This isn’t the first time there’s been a reason to panic about ransomware. Years ago, when the threats first emerged, every business or government entity that stored sensitive information went into full panic mode. Since then, security experts have implemented improved safeguards against this ransomware. A new type of ransomware has emerged, and old or outdated forms of protection won’t help anyone.
Nemty, the emerging ransomware, can easily overtake many unprotected systems. It’s still in the development stages and is currently being fortified. With time, it will only become stronger and more efficient. Get worried now, before it’s too late.
What is Nemty?
Nemty is a ransomware that utilizes overkill encryption to lock users out of their systems. It’s smart enough to unencrypt most encrypted data, even without access to the entire keyset. This puts sensitive data in the hands of hackers who can easily exploit it, and can potentially destroy businesses or entities that retain sensitive information.
Once Nemty has access, it locks users out of their system and demands an equivalent of $1,000 in Bitcoin for the release of the ransom. Even if the ransom is paid and the data is returned, everything is still compromised. Things like social security numbers and credit card numbers could have easily been stolen in the interim, making the ransom the least of your worries.
Who is it Affecting?
As of publishing, no major corporations have come forward and admitted to being on the receiving end of Nemty. This ransomware is powerful and ominous, even in its infancy. Experts agree that it’s ready to deploy just based on small traces that have been discovered across the internet. It’s likely that the developers of the ransomware will first target lower level individuals to fortify their malicious code and prepare for a larger attack.
Right now, anyone can be the next target of Nemty. Hackers and thieves don’t generally announce what they plan to do or why they’re creating something malicious. The fear comes in not knowing what the main purpose or the end goal of Nemty may be. Unless and until its developers launch an actual large scale attack, we won’t know who is most vulnerable. Don’t find yourself on the receiving end of that attack.
Protecting Against Nemty
Nemty can easily be downloaded by unwitting employees. It will masquerade as something innocuous and spread through the entire system. It can also be deliberately placed by a hacker who obtains someone else’s credentials, someone with shared credentials, or someone using a network that isn’t secured by a VPN.
Start by making multifactor authentication mandatory. Doing so would leave less room for error. This makes it harder for someone without necessary access permissions to enter a system using someone else’s credentials, as they would need to be verified at least one more time beyond the entry of a password.
Never share credentials for access to client networks. Diversity of information and privacy makes it more difficult for information to get into the wrong hands. Eliminating the use of shared credentials altogether will also make it easier to monitor who is accessing what and when they’re accessing it.
Update your operating system immediately when prompted to do so as this often patches severe security vulnerabilities that have not yet been released to the public.
Do not download unknown attachments or click hyper links from someone you don’t know. Even if an email was made to look like an actual vendor you work with, if it doesn’t look right don’t click. Instead, copy paste the link in an online web trace tool and see if the sender is trying to mislead you.
Lastly, but most importantly, make VPN connections mandatory. Make employees utilize a VPN to access any system containing sensitive information by whitelisting a dedicated IP address for teams or employees that require access to that information. If no one really needs to access that information at all, store it securely offline.
Get a VPN Right Now
While there is no substitute for being vigilant against clicking random email links and frequently updating your operating system, a VPN should be party of your security shield. Internet privacy and protection against attacks of all kinds, including ransomware, starts with a VPN. Using a VPN is a simple and commonplace practice that has the potential to save your business as TorGuard blocks advertisements and known malware networks. No one can compromise your network if no one can get in. TorGuard provides VPN solutions for enterprises of all sizes, including stealth VPN services.