The lab's research indicates that 47.8% of detonated variants utilized directory-entry destruction, a figure more than double the 18.3% that employed full encryption. By preserving original file extensions, timestamps, and maintaining low entropy, these newer threats successfully mask their presence from surface-level scans. Jim McGann, CMO at Index Engines, highlighted the 'Encoder' strain as a prime example of this evolution, noting that it destroys files while leaving their names and sizes unchanged, rendering typical detection methods ineffective.
Beyond directory destruction, the study identified that 64.7% of samples exhibited polymorphism, allowing them to regenerate file signatures and bypass traditional signature-based security. The speed of these attacks remains a critical concern, with a median velocity of 97,321 files corrupted per hour. Because these variants move faster than most incident response teams can mobilize, the findings suggest that organizations must move beyond simple detection and adopt forensic validation to determine which data backups remain truly clean before initiating recovery.




Comments (0)
No comments yet. Be the first!