<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Phishing &#8211; Infinity DataTel</title>
	<atom:link href="https://infinitydatatel.com/category/phishing/feed/" rel="self" type="application/rss+xml" />
	<link>https://infinitydatatel.com</link>
	<description></description>
	<lastBuildDate>Thu, 19 Jan 2023 12:46:14 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://infinitydatatel.com/wp-content/uploads/2017/04/cropped-IDT_Symbol_Color-32x32.png</url>
	<title>Phishing &#8211; Infinity DataTel</title>
	<link>https://infinitydatatel.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>8 Dangerous Computer Viruses You Should Remove Immediately! Updated!</title>
		<link>https://infinitydatatel.com/dangerous-computer-viruses/</link>
		
		<dc:creator><![CDATA[Chad Elliott]]></dc:creator>
		<pubDate>Tue, 08 Dec 2020 08:59:35 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Cloud Backup]]></category>
		<category><![CDATA[Cloud Restore]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Education]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[what are botnet sifters]]></category>
		<category><![CDATA[what is a botnet]]></category>
		<category><![CDATA[what is BazarLoader]]></category>
		<category><![CDATA[what is dridex]]></category>
		<category><![CDATA[What is emotet]]></category>
		<category><![CDATA[what is MARS ransomware]]></category>
		<category><![CDATA[what is MARS virus]]></category>
		<category><![CDATA[what is qakbot]]></category>
		<category><![CDATA[what is qbot]]></category>
		<category><![CDATA[what is sdbbot]]></category>
		<category><![CDATA[what is trickbot]]></category>
		<guid isPermaLink="false">https://infinitydatatel.com/?p=4502</guid>

					<description><![CDATA[There has been an insane increase in ransomware and computer viruses that have been jumping onto computer systems. In the past, hackers primarily emailed spam campaigns that people fell for (these still exist, but they&#8217;re becoming less common). Now, ransomware techs can use many hacking tools – some new groups even have government funding from [&#8230;]]]></description>
										<content:encoded><![CDATA[<p><strong>There has been an insane increase in ransomware and computer viruses that have been jumping onto computer systems. In the past, hackers primarily emailed spam campaigns that people fell for (these still exist, but they&#8217;re becoming less common). Now, ransomware techs can use many hacking tools – some new groups even have government funding from their third-world countries to hack our systems. Most importantly, hackers are accessing systems to steal data, earn cryptocurrency, commit identity theft, and much more.</strong></p>
<p>&nbsp;</p>
<h2>How Are the Hackers Connecting?</h2>
<p>&nbsp;</p>
<p>One of the most common methods is accessing RDP ports and points on computers and devices that share the SMB protocols in Windows 10. The hackers are acting as brokers to help other scammers and cyber attackers alike. They aren&#8217;t just ethical hackers or cyber attackers these days – now people are giving the job a title: initial access broker. This is because they get the data and sell it to bidders on the dark web and other areas, government offices, countries, and even your competitors (yes, this happens).</p>
<p>&nbsp;</p>
<h3>RDP Endpoint Sales</h3>
<div id="attachment_4508" style="width: 1034px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-4508" class="size-large wp-image-4508" src="https://infinitydatatel.com/wp-content/uploads/2020/12/Remote_Accesses_IT_Glue-1024x399.png" alt="RDP access is a hacker's dream come true when it comes to spreading computer viruses." width="1024" height="399" /><p id="caption-attachment-4508" class="wp-caption-text">RDP connections are a hacker&#8217;s dream come true when spreading computer viruses.</p></div>
<p>&nbsp;</p>
<p>This is when cyber criminals succeed with brute force cyberattacks on your servers or workstations configured to use the Remote Desktop Protocol. They then sell these remote desktop connections.</p>
<p>&nbsp;</p>
<h3>Hacked Network Equipment</h3>
<p>&nbsp;</p>
<p>Believe it or not, there are more and more vulnerabilities becoming persistent with this. As major ISPs worldwide are getting slammed with lawsuits regarding the issue, it still happens. Hackers exploit vulnerabilities of your network routers and modems, or even VPNs, and get access into the network and to the central data unit.</p>
