Suggestions on general preventive measures against ransomware viruses

** Excerpted from: 2020 China Internet Network Security Report Pages 85-86 **

Judging from the propagation methods of major ransomware families, the less secure Remote Desktop Protocol (RDP) is the most common attack vector. Secondly, it uses spam, phishing emails, puddle websites, etc. to spread the virus and induce victims to download and run the ransomware. For ransomware viruses that are mainly spread through remote desktop login blasting,

● The device login password should be a strong password (a long combination of letters + numbers + special symbols), and the password should be changed regularly; ● Different devices should use different strong passwords to avoid repeated use of a password; ● Make regular data backups and save them off-site; ● Close or modify high-risk ports such as 135~139 and 445, and close file sharing between servers; ● Conduct security self-examinations on assets regularly and install vulnerability patches in a timely manner; ● Reasonably divide the security domains of the intranet, and implement Access Control Lists (ACL) restrictions between domains, especially the domain administrator’s computer. If it is breached, it will bring the risk of the entire LAN being compromised; ● Record and monitor full traffic logs, and regularly check the equipment for abnormalities; ● Install security software to improve server security to prevent core data from being encrypted, causing heavy losses. For ransomware viruses that are mainly spread through phishing and other methods, the following preventive measures are recommended: ● Do not download unknown files, documents, pictures or videos on the Internet, and be cautious about links in unfamiliar emails and text messages; ● Download and install software from formal channels; ● Pay attention to standardize the use of removable media such as USB flash drives, turn off the automatic playback function, and scan and kill before use; ● Conduct regular security training to enhance the security awareness of network administrators and ordinary users.

** Excerpted from: 2020 China Internet Network Security Report Pages 85-86 **