The Future of Malware is Here

Until now, malware has generally been more of a nuissance than a serious issue. Avoidance was generally possible, and those that did slip through security software and cautious surfing practices could easily be removed or dealt with. Now a new breed of malware (I really hate the terminology people use for all the different types of malicious software out there, so malware is what I will use) has been spotted in the wild. Instead of just trying to get you to purchase some kind of scam antivirus software as has been the trend lately, this new malware encrypts your files (files ending in .psd, .doc, etc) and then requires you to pay them for the software to decrypt your own data.

This means several things for typical users:

  • No longer is a malware infection something that can be repaired. A restore will return your machine to working order, but anything you have saved on the computer is lost regardless.
  • A good backup solution is even more imperative. Now it is not just hardware failure that you risk without having a backup, you risk losing access to your data.
  • Automated data backup services are dangerous. If your data is automatically backed up to some location you could potentially backup these newly encrypted files. Incrimental backups will be safe as you can just choose an older version, but backing up manually to DVD or an external drive is the best option.

Fortunately this first wave of encryption has been cracked, and for the crack and more information see the original article on fireeye here.

Thanks Eric, for pointing me to this article. See Eric’s blog here. (I know it’s empty, he just hasn’t written anything to it yet)

Tags: , , ,

This entry was posted on Friday, March 27th, 2009 at 10:31 pm and is filed under Computers, Security. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Reply




XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>