<p>&nbsp;</p>
<h3>BOTNet Sifters</h3>
<p><img decoding="async" class="aligncenter size-large wp-image-4513" src="https://infinitydatatel.com/wp-content/uploads/2020/12/Inforgaphic-Botnet-1024x684.png" alt="Botnet computer virus infographic" width="1024" height="684" srcset="https://infinitydatatel.com/wp-content/uploads/2020/12/Inforgaphic-Botnet-980x655.png 980w, https://infinitydatatel.com/wp-content/uploads/2020/12/Inforgaphic-Botnet-480x321.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw" /></p>
<p>The malware and ransomware botnets go through the computers they infect and encrypt all their data. This allows them to be sold to other ransomware teams.</p>
<p>&nbsp;</p>
<p>Fortunately, there are some defenses regarding these computer viruses. Still, the biggest problem is that many of these emerging viruses have never been seen before – let alone in the volume in which they are modified these days. Here are some of the most common computer viruses cyber attackers use nowadays.</p>
<p>&nbsp;</p>
<h2>MARS Virus</h2>
<div id="attachment_4327" style="width: 710px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-4327" class="size-full wp-image-4327" src="https://infinitydatatel.com/wp-content/uploads/2020/12/remove-mars-ransomware.png" alt="The MARS ransomware digs its heels into your data and encrypts more files than you think." width="700" height="410" srcset="https://infinitydatatel.com/wp-content/uploads/2020/12/remove-mars-ransomware.png 700w, https://infinitydatatel.com/wp-content/uploads/2020/12/remove-mars-ransomware-480x281.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 700px, 100vw" /><p id="caption-attachment-4327" class="wp-caption-text">The MARS ransomware computer virus digs its heels into your data and encrypts more files than you think.</p></div>
<p>&nbsp;</p>
<p><a href="https://infinitydatatel.com/the-mars-ransomware-landing/">The MARS virus</a> is extremely new – only being discovered in November 2020. What&#8217;s interesting about this is that the primary attacks seem to be coming from Russia and the surrounding areas. This ransomware acts like many others, but there is no fix for it yet (many others have decryptors for files already, but not this one).</p>
<p>&nbsp;</p>
<h2>Emotet</h2>
<div id="attachment_4136" style="width: 1034px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-4136" class="size-large wp-image-4136" src="https://infinitydatatel.com/wp-content/uploads/2020/11/windows-update-document-template2222-1024x493.jpg" alt="The Emotet malware strikes when you click the " width="1024" height="493" srcset="https://infinitydatatel.com/wp-content/uploads/2020/11/windows-update-document-template2222-1024x493.jpg 1024w, https://infinitydatatel.com/wp-content/uploads/2020/11/windows-update-document-template2222-480x231.jpg 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 1024px, 100vw" /><p id="caption-attachment-4136" class="wp-caption-text">The <a href="https://infinitydatatel.com/malware-windows-update-emotet/">Emotet malware</a> strikes when you click the &#8220;Enable Editing&#8221; button and is one of the more complex computer viruses to remove.</p></div>
<p>&nbsp;</p>
<p>This is one of the most popular and largest malware botnets out there. While most of these attacks are with ransomware teams directly, this attack is a chain of other ransomware infections. The compromised system&#8217;s data is then sold.</p>
<p>&nbsp;</p>
<h2>Trickbot</h2>
<div id="attachment_976" style="width: 1034px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-976" class="size-large wp-image-976" src="https://infinitydatatel.com/wp-content/uploads/2019/04/z-trickbot-1024x641.png" alt="Trickbot has been making a comeback during the pandemic and reaping havoc on RDP accounts. " width="1024" height="641" /><p id="caption-attachment-976" class="wp-caption-text">Trickbot has been making a comeback during the pandemic and is one of many computer viruses reaping havoc on RDP accounts.</p></div>
<p>&nbsp;</p>
<p><a href="https://infinitydatatel.com/battle-rdp-attacks/">Trickbot</a> is a pretty similar botnet. Like Emotet, it is malware that allows cybercrime to take place. However, this one infects the victims but gets access to Emotet-infected systems.</p>
<p>&nbsp;</p>
<h2>BazarLoader</h2>
