have taken a single powerful PC around 30 years to crack, but was actually broken quickly by Kaspersky Labs, he said.

"We cracked it in 10 minutes, because this guy did not read the cryptographic book until the end," explained Kaspersky. "But if he does get to the end, antivirus vendors will not be able to decrypt and recover your data without help."

Kaspersky also told the conference that distributed denial of service (DDoS) attacks — where a company's servers are bombarded with data in an attempt to drive it offline — are declining. This is partly because better filtering technologies have been developed, which can strip out DDoS traffic before it reaches a corporate server. Another factor is the arrest of several people accused of extorting money from companies by launching a DDoS attack and demanding payment in exchange for stopping the attack.

"This is a dangerous kind of criminal activity, because the attack takes place before the money is transferred," said Kaspersky, explaining that victims of DDoS attacks have the opportunity to get the police involved before paying a ransom. One audience member pointed out that someone who falls victim to a ransomware Trojan could also get the the police involved. However, Kaspersky responded that the police might not be very interested, as the ransom might only be $20 or $30.

Several UK online betting firms, including Betfair, were targeted with DDoS attacks in the summer of 2004. Later that year, nine Russian citizens were arrested over their alleged involvement in the crimes, and three were later sentenced to eight years' imprisonment. However, the two suspected ringleaders are still at large.

Kaspersky is concerned that law enforcement is struggling to catch internet criminals. "In 2004 there were around 100 arrests of suspected cybercriminals. In 2005 there were around 400, but last year there were just 100. It seems that the stupid guys are being jailed, but the clever ones are still operating," he said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
22 out of 22 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Oracle 10g DBA -Northampton -40-50K+bens

The Senior Oracle 10g DBA/ Database Administrator will work within a team of system and Oracle DBA/ database administrators to oversee and support a ...

Junior VB.Net / ASP.Net Developer required for client in Bristol

You will be working on a range of software applications including a number of systems for the police. This does mean that you will go through a basic ...

URGENT! ASP.Net / VB application developer required in Bristol

The vast majority of their business is for the UK police forces. That means you will have to under go police vetting to work for this company. Huxley ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation