{"id":21523,"date":"2021-06-07T10:30:21","date_gmt":"2021-06-07T14:30:21","guid":{"rendered":"https:\/\/www.thundercloud.net\/infoave\/new\/?p=21523"},"modified":"2021-06-07T10:30:21","modified_gmt":"2021-06-07T14:30:21","slug":"how-emsisoft-protects-you-from-ransomware","status":"publish","type":"post","link":"https:\/\/www.thundercloud.net\/infoave\/new\/how-emsisoft-protects-you-from-ransomware\/","title":{"rendered":"How Emsisoft Protects You from Ransomware"},"content":{"rendered":"<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong><span style=\"font-family: helvetica, arial, sans-serif; font-size: 24pt;\">How Emsisoft Protects You from Ransomware<\/span><\/strong><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">We&#8217;ve been an Emsisoft partner for many years. And we&#8217;re proud to be affiliated with Emsisoft and the Emsisoft team.\u00a0 Emsisoft not only provides our members and customers with world-class malware, ransomware, and anti-virus protection, they also provide our mutual customers with friendly and timely support. In short, Emsisoft takes care of our mutual customers with Emsisoft Anti-Malware and with their great after-the-sale support. <\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Ransomware has been in the news a lot lately. The recent <a href=\"https:\/\/www.theverge.com\/2021\/6\/5\/22520297\/compromised-password-reportedly-allowed-hackers-colonial-pipeline-cyberattack\" target=\"_blank\" rel=\"noopener\">Colonial Pipeline ransomware attack<\/a> and the <a href=\"https:\/\/www.washingtonpost.com\/business\/2021\/06\/01\/jbs-cyberattack-meat-supply-chain\/\" target=\"_blank\" rel=\"noopener\">JBS attack<\/a> are two of the most notable.\u00a0<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">With permission from Emsisoft, we&#8217;re sharing the following Emsisoft Blog post (written by Jareth) with you. It details how Emsisoft protects you from ransomware.\u00a0 Thanks to Emsisoft for allowing us to share this article with you &#8211; and thank <strong>you<\/strong> for reading it!<\/span><\/p>\n<blockquote><p><strong><span style=\"font-family: helvetica, arial, sans-serif; font-size: 24pt;\">How Emsisoft prevents ransomware attacks<\/span><\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-21524\" src=\"https:\/\/www.thundercloud.net\/infoave\/new\/wp-content\/uploads\/2021\/06\/ransomware.png\" alt=\"\" width=\"544\" height=\"283\" srcset=\"https:\/\/www.thundercloud.net\/infoave\/new\/wp-content\/uploads\/2021\/06\/ransomware.png 544w, https:\/\/www.thundercloud.net\/infoave\/new\/wp-content\/uploads\/2021\/06\/ransomware-300x156.png 300w\" sizes=\"(max-width: 544px) 100vw, 544px\" \/><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Emsisoft is a global leader when it comes to combating ransomware. We\u2019re an Associate Partner of the\u00a0<a href=\"https:\/\/www.nomoreransom.org\/?utm_source=Emsisoft\" target=\"_blank\" rel=\"noopener\">No More Ransom Project<\/a>. We provide\u00a0<a href=\"https:\/\/www.emsisoft.com\/en\/ransomware-recovery-services\/\" target=\"_blank\" rel=\"noopener\">custom decryption services<\/a>\u00a0to help organizations impacted by ransomware minimize downtime. And our\u00a0<a href=\"https:\/\/www.emsisoft.com\/ransomware-decryption-tools\/\" target=\"_blank\" rel=\"noopener\">free decryptor tools<\/a>\u00a0have\u00a0saved ransomware victims hundreds of millions of dollars in ransom payments.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">We also recognize that stopping ransomware starts with protecting the user. That\u2019s why our protection solutions feature a range of ransomware-specific technologies that work in synergy to reliably detect ransomware\u00a0<em>before<\/em>\u00a0it can encrypt your files. This is particularly important now that backups are no longer the ransomware panacea they once were, thanks to the rise of\u00a0<a href=\"https:\/\/blog.emsisoft.com\/en\/38394\/what-is-extortionware\/\" target=\"_blank\" rel=\"noopener\">double extortion<\/a><\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">In this blog post, we\u2019ll explore Emsisoft\u2019s ransomware protection layers and how they work to protect our users from both known and unknown ransomware families.