Connect with us

Hi, what are you looking for?

HEADLINES

Attackers increasingly encrypting files out of sight

At the end of 2023, Sophos X-Ops noted a significant increase in ‘remote encryption’ attacks – where ransomware attackers breach a compromised and often under protected endpoint to encrypt data on other devices connected to the same network. 

Ransomware is one of the most significant threats facing organizations today. Battling it is no easy task, particularly given that threat actors are continually refining their techniques and approaches.

At the end of 2023, Sophos X-Ops noted a significant increase in ‘remote encryption’ attacks – where ransomware attackers breach a compromised and often under protected endpoint to encrypt data on other devices connected to the same network. 

This trend has only accelerated, with Sophos X-Ops now reporting a 50% year-over-year increase in remote ransomware attacks in 2024. That represents a 141% rise since 2022, underscoring the prevalence of this threat.

Remote encryption was relatively low throughout 2022 and the first half of 2023, but it increased significantly in the latter half of 2023. Since then, it’s remained at relatively high levels (albeit with some ups and downs).

Rising Trend of Remote Ransomware

Advertisement. Scroll to continue reading.

While remote encryption is not new, it has become increasingly common among modern ransomware groups since it can bypass many endpoint security products. That’s because the files are encrypted out of view of defensive capabilities, such as memory scanning and behavior monitoring.

Microsoft’s 2023 Digital Defense Report, observed that around 60% of human-operated ransomware attacks involved remote encryption, with 80% of all compromises originating from unmanaged devices. In its 2024 report, Microsoft also found that 70% of successful attacks involved remote encryption.

Chester Wisniewski, director and global field CISO at Sophos, said, “Remote encryption has now become a standard part of ransomware groups’ bag of tricks. Every organization has blind spots and ransomware criminals are quick to exploit weaknesses once discovered.  Businesses need to be hypervigilant in ensuring visibility across their entire estate and actively monitor any suspicious file activity.”

What to Do to Stay Protected 

To stay secure against remote ransomware, Sophos recommends the following:

Advertisement. Scroll to continue reading.
  • Practice active asset management – Regularly track all devices and endpoints to identify vulnerabilities and unauthorized access
  • Identify unmanaged machines – Continuously scan for rogue devices that could serve as entry points for attacks
  • Use security solutions that monitor file activity – Implement tools to track file movements and transfers in real time to detect suspicious behavior
  • Practice good cybersecurity hygiene – Enforce strong passwords, regular updates, multi-factor authentication, and employee training to reduce risks
Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

Maya has already integrated National ID eVerify, the Philippine Statistics Authority’s identity-verification service, into its onboarding process. Since early this year, eligible customers have been...

HEADLINES

In 2025 alone, Converge denied nearly 12 billion entry requests to websites hosting dangerous, inappropriate, and harmful content that attempted to pass through its...

HEADLINES

The announcement represents one of the first major third-party technology integrations following the launch of Sophos Fusion, demonstrating Sophos' commitment to an open ecosystem...

HEADLINES

APAC consumers are more concerned about digital tech usage for crime than consumers globally (35% vs 32%). The awareness is highest in Thailand (39%),...

HEADLINES

Through this partnership, Sophos intends to give partners a new way to deliver frontier AI security as one connected defense system, and to build...

HEADLINES

“It is the time for Radenta to demonstrate that it is strongly committed to protecting client data,” remarks Nereo Bolante, Co-Director, Radenta Ethics, Compliance, and Governance Team...

HEADLINES

Attackers are operationalizing artificial intelligence (AI) to collapse attack workflows from weeks to days. The report finds that AI’s most immediate impact on cybercrime...

HEADLINES

The prominence of identity attacks in ransomware indicates a shift in method, as attackers increasingly recognize identity as a key component in ransomware delivery....

Advertisement