Posts

Showing posts with the label malware

Seriously? A Fake Windows 11 Update

Image
Fake Update...Beware! ​Credit where it’s due: we have to admit, scammers are a persistent bunch. It feels like every three weeks or so we hear about a new approach to hack, scam, or otherwise access devices and data. This one’s a doozy… both because of how simple it is, and how easy it is to fall victim to it. Scammers Have Created a Fake Windows 11 Update It sounds almost impossible, but scammers have managed to create something that looks almost exactly like a real Windows 11 update. You can probably guess where this is going: click the link, download the update, and boom — it wasn’t actually an update. It was malware, and now you’re infected. It works because people inherently tend to trust big tech, at least in some ways. When Microsoft says “hey it’s time to update Windows to make it more secure,” very few consumers or businesses think “yeah, that might just be a scam.” That’s exactly what the scammers are counting on. If they can get you to that very realistic-looking webpage tha...

Fake Versions of Apps Can Infect Your Systems with Malware

Image
Fake Apps with Malware Fake apps loaded down with malware are on the rise…again. What’s worse, new techniques are getting those malicious apps more and more visible, so that unsuspecting team members could easily download them without noticing anything’s wrong. This time there are two distinct elements you need to understand so you can keep your company and data safe. We’ll discuss the apps themselves first, then we’ll dive into SEO poisoning (the technique the bad guys are using to get these apps found). Problem #1: The Apps Themselves So what exactly are these apps? They look like apps your team needs to get work done, like WhatsApp, Chrome, and so on. Even apps we look at as extra secure, like Signal or Telegram, are getting spoofed. Of course, these aren’t the real versions of those apps. They won’t work well or fully, so eventually it might become obvious that something nefarious is happening. But maybe not: it could be that an unsuspecting user tries to install and open the app, ...

Beware Amadey, a Deviously Tricky New Malware Threat

Image
Beware this malware: It "annoys" you into handing over login details There’s a new malware threat that’s been on the rise since August. This one’s a little…weird, to be honest. But because it’s unusual and unexpected, it’s working surprisingly well at tricking people into giving up their credentials and causing massive risks of data breaches and more. This week, we’re explaining how this malware works, why it’s been so effective, and how you can avoid getting sucked in. Meet Amadey: A New Breed of Annoyance Malware Amadey is what some call “annoyance malware”: it doesn’t lock up your data and threaten you for ransom, and it doesn’t do major damage to your computer or turn it into a botnet. It just emulates a problem with Windows itself and annoys you. And this particular version makes you think the only way to solve the problem is to log in and change your settings. You might already see where we’re going with this: the login link and screen are fake, of course. So if you ent...

Chrome Extensions: Life Hacks or Security Nightmares?

Image
Chrome extensions are great for boosting productivity and saving time. But if they’re not the real deal, you could be at risk from malware. Watch our latest tech update to stay protected. There are plenty of good reasons to use Chrome, from quality of life to productivity and efficiency. But Chrome comes with several drawbacks users should be aware of. Possible Chrome Drawbacks We see two major potential drawbacks to using Chrome: data use and extension security. Data Use Creates Business Concerns One big drawback to using Chrome is the way Google is likely using you — that is, your data. Remember the old adage, “if you’re not the customer, you’re the product”? That’s definitely the case with Chrome. Google wants you to use its free, really good browser because of what it does for them , not just out of the goodness of their hearts. More than other browser makers, Google appears to collect tons of data on its users: what you do, where you visit, what you like to buy, and more. Even if...

Malware Threats Are on the Rise in 2024

Image
A new report claims that malware attacks are once again on the rise in 2024. This type of attack seems like it used to be all we talked about, but in recent years, it was dwarfed in popularity and frequency by phishing scams. Since the threat level of malware is rising, it's time to talk about it again. Here's what you need to know about malware attacks: what they are, why they matter, and what's different this time around. What Is Malware? Malware is a portmanteau of “malicious” and “software,” which pretty much explains the game: malware is software that runs on your computer just like any other software you would use, only this particular subset of software is malicious, dangerous, and usually installed without your consent or awareness. What Can Malware Do? All sorts of nasty things. Malware has the ability to do a wide range of things to your computer. It can act as a keylogger, which means recording every keystroke you make and sending that data back to the bad guys...

Ransomware: To Pay or Not to Pay?

Image
Which ransomware payment option is best? (Hint: none) We don’t like to think about it, but ransomware attacks are on the rise, and that means the chances that your business goes through one are on the rise, too. At Blue Ridge Tech, we genuinely hope you never suffer a ransomware attack — and we can help you reduce your risk in all kinds of ways. But if you do go through a ransomware attack, it pays to be prepared. That means understanding how these attacks work, what kinds of new tactics and innovations the scammers are using, and so on. Most importantly, you need to have a ready answer to this fundamental question: should you pay up, or should you refuse to do so (and risk whatever consequences you’ve been threatened with)? The Best Answer Is Avoiding the Question Entirely Of course, the best answer is “none of the above.” If you can avoid getting into this situation, you should. That’s why robust cybersecurity tactics and cybersecurity awareness training are so important. Why Busines...

