03/07/2018
09:49

Great interest in TG Soft's C.R.A.M disclosure workshop at SMAU Bologna 2018


Great interest at TG Soft's C.R.A.M. training/discussion workshop on Crypto-Malware on Thursday, June 7 at SMAU Bologna 2018, find out the topics covered, view and download the presentation.

Great attendance at TG Soft's Anti-Malware Research Center's worskshop titled ''Ransomware but not only...here's how threats are evolving in 2018...'' held on Thursday, June 7, 2018 at 11:00 a.m. at BolognaFiere as part of the SMAU Bologna 2018 event (Hall 33 - SMAU ICT Arena).

Clicca per accedere alla pagina del Workshop sul sito di SMAU...

                                     INDEX

 


 

 

The speakers at the workshop

Eng. Enrico Tonello
IT Security Researcher & Co-Author of Vir.IT eXplorer

With collaboration for attack and defense demonstrations from:
Federico Girotto
Coordinator of TG Soft's Technical Support Team for Vir.IT eXplorer software.

Torna ad inizio pagina

 

Great interest in Anti-Ransomware / Anti-CryptoMalware protection technologies

More than 100 participants registered for the workshop, which was sold out and with a large audience who, unfortunately, without the comfort of a seat, followed stoically on their feet the more than 50-minute presentation and the more than 10 minutes of Q&A with competent audience members present.

The conference is technical-disclosure in nature and aimed to present to the public the state of the art of Crypto-Malware, ransomware that encrypts PC and SERVER data files to demand ransom generally in BitCoin.

In particular, the attacks that have also received the most media attention in Italy were explained, going on to analyze how they spread and the damage they caused, in particular:
•    WannaCry (2017-05);
•    NotPetya / EternalPetya (2017-06);
•    GandCrab 1.0, 2.0 e 3.0 (2018).

To try to defend against these fearsome threats, some anti-ransomware technologies have been presented that can block encryption in its initial stage.The attack from WannaCry was shown, analyzing the damage it causes by exploiting vulnerabilities such as EternalBlue, which does not require user interaction, in situations where:

  • the PC / SERVER does NOT have a protection system capable of reporting the attack
  • a heuristic-behavioral protection system was present on the PC/ SERVER that was capable, therefore, of signaling and mitigating the effects of the attack even from next-generation variants not yet identifiable by the identification signature method
Finally, the new trends of malware code creators who have shifted their focus to activities that are less invasive and impactful in the immediate term, but no less risky for victims, were illustrated.

These are cyber-crime activities geared toward obtaining direct or indirect gains such as:
  • production and spread of malware that exploits the processors of affected PCs/Servers to "mine" crypto-currencies (BitCoin but not only...);
  • mal-spam attacks geared toward stealing credentials such as home banking logins and passwords that, if not debunked, turn PCs/Servers into Zombie computers of the mal-spam Botnet. We will see how AdWind, UrSnif, Zeus/Panda etc. manage to reap their victims.

Torna ad inizio pagina

The workshop presentation in .PDF format

Ransomware but NOT only...here's how threats are evolving in 2018 by Enrico Tonello

Torna ad inizio pagina

Photo gallery of the workshop...

Click per ingrandire l'immagine Click per ingrandire l'immagine
Enrico ready to welcome the many members
Enrico as he explains how to defend against ransomware

Click per ingrandire l'immagine Click per ingrandire l'immagine
Enrico provides an overview of the evolution of ransomware in Italy in 2018 Fact sheet illustrating how malware "undermines" Crypto Currencies.


Click per ingrandire l'immagine Click per ingrandire l'immagine
Enrico explains the Anti-Crypto Malware technology built into VirIT eXplorer PRO to mitigate the attack. Final considerations

Torna ad inizio pagina


Enrico and Federico thanked for their interest in the topics discussed.
 

TG Soft's C.R.A.M.(Anti-Malware Research Center)

Any information published on our site may be used and published on other websites, blogs, forums, facebook and/or in any other form both in paper and electronic form as long as the source is always and in any case cited explicitly “Source: CRAM by TG Soft www.tgsoft.it” with a clickable link to the original information and / or web page from which textual content, ideas and / or images have been extrapolated.
It will be appreciated in case of use of the information of C.R.A.M. by TG Soft www.tgsoft.it in the report of summary articles the following acknowledgment/thanks “Thanks to Anti-Malware Research Center C.R.A.M. by TG Soft of which we point out the direct link to the original information: [direct clickable link]”

Vir.IT eXplorer PRO is certified by the biggest international organisation: