{"id":34306,"date":"2019-01-31T19:45:22","date_gmt":"2019-01-31T11:45:22","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=34306"},"modified":"2019-01-31T19:45:27","modified_gmt":"2019-01-31T11:45:27","slug":"sophos-releases-report-on-matrix-ransomware","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2019\/01\/31\/sophos-releases-report-on-matrix-ransomware\/","title":{"rendered":"Sophos releases report on Matrix ransomware"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><a rel=\"noreferrer noopener\" href=\"http:\/\/www.sophos.com\/\" target=\"_blank\"><strong>Sophos<\/strong><\/a><strong>,\u00a0a player in network and endpoint security, released a new report about a ransomware family called Matrix. The malware has been operating since 2016 and Sophos has tracked 96 samples in the wild. Like previous targeted ransomware, including BitPaymer, Dharma and SamSam, the attackers who are infecting computers with Matrix have been breaking in to enterprise networks and infecting those computers over\u00a0Remote Desktop Protocol (RDP), a built-in remote access tool for Windows computers. However, unlike these other ransomware families, Matrix only targets a single machine on the network, rather than spreading widely through an organization.\u00a0 <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In its\nlatest&nbsp;paper, SophosLabs reverse engineered the evolving code and\ntechniques employed by the attackers, as well as the methods and ransom notes\nused to attempt to extract money from victims. The Matrix criminals evolved\ntheir attack parameters over time, with new files and scripts added to deploy\ndifferent tasks and payloads onto the network.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Matrix ransom\nnotes are embedded in the attack code, but victims don&#8217;t know how much they\nmust pay until they contact the attackers.&nbsp;For most of Matrix&#8217;s existence, the authors used a\ncryptographically-protected anonymous instant messaging service, called&nbsp;<strong><a href=\"http:\/\/bitmsg.me\/\" target=\"_blank\" rel=\"noreferrer noopener\">bitmsg.me<\/a><\/strong>, but that service has now been\ndiscontinued and the authors have reverted to using normal email\naccounts.&nbsp;The threat actors behind Matrix make their\ndemand for cryptocurrency ransom in the form of a U.S. dollar value equivalent.\nThis is unusual as demands for cryptocurrency normally come as a specific value\nin cryptocurrency, not the dollar equivalent. It&#8217;s unclear whether the ransom\ndemand is a deliberate attempt at misdirection, or just an attempt to surf\nwildly fluctuating cryptocurrency exchange rates.&nbsp;Based on the communications\nSophosLabs had with the attackers, ransom demands were for US$2,500, but the\nattackers eventually reduced the ransom when researchers stopped responding to\ndemands.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Matrix is\nvery much the Swiss Army Knife of the ransomware world, with newer variants\nable to scan and find potential computer victims once inserted into the\nnetwork. While sample volumes are small,&nbsp;that doesn&#8217;t make it any less\ndangerous; Matrix is evolving and newer versions are appearing as the attacker\nare improving on lessons learned from each attack.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a rel=\"noreferrer noopener\" href=\"https:\/\/www.sophos.com\/en-us\/medialibrary\/pdfs\/technical-papers\/sophoslabs-2019-threat-report.pdf\" target=\"_blank\">Sophos\u2019 2019 Threat Report<\/a> highlighted that targeted ransomware will be driving hacker behavior, and organizations need to remain vigilant and work to ensure they are not an easy target.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Sophos\nrecommends implementing the following four security measures immediately:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Restrict access to remote control applications such as Remote Desktop\n(RDP) and VNC<\/li><li>Complete, regular vulnerability scans and penetration tests across the\nnetwork; if you haven\u2019t followed through on recent pen-testing reports, do it\nnow. If you don\u2019t heed the advice of your\npentesters, the cybercriminals will win<\/li><li>Multi-factor\nauthentication for sensitive internal systems, even for employees on the LAN or\nVPN<\/li><li>Create back-ups that are offline and offsite, and develop a disaster\nrecovery plan that covers the restoration of data and systems for whole organizations,\nall at once<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Like previous targeted ransomware, including BitPaymer, Dharma and SamSam, the attackers who are infecting computers with Matrix have been breaking in to enterprise networks and infecting those computers over Remote Desktop Protocol (RDP), a built-in remote access tool for Windows computers.<\/p>\n","protected":false},"author":6,"featured_media":32439,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,25],"tags":[103,206],"class_list":["post-34306","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-software","tag-malware","tag-sophos"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/34306","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=34306"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/34306\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/32439"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=34306"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=34306"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=34306"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}