MAZE Ransomware is a form of ransomware that poses a triple threat to your data security. With MAZE, hackers export your data to online storage sites in order to extort payment from you in bitcoins. Hackers at this point can impact all three aspects of data security: availability, confidentiality, and Integrity. Importantly, for companies that might normally restore their data from backup and refuse to pay any ransom, MAZE has already exported their data which will be released on the public Internet jeopardizing your data’s confidentiality.
CyberHoot predicts this will force many more companies to pay their ransom despite being able to restore their data’s availability from backups. Ransomware traditionally targets data availability by encrypting it and selling a decryption key back to you for a bitcoin ransom. Companies with deep pockets, but poor backups, can expect to pay tens to hundreds of thousands of dollars to get their “decryption key“. This traditional form of ransomware attack has been very successful for hackers, but the new strain of MAZE ransomware can change the game for hackers.
Additional Reading:
Related Terms: Ransomware
Yes. SMB’s absolutely should worry about MAZE ransomware. Hackers usually try the easiest path to compromising target companies. If they can find a VPN that isn’t set up for two-factor authentication, they’ll exploit this by finding an employee password on the dark web and simply log in and plant the MAZE ransomware in your environment. If that’s not possible, they’ll send convincing phishing attacks and entice users to click on the malware thereby accidentally installing it on your network.
CyberHoot’s has a detailed article addressing these MAZE Ransomware attacks.
Standard cybersecurity best practices will help your reduce your risks to MAZE and many other online threats. Take action now before its too late.
If you own a business, you need to be doing these things:
Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.
Stop tricking employees. Start training them. Take Control of Your Security Awareness Training with a Platform...
Read moreA recent discovery by cybersecurity firm Oligo Security has unveiled a series of critical vulnerabilities in...
Read moreGet sharper eyes on human risks, with the positive approach that beats traditional phish testing.