What Recent Ransomware Attacks Can Teach Hospital IT Teams
Aside from the ordinary data breach, hospitals are falling victim (at an alarming rate) to a relatively new type of threat: ransomware.
2 min read
Craig Badrick is President and CEO of Turn-key Technologies, Inc., bringing extensive experience in wireless communications and IT infrastructure across education, healthcare, enterprise, government, and hospitality environments. His expertise includes Wi-Fi and wireless networking, voice over Wi-Fi, wireless telephony, paging, emergency communications, network optimization, load balancing, backup systems, message archiving, data protection, firewalls, and spam filtering. Craig also brings deep ...
Craig Badrick
Updated on
January 25, 2017
A decade or two ago, the hacking community consisted mostly of a bunch of bored teenagers, with scant few high-level hackers capable of penetrating enterprise-grade security. For every Kevin Poulsen, you would find thousands of pimple-faced high school juniors hiding in their parents' basements killing time until their application to MIT got accepted. That is no longer the case. Even the unfunded amateur hackers today can get access to sophisticated hacking tools for relatively little money on the Dark Web. That speaks nothing of the well-funded, highly-motivated, surprisingly sophisticated attackers backed by international organizations -- sometimes even government entities -- who are paid big bucks to attack your enterprise, steal the data, corrupt your databases, and generally wreak havoc on your business. Hence, the phenomenon of ransomware, which can now be carried out using a very common and seemingly harmless JavaScript framework. Here's how it works.
Ransomware is malware that is specifically designed to hijack a computer system or data store and hold it hostage (inaccessible and un-retrievable to the users) until they pay a ransom. The ransom demanded can soar upwards of tens of thousands of dollars, though for smaller businesses it is often only a few hundred or thousand dollars. The ransom is usually demanded to be paid in bitcoins, a popular cryptocurrency. If the ransom isn't paid, the hacker might release sensitive data about your organization on the Internet, corrupt your databases so the data is useless, or make off with your customer information (which customers aren't usually thrilled about). Ransomware not only damages the company monetarily through loss of revenue during the attack and the cost of the ransom, it also damages their corporate reputation, runs up extraordinary legal bills, and is a PR nightmare of the highest magnitude.
JavaScript has long been associated with security risks, so it's usually used to run code in a sandbox environment, meaning it is unable to access or compromise the underlying operating system or applications on the users' machines. It's used to develop Web-based routines, and can be found on many, many websites that your users access on any given day.
The malware behind ransomware encrypts the data, so that it is inaccessible to the user. Unless they pay up, the data is released publicly, deleted, or corrupted so that it is unusable.
Web developers have constructed a new JavaScript framework called NW.js, which was built to give developers more control and interactivity with the users' machines. This framework has as much access to the user's operating system as C++ code does, and to ordinary antivirus and antimalware software it looks just like any old Windows or Mac code, so it goes undetected by most security software, firewalls, etc.
Using the NW.js framework, hackers have developed a Ransomware-as-a-Service called Ransom32. That means that anyone who is willing to get their hands on the code via Torrent and the Dark Web can use this JavaScript framework to infect your users' systems with ransomware. It's just one of the many high-level tools available to today's wanna-be hackers.
Here's your plan for keeping Ransom32 and other nefarious code out of your systems and network:
Have questions about your IT environment? Tell us what you're working on and our team will help you identify the right next step.
Aside from the ordinary data breach, hospitals are falling victim (at an alarming rate) to a relatively new type of threat: ransomware.
A network site survey will assess your vulnerabilities and identify where you need to make changes.
It is now time for Mac users to begin using the same network security protective as Ransomware hits OSX