<p><img decoding="async" class="aligncenter wp-image-4512 size-large" src="https://infinitydatatel.com/wp-content/uploads/2020/12/bazarbackdoor-1024x473.jpg" alt="Bazaarloader" width="1024" height="473" srcset="https://infinitydatatel.com/wp-content/uploads/2020/12/bazarbackdoor-1024x473.jpg 1024w, https://infinitydatatel.com/wp-content/uploads/2020/12/bazarbackdoor-480x221.jpg 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 1024px, 100vw" /></p>
<p>This one&#8217;s a doozy but acts like the backdoor trojans of yesteryears. However, it linked to the original Trickbot hacking group and became a spinoff of that project. What&#8217;s the most important problem is that they install the <a href="https://www.crowdstrike.com/blog/big-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/" target="_blank" rel="noopener">Ryuk ransomware</a>.</p>
<p>&nbsp;</p>
<h2>Qakbot/Qbot</h2>
<div id="attachment_4511" style="width: 710px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-4511" class="size-full wp-image-4511" src="https://infinitydatatel.com/wp-content/uploads/2020/12/HackRead-750x430-2.png" alt="" width="700" height="401" srcset="https://infinitydatatel.com/wp-content/uploads/2020/12/HackRead-750x430-2.png 700w, https://infinitydatatel.com/wp-content/uploads/2020/12/HackRead-750x430-2-480x275.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 700px, 100vw" /><p id="caption-attachment-4511" class="wp-caption-text">QakBot/Qbot is one of the most devastating computer viruses you can get infected with.</p></div>
<p>&nbsp;</p>
<p>This one goes by multiple names. Infosec has deemed this one a slower infection than older systems. At the same time, the QakBot groups end up taking their time with their infections. However, they collaborate with other botnet networks to make them even more lethal.</p>
<p>&nbsp;</p>
<h2>SDBBot</h2>
<div id="attachment_4505" style="width: 710px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-4505" class="size-full wp-image-4505" src="https://infinitydatatel.com/wp-content/uploads/2020/12/ta505picture2-e1607394564172.png" alt="" width="700" height="498" srcset="https://infinitydatatel.com/wp-content/uploads/2020/12/ta505picture2-e1607394564172.png 700w, https://infinitydatatel.com/wp-content/uploads/2020/12/ta505picture2-480x342.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 700px, 100vw" /><p id="caption-attachment-4505" class="wp-caption-text">You need to audit your network immediately if you see any computer viruses.</p></div>
<p>&nbsp;</p>
<p>This one&#8217;s a more recent malware infection. It&#8217;s tied to a cybercrime group that has been seen where <a href="https://www.pcrisk.com/removal-guides/14451-clop-ransomware" target="_blank" rel="noopener">Clop</a> and other ransomware computer viruses were inserted.</p>
<p>&nbsp;</p>
<h2>Dridex</h2>
<div id="attachment_4504" style="width: 710px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-4504" class="size-full wp-image-4504" src="https://infinitydatatel.com/wp-content/uploads/2020/12/2019-06-18--scaled.jpg" alt="Dridex helps distribute computer viruses to unsuspecting individuals." width="700" height="473" srcset="https://infinitydatatel.com/wp-content/uploads/2020/12/2019-06-18--scaled.jpg 700w, https://infinitydatatel.com/wp-content/uploads/2020/12/2019-06-18--480x324.jpg 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 700px, 100vw" /><p id="caption-attachment-4504" class="wp-caption-text">Dridex helps distribute computer viruses to unsuspecting individuals.</p></div>
<p>&nbsp;</p>
<p>This <a href="https://www.firewalls.com/blog/security-terms/backdoor-trojan/" target="_blank" rel="noopener">backdoor trojan</a> is more of a malware downloader program. It is one of the most used spam email campaigns today and distributes the ransomware called Locky. However, they are using other newer ransomware strains to hit larger companies.</p>
<p>&nbsp;</p>
<h2>So How Do I Stay Protected?</h2>
<p><img decoding="async" class="aligncenter size-full wp-image-4514" src="https://infinitydatatel.com/wp-content/uploads/2020/12/malware_spreading-way-e1607414079120.png" alt="" width="700" height="376" srcset="https://infinitydatatel.com/wp-content/uploads/2020/12/malware_spreading-way-e1607414079120.png 700w, https://infinitydatatel.com/wp-content/uploads/2020/12/malware_spreading-way-480x258.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 700px, 100vw" /></p>