87% of Web-Based Businesses Faced This Threat

Image
Scary stat: 87% of businesses hit by this in the last year Do you interact with customers via the web? Do you sell products online? If so, you’re technically a web-based business (even if you have lots and lots of “offline” business too). And you need to know about this scary statistic from the previous year. CDNetworks performed a massive analysis of more than 45 billion cyberattack attempts during 2022. Its findings were both sobering and encouraging. But let’s start with this 87%. Based on the title alone, would you think we’re about to say 87% of businesses faced an attempted cyberattack in 2022? Good guess, and we wish that was all. But no: CDNetworks found that 87% of web-based businesses faced two or more cyber threats at the same time ! What’s worse, 65% encountered “three or more simultaneous threats.” If you think your business is immune to cyberattack attempts, think again. Now let’s get into the data and figure out what all this means for you. Good News: Billions of Attack...

The Dark Sides of AI Revisited: 3 New Tactics Criminals Are Already Using

Image
Criminals are exploiting AI to create more convincing scams We wrote a couple of months ago about the dark side of generative AI . In that post we showed you a few ways that these new chatbots and other AI-powered generative technologies could do harm. Some of the things we talked about — like damaging your search engine optimization (SEO) or how generative AI generally has a loose relationship with telling the truth — aren’t exactly malicious or nefarious. They’re just things you need to know before you jump into using these tools. But other concerns do have some potential for malicious use and could be abused by criminals and bad actors. A few months ago, “could” was the operative word — but not anymore. Now it’s happening pretty much like we predicted. Here’s what you need to know about 3 new tactics criminals are already using to weaponize generative AI. 1. Phishing Emails Are Getting Harder to Spot In the past, most phishing emails had some tell-tale signs, like questionable gram...

Have You Implemented MFA Yet? Don’t Wait Any Longer. (FREE GUIDE)

Image
All businesses should adopt MFA. Now Have you implemented MFA yet on your business’s digital accounts? If not, you can’t afford to wait any longer. Here’s what you need to know about this crucial security tactic. What Is MFA? MFA stands for multifactor authentication. It’s a category of authentication methods that offer far greater security than the internet’s standard “username + password” system. If you’re not sure exactly what authentication means in this context, start with that username + password. At virtually any website you visit, those two elements tell the site that you’re you. (Sort of: technically it just tells the site that someone has credentials that only you should have — and that’s where the problems start.) You’ve probably come across two-factor authentication (2FA) somewhere in your business or personal life. There are lots of ways to do it, but the most consumer-familiar version is when a company asks for your username and password, then texts or emails you a tempor...

Microsoft Windows Remains the Biggest Cyberattack Target

Image
Windows is the prime target for cyber criminals If your business is like most, you rely on Microsoft Windows to get work done. Unless you’re a 100% Mac workplace (or Linux, we suppose), someone, somewhere in your organization is using a PC running Windows. That’s not exactly surprising news, and neither is this: because Windows is ubiquitous throughout the business world, it’s a prime target for cyber criminals and cyberattacks. The important question is what this means for your business, and what you should do about it. Should you throw out all your PCs and switch your entire company to Mac? Probably not. But you need to be aware of the threats and take the necessary steps to stay protected. Good News: Most Attacks Fail We’ll start with some good news: while something like 95 percent of all cyberattacks target Windows itself or applications running in Windows, most of them fail. That’s because, at least in part, Microsoft didn’t achieve this kind of success by failing to protect its u...

Business Software Impostors: Legit Zoom or Malware Lookalike?

Image
Are you really downloading Zoom… or is it malware? We talk a lot on this blog about keeping your company’s digital assets secure — stuff like your network storage, client files, business data, and account access to the systems that keep business moving forward. And there’s a good reason for it: digital threats to your business are all around you, and they’re more significant and more dangerous than most business leaders realize. Today we’re looking at another threat that’s a little different from phishing attacks and business email compromise. Let’s examine what we’re calling business software impostors. The good news on this one is that there are two really great ways to avoid the threat — but you and every member of your team have to know how. What’s a Business Software Impostor? A business software impostor is a fake version of a popular business software product or digital tool, designed with the intent of perpetrating some kind of attack once installed. In other words, it’s malwar...

Many Cyber Criminals are just Fine with Waiting...and Waiting...

Image
What does Persistence mean in regards to a Cyber Attack? Persistence is a tactic that allows attackers to quietly maintain access to a system over time. This “dwell time” is often used to conduct additional research, explore the victim’s environment and determine what the best (i.e. the most profitable) next step should be. Hackers can spend 11-24 days in a network before being discovered! Right Click and save our Infographic The longer an attacker persists on a device, the more intel they’re able to gather—and the more damage they can ultimately do when deploying ransomware, stealing passwords or executing other malicious activity. Not to mention the amount of your Client’s information that they can absorb! Our security agents are always on guard against attack plans like this, shining a light on hidden trespassers and removing them. Give us a call to help get your business properly secured and constantly monitored, today!

