In this blog post, “Why Backups Alone Won’t Protect Your Business from Modern Ransomware,” we will examine why traditional backup strategies are not enough.
In a recent threat intelligence report, Microsoft unveiled how a few specific techniques and strategies can prevent the well-known Storm-2570 ransomware group from disrupting and breaching a business’s IT infrastructure.
The main focus behind the published technique is not to look at each ransomware attack as an isolated attack, but rather to look at it as an attack chain that uses multiple activities to infiltrate the infrastructure. These attacks can use credential access, security tampering, data exfiltration and lateral movement.
An important takeaway from the report is that even when a business is initially compromised, it’s not too late to harden and defend against the attack because every attack involves multiple steps, and in order for an intruder to gain access to a business, all steps need to work.
By disrupting an attack in the early stages, you can still prevent your business from being breached and valuable data from being compromised.
Storm-2570
The active player behind some of the latest sophisticated attacks is a group called Storm-2570, and it has compromised many organisations in the United States, Canada, the United Kingdom, Spain and many other countries.
The difference with Storm-2570 is that it is not a single ransomware operation. It has an entire ecosystem of threats that are deployed at different levels against an organisation using a sophisticated campaign.
Their strategy resembles an attack chain that uses well-known tools that allow the group to stage a pre-ransomware attack, then move in and breach a business operation.
How to Protect Your Business
When I work with clients, I take into account the latest threats, like Storm-2570, and work with clients on building and implementing a security strategy that includes credential hygiene and limits what elevated super users can do.
An important feature that I use with Microsoft Defender is tamper protection, which prevents attackers from stopping security services on breached endpoints.
That alone stops attackers from installing malware on a compromised machine and disabling antivirus exclusions.
When attackers can’t gain full admin access to a compromised machine, their blast radius is severely limited because they can’t move up the chain to fully gain access to critical components in the IT infrastructure.
In every Microsoft Defender implementation, we also enable and configure Defender XDR’s advanced capabilities, which reduce the blast radius of many attacks at their initial stages.
Get in touch
If your business or organisation is in need of a fresh security implementation that will protect you against cyber threats, please contact us for a free assessment.