<p>First, you need a network solution to protect your business&#8217;s data and preserve its security. Finding the right IT support team is one of the most important things you can do. Ransomware hackers aren&#8217;t just sticking to computers and emails anymore. These days, exploits in various items around your offices can quickly become a target. And if they get access to your router, you&#8217;re in for a world of hurt. The most important thing you can do is contact your team to install some very secure firewalls, then increase your device security with a high-powered sentinel to protect your computer.</p>
<p>&nbsp;</p>
<h2>Important January 2021 Update</h2>
<p>&nbsp;</p>
<h1>How One Malware Chain Became the Most Costly &amp; How to Defend Against It</h1>
<div id="attachment_4855" style="width: 710px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-4855" class="wp-image-4855 size-full" src="https://infinitydatatel.com/wp-content/uploads/2020/12/6012314e00a9e-scaled.jpg" alt="Emotet super virus" width="700" height="394" srcset="https://infinitydatatel.com/wp-content/uploads/2020/12/6012314e00a9e-scaled.jpg 700w, https://infinitydatatel.com/wp-content/uploads/2020/12/6012314e00a9e-480x270.jpg 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 700px, 100vw" /><p id="caption-attachment-4855" class="wp-caption-text">Emotet is one of the most dangerous computer viruses we have seen in a long time.</p></div>
<p>&nbsp;</p>
<p>We&#8217;ve mentioned it, and you&#8217;ve probably heard about it elsewhere. Still, Emotet – the super virus of 2020 – has become the most impactful and destructive threat to small and medium businesses, government organizations, and larger corporations. While it&#8217;s not a new virus, it&#8217;s more heavily modified. It is evolving beyond a banking trojan – including selling information to other cyber attackers and infecting users with ransomware. But what is it? And how could one initially just an email phishing virus become this big?</p>
<p>&nbsp;</p>
<h2>Much Like a Worm</h2>
<div id="attachment_4856" style="width: 710px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-4856" class="size-full wp-image-4856" src="https://infinitydatatel.com/wp-content/uploads/2020/12/6012321a67fcf-scaled.jpg" alt="The super computer virus known as emotet is similar to computer virus worms." width="700" height="467" srcset="https://infinitydatatel.com/wp-content/uploads/2020/12/6012321a67fcf-scaled.jpg 700w, https://infinitydatatel.com/wp-content/uploads/2020/12/6012321a67fcf-480x320.jpg 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 700px, 100vw" /><p id="caption-attachment-4856" class="wp-caption-text">The super virus known as Emotet is similar to past computer viruses called worms.</p></div>
<p>&nbsp;</p>
<p>Like the old viruses called &#8220;worms,&#8221; Emotet often uses phishing emails to infect other systems on a network, other people&#8217;s contacts, and much more. And just like computer viruses of the past, users don&#8217;t know that they&#8217;ve been attacked until after.</p>
<p>&nbsp;</p>
<p>However, Emotet is not a worm, even though it acts like one. And it can be spread in similar fashions, and other attackers have been delivering it with other methods. It was initially made as banking malware but has made its way to personal and small business computers, making it one of the most widely used and dangerous computer viruses.</p>
<p>&nbsp;</p>
<h2>Trickbot is the Second Most Dangerous</h2>
<div id="attachment_4857" style="width: 710px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-4857" class="size-full wp-image-4857" src="https://infinitydatatel.com/wp-content/uploads/2020/12/601233ff3a214-scaled.jpg" alt="Out of all the current computer viruses the Trickbot trojan ranks second " width="700" height="465" srcset="https://infinitydatatel.com/wp-content/uploads/2020/12/601233ff3a214-scaled.jpg 700w, https://infinitydatatel.com/wp-content/uploads/2020/12/601233ff3a214-480x319.jpg 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 700px, 100vw" /><p id="caption-attachment-4857" class="wp-caption-text">Out of all the current computer viruses, the Trickbot banking trojan ranks second regarding how much damage it produces.</p></div>