An Old Threat Resurfaces: Warn Your Team About This Scam

Image
None of your team would fall for this trick… would they What’s old is new again. Remember the early aughts, when USB flash drives seemed like the definition of our technological future? Think about it: cheap, extremely portable devices that work on just about any computer anywhere and can store any file type you can imagine. It was and still is an awesome technology, even if the advent of cloud storage and faster internet speeds have limited our need for them. The Problem with USB Flash Drives Back Then The USB drive suffered from one very frustrating (and sometimes dangerous) problem, though: because of the way USB works, there was no effective way to stop a USB drive from auto-installing stuff whenever it got plugged into a new machine. The PC simply recognized the new drive and tried to read it, and that was it: the damage was already done. Simply reading the contents of the drive was enough to install malware. If hackers, scammers, or corporate thieves had the right tech capabiliti...

Browser Extensions Have Hidden Risks. Are You Protected?

Image
Are you using a malicious browser extension without realizing? If you’re a regular internet user, chances are you’ve come across browser extensions by now. They’re so popular and so widespread that, even if you’ve never heard of them, you’re probably even using some right now as you read this post. Browser extensions can be a fantastic thing: they can enhance your productivity, make you (look like) a better writer, and help your browser be a more enjoyable thing to use. But browser extensions can also have a dark side. It’s important to understand the risks before diving down the extension rabbit hole — especially on business devices. What Are Browser Extensions? Browser extensions are little bits of software that change the way an internet browser behaves. They can deliver tons of helpful functionality, like adding in a grammar checker like Grammarly or a translator or making it easier to take and edit screenshots within your browser. A decade or so ago, extensions that blocked obtrus...

Rein In Notifications from Chrome and Windows to Regain Your Sanity

Image
Rein In Notifications from Chrome and Windows to Regain Your Sanity If you’ve been using tech for a few years, you can probably appreciate just how powerful, efficient, and even intuitive today’s computers are compared to what you used 10 years ago or longer. Processor speeds have increased exponentially, and other under-the-hood tech improvements have helped, too. But where we’ve really seen improvements in usability and intuitiveness is in the software and operating systems running on our computers. Now that they have more power available to them, software and OS makers have been able to do some pretty awesome things. Like the humble notification. Notifications: A Powerful Tool, But Easy to Abuse Take notifications, for one. Best case, notifications are intuitive and immensely helpful, letting you know about a crucial email, a new Slack message, or even something like a severe weather alert or a missing child. But like absolutely everything new, notifications have a dark side. Even t...

Are Ransomware Attacks Really a Threat to Your Business?

Image
Most ransomware victims would pay up if attacked again If you read much in the news — or in tech news specifically — it’s easy to grow a little numb to the constant reporting of digital threats and attacks on businesses. This is especially true if your business has yet to face a cyberattack: your policies and practices have gotten you by so far, so they must be good enough … right? The truth is, ransomware attacks are a threat, one that businesses like yours must take seriously now, not once you’ve already been attacked. How Ransomware Attacks Work Ransomware attacks can start like any other digital threat. Bad actors could go on a phishing expedition and steal the credentials of an unwitting employee. (We’ve said it before, and we’ll say it again: two-factor or multifactor authentication eliminates the vast majority of phishing threats.) Or threat actors could identify a vulnerability in your system through more sophisticated computer wizardry. Whatever way the bad guys find a way i...

Microsoft, Apple, and Google Join Forces to Kill the Password

Image
Is this the end of passwords… forever? The move to simultaneously simplify and enhance security has been a long time coming. We’ve said it before: passwords are a terrible way to protect your business accounts. Microsoft, Apple, and Google all agree— and they’re finally going to work together to do something about it . This is going to be a pretty big shift once it arrives, and with the Big 3 involved, there’s every reason to believe this new system could become the new standard across most of your accounts and business services. And that’s very good news! Here’s what you need to know about this coming change: what it is, when it will roll out, and how to prepare. The Problem with Passwords We won’t go too deep here because we’ve talked about it so often already, but the short version is this: passwords are awful. They’re hard to remember and easy to steal or crack. They lead to all sorts of security breaches, data theft, and more: as many as 81 percent of data breaches are due to weak...

Surprising Security News from Microsoft: Are You Protected?

Image
Multi-Factor, A New Way of Life. Microsoft recently announced some security statistics from 2021, and they’re more than a little eyebrow-raising. The headline statistic? Microsoft blocked more than 35.7 billion malicious emails from reaching the inboxes of its Microsoft 365 customers. Yes, that’s billion — with a b . That’s nearly 100 million emails a day, or more than 4 million per hour, or almost 68,000 every minute of every day in 2021. As bad as malicious emails are, imagine how much worse they’d be without the Herculean efforts of cloud providers like Microsoft and others. We’ll cover other news from Microsoft’s latest security announcement today, plus talk about what steps you should take to make sure your company remains protected. What Were These Malicious Emails? “Malicious emails” is a broad term that can include a wide range of attacks. But most of the 35.7 billion were plain old phishing emails. That’s both good and bad news, depending on how you look at it. It’s good news ...