SpinSafe
  • Cloud Backup Solutions
  • Torrents
    • Are Torrent Websites Safe?
    • How to Torrent
    • Popular Torrent Website List
  • Best VPN
  • Security Alerts
    • National Cyber Alerts
    • NIST
  • How To
    • Secure Your Wireless Network
    • Home Network Security
  • News
    • Active Threat Alerts
    • Computer Security News
    • Internet Security News
    • Mobile Security News
    • Tech Video News
  • Search
  • Menu Menu
  • Twitter
  • Rss

A Rookie Mistake Shows Hackers Aren’t All Geniuses

June 20, 2022/in Computer Security


Placeholder while article actions load

For more than two decades, ransomware attacks have been the bane of corporate IT managers and their CEOs, and a source of much research for cybersecurity professionals. An underground market for hacking and encryption tools has helped such incursions proliferate, but thankfully a recent case shows what we can learn when attackers don’t know what they’re doing. 

Unlike other cyber nuisances, such as viruses, which replicate and cause mayhem, or denial of service attacks, which bring networks to a grinding halt, ransomware is almost impossible to unwind once it’s been deployed successfully. That’s because they use encryption to lock up the files, with a secret decryption key being the only route out. 

Rather than try to undo this encryption, most victims just write off the files and restore their systems using backups. This can take days or weeks, assuming the target has good data practices, while still costing millions of dollars. It may be impossible if secure backups don’t exist. And that’s what ransomware attackers are betting on: the losses from restoring systems are so high that a target is willing to pay to get a copy of the digital key, which can decrypt the files and restore everything to normal. 

But what hackers don’t bet on is savvy cybersecurity professionals coming across rookie mistakes in the malware code that lets them reverse the encryption without paying a dime to the assailant.

A group at International Business Machines Corp.’s X-Force team did just that. Taipei-based CyCraft Corp. also managed to find the flaws and offered decryption tools for free.

In an article on IBM’s Security Intelligence website, and a recent presentation at the RSA Security Conference, the researchers outlined how they spotted an error within the code of the Thanos family of ransomware. Prometheus, a variant of Thanos, is believed to have struck at least 30 victims in industries including manufacturing, logistics and finance.

It all centers around randomness. This quality is one of the most important aspects of good encryption because encryption-decryption keys — they usually come as a mathematically linked pair — rely…

Source…

Share this entry
  • Share on Facebook
  • Share on Twitter
  • Share on WhatsApp
  • Share on Pinterest
  • Share on Tumblr
  • Share on Reddit
https://spinsafe.com/wp-content/uploads/2022/06/twp-social-share.png 779 1484 SecureTech https://spinsafe.com/wp-content/uploads/2016/11/spinsafelogo-1.png SecureTech2022-06-20 03:00:152022-06-20 03:00:15A Rookie Mistake Shows Hackers Aren’t All Geniuses

Archives

© 2022 SpinSafe
SpinSafe may be compensated by providing links to products, services, websites, and various other options.
  • Twitter
  • Rss
  • Privacy Policy
  • Terms of Service
The United States forcibly demolished Huawei and ZTE, and the price was too...“Unpatchable” hardware flaw. Nation-state conflict in cyberspace....
Scroll to top