Ransomware totally dominated FireEye’s malware detections in March

Security firm FireEye says that ransomware variants made up over 70 percent of all malware that its products detected in March.

In October last year ransomware made up well under five percent of malware that FireEye detected, and since then ransomware has climbed steadily as a proportion of overall malware its product installations detect.

Ransomware only breached 10 percent in February 2016, however in March ransomware detections spiked, exceeding 70 percent of the total, according to FireEye.

The rise coincides with numerous security firms detecting a surge in Locky ransomware, which was being spread in March via downloaders embedded in spam email attachments. The attachments purported to contain an invoice or image and later included ZIP files. One of the key methods of infecting targets in the Locky campaign was to trick targets into enabling macros for Office documents.

Microsoft on Tuesday published its analysis of how a downloader, designed to fetch Locky ransomware, was hidden inside seven Visual Basic for Applications (VBA) modules in a Word document. Microsoft said it was part of a JavaScript macro-based malware family that’s been active for several years, but has highlighted the case a sneaky use of VBA modules to install the Locky ransomware.

The VBA modules appeared to be legitimate SQL programs, however Microsoft found that a macro in one of the seven modules was designed to decrypt an encrypted string in another module. Once decrypted, that string turned out to be a URL, from where it would download Locky.

“The VBA project (and, therefore, the macro) will automatically run if the user enables macros when opening the file,” noted Microsoft threat researchers Marianne Mallen and Wei Li.

“Our strongest suggestion for the prevention of Office-targeting macro-based malware is to only enable macros if you wrote the macro yourself, or completely trust and know the person who wrote it,” they added.

FireEye’s new warning about the surge in ransomware follows an alert from the FBI in April over file-encrypting ransomware. The FBI didn’t offer any statistics but said it had received reports of ransomware affecting home PCs, hospitals, school districts, state and local governments, law enforcement agencies, small businesses, and large businesses.

Countering reports that the FBI had suggested paying ransomware demands, the bureau stressed that it does not support paying the ransom since paying up does not guarantee receipt of the decryption key, and encourages ransomware attackers.

Regardless of the FBI’s advice, it was widely reported in February that Hollywood Presbyterian Medical Centre paid around $17,000 in Bitcoin after some computers on its network were infected with file-encrypting ransomware.

The hospital’s CEO said paying to obtain the decryption key was the “most efficient way to restore our systems and administrative functions”.

Lucky however was not the most prevalent piece of ransomware in the first quarter of 2016, according to security firm Kaspersky. According to it, in that period Teslacrypt was the most widely encountered by Kaspersky installations, followed by CTB-Locker, Cryptowall, Cryakl, Scatter, and Rakhni. Locky was in seventh spot. Still, as Kaspersky highlighted, Locky was the “biggest crypto epidemic” in the first quarter of 2016, due to how widely it had been spread across different countries.

FireEye reported in March that it detected Locky infection attempts among its users in 50 nations.

Join the CSO newsletter!

Error: Please check your email address.

Tags telascriptFireEyeCryptoWallmalwareVBAZIP filesmacro malwareMicrosoftCTB LockerkasperskySQL ProgramsfbiRakhnijavascriptransomwareBitcoinCryakl

More about FBIFireEyeKasperskyMicrosoft

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Liam Tung

Latest Videos

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

  • 150x50

    IDG Live Webinar:The right collaboration strategy will help your business take flight

    Speakers - Mike Harris, Engineering Services Manager, Jetstar - Christopher Johnson, IT Director APAC, 20th Century Fox - Brent Maxwell, Director of Information Systems, THE ICONIC - IDG MC/Moderator Anthony Caruana

    Play Video

More videos

Blog Posts