<\/span><\/p>\n<h3><span style=\"font-family: helvetica, arial, sans-serif; font-size: 18pt;\">1. Signature-based detection<\/span><\/h3>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">In the digital world, all objects have specific attributes that can be used to create a unique digital signature. When an object is identified as malicious, its signature is added to a database of known malware, which cybersecurity companies use to detect potential threats. When your Emsisoft protection solution comes across a file on your system with a signature that matches a known malicious signature, the file is flagged as a threat and blocked.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Our signature databases are constantly being updated to ensure our users are protected against emerging threats. Thanks to our intelligence-gathering networks and exclusive partnership with\u00a0<a href=\"https:\/\/id-ransomware.malwarehunterteam.com\/\" target=\"_blank\" rel=\"noopener\">ID Ransomware<\/a>, we\u2019re often among the first in the industry to provide signature-based detection for new ransomware variants.<\/span><\/p>\n<h3><span style=\"font-family: helvetica, arial, sans-serif; font-size: 18pt;\">2. Anti-Ransomware behavior-based detection<\/span><\/h3>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">While signature-based detection is excellent at stopping known ransomware, it is unable to detect new ransomware variants that have never before been seen in the wild (and therefore don\u2019t exist in any signature database).<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">This is where behavior-based detection comes in. Behavior-based detection, such as Emsisoft\u2019s Behavior Blocker, works by detecting unusual patterns of behavior and stopping suspicious programs before they can make any changes to your system. Our Behavior Blocker includes a dedicated Anti-Ransomware layer that looks for ransomware-specific behavior and stops threats before they can encrypt the first file. There are many actions or combinations of actions that could indicate the presence of ransomware, including the encryption of a large number of files, the dropping of ransom notes, attempts to\u00a0<a href=\"https:\/\/blog.emsisoft.com\/en\/34083\/how-to-protect-your-companys-backups-from-ransomware\/\" target=\"_blank\" rel=\"noopener\">encrypt or delete backups<\/a>\u00a0and more.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Because there are only a certain number of ways malware can behave, the Behavior Blocker can reliably detect almost any type of malware, even without receiving frequent online updates.<\/span><\/p>\n<h3><span style=\"font-family: helvetica, arial, sans-serif; font-size: 18pt;\">3. Exploit detection<\/span><\/h3>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">The ransomware attack chain often begins with the exploitation of security vulnerabilities in your operating system or software. After the initial compromise, bad actors typically\u00a0<a href=\"https:\/\/blog.emsisoft.com\/en\/36786\/how-ransomware-attackers-evade-your-organizations-security-solutions\/\" target=\"_blank\" rel=\"noopener\">deploy reconnaissance malware<\/a>\u00a0to learn more about the target environment, spread laterally and steal sensitive data before deploying the ransomware in the final phase of the attack.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Emsisoft\u2019s exploit detection systems interrupt the attack chain before bad actors can gain a stranglehold on your system. It achieves this by preventing exploits from injecting code into foreign programs to execute harmful payloads and reducing the attack surfaces of commonly targeted applications (e.g. preventing Microsoft Office from being able to execute dangerous PowerShell scripts). Exploit detection ensures that ransomware is detected and blocked in the early stages of the attack, regardless of the\u00a0<a href=\"https:\/\/blog.emsisoft.com\/en\/35083\/how-ransomware-spreads-9-most-common-infection-methods-and-how-to-stop-them\/\" target=\"_blank\" rel=\"noopener\">infection method<\/a>, be it email, RDP or unpatched vulnerabilities.<\/span><\/p>\n<h3><span style=\"font-family: helvetica, arial, sans-serif; font-size: 18pt;\">4. Password protection<\/span><\/h3>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Ransomware is typically deployed some days, weeks or even months after the\u00a0target system has been compromised.\u00a0Attackers use this\u00a0time\u00a0to\u00a0perform\u00a0reconnaissance, establish a stronger foothold\u00a0and prepare\u00a0the target environment to maximize the\u00a0impact\u00a0of the attack. Part of\u00a0this process involves disabling security processes, which ensures that the\u00a0ransomware will be able to operate undetected and unimpeded when it is finally deployed.