12 Points Technologies
  • Managed Services
    • IT Support
      • Managed Support Services
      • Data Backup and Disaster Recovery
      • Managed Network and Infrastructure
      • Co-Managed IT
    • Cloud
      • Cloud Migration
      • Private Cloud Hosting
  • Security
    • Cybersecurity
      • Advanced Threat Protection
      • Security Assessment
      • Vulnerability Management
      • Incident Detection & Response
      • Network Monitoring
    • Physical Security
      • Access Control
      • Visual Security
  • VoIP / Webex
    • Webex Cloud Solutions
    • Unified Communications
    • Business Phone Systems
  • About Us
    • Leadership Team
    • Blog
    • Partners
    • Customer Referral
    • Careers
  • Contact Us
  • GET A QUOTE
  • Menu Menu

Anatomy of a Breach: What Happens Behind the Scenes of a Ransomware Attack

As a business owner, there are probably not many more frightening things you can hear than, “We have a virus” or “We’ve experienced a breach”. Immediately, you start thinking the worst. Will all our systems go down? How will we recover? How much information was exposed?

Of course, this is quickly followed up with “How did this happen? Why didn’t my antivirus catch it? How did it make it through the firewall? I thought we had software to notify us of suspicious software?” And on and on. It’s easy to blame yourself or your technology for the crisis, but many times this is simply not the case.

When it comes to a malware infection or a breach, the answer to “How did this happen?” is usually this: Someone clicked a link or opened an attachment they shouldn’t have. Antivirus and similar protection technologies simply cannot detect malware that hasn’t already been discovered because their signature databases have not been updated to protect against them. The simplest analogy to why malware makes it through is to compare it to why we need to get a flu shot every year. Because influenza, a virus, mutates constantly, our immune system does not recognize the new strain(s) until after infection. In other words, our bodies react after the damage has already been done. In this same vein, new variants of malware are written hourly. This means that computers and devices around the world are infected and compromised at an ever-increasing rate because most counter-measures simply cannot keep up with the new mutations.

So, what happens when someone clicks that link or opens that attachment? How does a computer become infected, despite all of our efforts to always remain updated? To best illustrate what happens, we’ll tell a theoretical story about a company who has been hit with ransomware, one of the most common versions of malware circulating today. This “Anatomy of a Breach” discussion will help you see what happens ‘behind the scenes’—and help you devise measures to protect against it happening to you.

A user opens their email and sees a message with a document attached, along with a potentially compelling reason to open it. The email may announce that your invoice is past due or that you need to review an attached subpoena before it is submitted to a judge. Hackers know that while 90% of people (or more) will know this doesn’t apply to them and simply delete the message, at least a small percentage may be expecting a message just like this and it never occurs to them that it might not be legit. One of these users opens the attachment and is typically presented with a note stating something such as: “The contents of this document are encrypted for your protection, please click here to enable decryption”. This tactic is used to play on the psychological aspect of the attack and gain the victim’s trust.

What is really happening is that the user is enabling macros (in the case of Word and Excel documents) or accessing a website with malicious code, which allows the malware to start its work:

  1. A small executable file and any supporting files embedded in the attachment are saved to the hard drive of the user’s device.
  2. The computer registry is modified to start the malware every time the user logs on or the computer is rebooted.
  3. The executable file is launched (sometimes as a hidden process) and it immediately connects to a “Command and Control” (CNC) server to register itself and uniquely identify the infected computer.
  4. An RSA public key is requested from the CNC server and stored in the computer registry.
  5. Any additional downloads/information the hackers want to transfer (ransom details, malware updates, etc.) are completed.
  6. The malware then quietly starts encrypting all files it is programmed to look for, both on the local computer and and on any devices it’s connected to.
  7. Once the malware finishes, it displays a notice to the victim that their files have been encrypted and a ransom demand is made.

Once the malware has done its job, the victim is basically at the mercy of the hackers. Without backups, the data is lost unless a gamble is made to pay the ransom. Even then, there is no guarantee the data will truly be restored in a usable fashion. The aftermath is typically the same: Restore from backup, if possible; rebuild the infected computer; review and update protection mechanisms and hope it doesn’t happen again.

The above scenario is one that plays out hundreds of times per day, with little variation other than the actual ransomware attack used. The underlying problem is that the hackers are, as noted above, constantly writing new variants of their attacks. The malware attack thus “looks and smells” like something completely new to automated scanners and signature-based technologies. Traditional protection simply does not work and executives from well-known technology companies have recently admitted as much. Also keep in mind, we are just referring to the recent ransomware epidemic and not even delving into the hundreds of other types of hacker attacks that are occurring as I write this.

Before you get frustrated and think there is nothing you can do, I urge you to relax. There are alternatives. Technology exists today that has consistently prevented users falling victim to these types of attacks, and it has been proven to work time and time again. That is part of our mission here at 12 Points: to find, test and explain groundbreaking technologies in this Brave New Cyber World of ours. Please don’t hesitate to contact us if you’d like to learn more.

Tony Cody is the Founder and CEO of 12 Points Technologies, a digital forensics and cyber security company that helps protect businesses from online threats, recover from online incidents and provides services for those who need to recover critical information from digital devices. Tony has over 20 years of IT experience with the U.S. military and private firms. For more information, please visit www.12PointsInc.com.

Share This Post

  • Share on Facebook
  • Share on X
  • Share on LinkedIn
  • Share on Reddit
  • Share by Mail

Related Postings

importance of network security

Why Network Security Is Important: The Key to Business Continuity

Cybersecurity, IT Services
Read more
January 27, 2025
Email Security For Small Business

Email Security for Small Businesses: Simple Steps to Stay Protected

Cybersecurity, IT Services
Read more
January 9, 2025
SMB Security Guide

Cybersecurity Guide for SMBs: Key Tips and Tools to Secure Your Business

Cybersecurity, IT Services
Read more
December 23, 2024

Categories

  • Cybersecurity
  • Digital Forensics
  • Door Security
  • IT Services
  • Managed Services

About Us

The experts at 12 Points Technologies LLC offer the highest level of Cyber Security, Digital Forensics, and Managed Service solutions to meet your needs.

What We Do

Managed IT Services in Omaha

IT Support

VoIP

Cybersecurity

Cloud

Digital Forensics

Contact Us

3730 S 149th St Suite 101
Omaha, NE 68135

SALES: (402) 844-1007
SUPPORT: (402) 401-6810

info@12pointsinc.com

Website by Abstrakt Marketing Group © 2025
  • Privacy Policy
  • Sitemap
  • Linkedin
  • Facebook
Scroll to top Scroll to top Scroll to top

This site uses cookies. By continuing to browse the site, you are agreeing to our use of cookies.

AcceptLearn more

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Accept settingsHide notification only

12pointsinc logo
Telling us about your needs can help us get you more accurate information.