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Emsisoft solutions feature an authentication system that prevents threat actors\u00a0from deactivating your antivirus software. Once an administrator password has been set, users will be prompted to enter the password any time they try to disable or configure our software.\u00a0In this way,\u00a0threat actors are unable to shut down our security software\u00a0\u2013\u00a0even if they\u2019ve\u00a0managed\u00a0to gain unauthorized access to your network.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">While admin passwords can be set locally on endpoints, we strongly recommend using the Emsisoft Management Console&#8230;<\/span><\/p>\n<h3><span style=\"font-family: helvetica, arial, sans-serif; font-size: 18pt;\">5. RDP attack alert\u00a0system<\/span><\/h3>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">RDP is one of the most common ransomware attack vectors. During an RDP-based attack, threat actors typically scan for Internet-exposed RDP ports and\u00a0attempt to gain access to the system using brute-force tools. Once the\u00a0account\u00a0has been\u00a0compromised, the attacker can do anything within the hacked account\u2019s privileges.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Emsisoft solutions help prevent RDP attackers by monitoring the RDP service in real-time. When multiple failed login attempts are detected, our\u00a0RDP attack alert system\u00a0notifies administrators, who can investigate and decide whether to disable RDP on the affected device. The RDP service status can be easily viewed within the Emsisoft Management Console.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">See this blog post for more information on\u00a0<a href=\"https:\/\/blog.emsisoft.com\/en\/36601\/how-to-secure-rdp-from-ransomware-attackers\/\" target=\"_blank\" rel=\"noopener\">how to secure RDP<\/a>.<\/span><\/p>\n<h3><span style=\"font-family: helvetica, arial, sans-serif; font-size: 18pt;\">Conclusion<\/span><\/h3>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Emsisoft solutions feature multiple layers of ransomware-specific technologies that work together to detect and stop ransomware before it can encrypt your files.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">It is important to note that this article only discusses Emsisoft\u2019s ransomware-specific technologies and does not include all of the other protection layers found in our software \u2013 many of which can also directly or indirectly reduce the risk of ransomware infection&#8230; <\/span><strong><span style=\"text-decoration: underline;\"><a href=\"https:\/\/thundercloud.net\/emsisoft\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Protect your device with Emsisoft Anti-Malware.<\/span><\/a><\/span><\/strong><\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; &nbsp; How Emsisoft Protects You from Ransomware We&#8217;ve been an Emsisoft partner for many years. And we&#8217;re proud to be affiliated with Emsisoft and the Emsisoft team.\u00a0 Emsisoft not only provides our members and customers with world-class malware, ransomware, and anti-virus protection, they also provide our mutual customers with friendly and timely support. In short, Emsisoft takes\u2026 <span class=\"read-more\"><a href=\"https:\/\/www.thundercloud.net\/infoave\/new\/how-emsisoft-protects-you-from-ransomware\/\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":13950,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1655,3389,1682,1656,1674],"tags":[],"_links":{"self":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/21523"}],"collection":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/comments?post=21523"}],"version-history":[{"count":6,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/21523\/revisions"}],"predecessor-version":[{"id":21530,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/21523\/revisions\/21530"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/media\/13950"}],"wp:attachment":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/media?parent=21523"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/categories?post=21523"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/tags?post=21523"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}