<p>Also, <a href="https://www.bankinfosecurity.com/banking-trojan-spy-on-over-150-financial-apps-a-15343" target="_blank" rel="noopener">banking trojans</a> are constantly being manipulated, and &#8220;improved&#8221; (more like tailored to do more damage) to the point that it&#8217;s become one of the other leading ways that cyber attackers can install ransomware on individual computers. Many of these trojans are being used to take advantage of exploits in network routers, home and business network computers, and even Microsoft products. This allows users to access any educated exploit they can use against the system to damage it.</p>
<p>&nbsp;</p>
<h2>Can an Antivirus Stop the Attack?</h2>
<div id="attachment_4858" style="width: 710px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-4858" class="size-full wp-image-4858" src="https://infinitydatatel.com/wp-content/uploads/2020/12/601238e46fc9c-scaled.jpg" alt="Installing an antivirus like SentinelOne can assist in keeping computer viruses at bay." width="700" height="545" srcset="https://infinitydatatel.com/wp-content/uploads/2020/12/601238e46fc9c-scaled.jpg 700w, https://infinitydatatel.com/wp-content/uploads/2020/12/601238e46fc9c-480x374.jpg 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 700px, 100vw" /><p id="caption-attachment-4858" class="wp-caption-text">Installing an antivirus like SentinelOne can assist in keeping computer viruses at bay.</p></div>
<p>&nbsp;</p>
<p>Although it&#8217;s highly reported that most attacks can be stopped with Windows Defender and other antivirus programs, many of these trojan viruses have protection to keep the user unaware that the virus is being installed. Even many advanced firewalls are not detecting the attacks. That&#8217;s where full-service solutions like SentinelOne come into play.</p>
<p>&nbsp;</p>
<p><a href="https://infinitydatatel.com/sentinelone-antivirus-software/">SentinelOne</a> can offer a large defense against these attacks and even prevent them. At the same time, it can also aid in recovering data that may have been breached – and many ransomware attackers know it. Numerous companies are threatened when the attacker realizes they&#8217;re ignoring their ransomware attacks. We&#8217;ve even mentioned in <a href="https://infinitydatatel.com/protect-yourself-from-robocallers/">a previous post that some hackers are cold-calling their victims</a> when they know that their demands are being ignored.</p>
<p>&nbsp;</p>
<h2>So How Can You Protect Yourself?</h2>
<p><img decoding="async" class="aligncenter size-full wp-image-4859" src="https://infinitydatatel.com/wp-content/uploads/2020/12/601239db5eb20-scaled.jpg" alt="protect yourself form computer viruses" width="700" height="413" srcset="https://infinitydatatel.com/wp-content/uploads/2020/12/601239db5eb20-scaled.jpg 700w, https://infinitydatatel.com/wp-content/uploads/2020/12/601239db5eb20-480x283.jpg 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 700px, 100vw" /></p>
<p>Aside from using a full-service solution, it would help if you instilled maximum security. This is sometimes hard to do when you&#8217;re busy working. Therefore, you must have IT specialists that provide multiple services to implement these different security solutions. This could include, but not be limited to:</p>
<ul>
<li><a href="https://infinitydatatel.com/data-backups-for-your-business-phoenix/">Local cloud backups</a> of your company&#8217;s financial and critical data</li>
<li>Increased email security</li>
<li>Advanced knowledge of cybersecurity that they&#8217;ll happily share so you can teach your employees</li>
<li>A defense and helpdesk solution lets you keep busy doing what&#8217;s important – running your business.</li>
<li>Voice over Internet Protocol (VoIP) systems and phone services that extend outside of your office to local home offices</li>
<li>Dedicated local web hosting solutions</li>
<li>And much more</li>
<li>Whatever you decide to do, it&#8217;s crucial that you avoid getting these &#8220;deadly for business&#8221; computer viruses, and give us a call at <a href="https://infinitydatatel.com/contact/">Infinity DataTel</a> today!</li>
</ul>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The New MARS Ransomware is #1 Threat Thanks to Microsoft Exploit</title>
		<link>https://infinitydatatel.com/the-mars-ransomware-landing/</link>
		
		<dc:creator><![CDATA[Chad Elliott]]></dc:creator>
		<pubDate>Tue, 01 Dec 2020 04:00:05 +0000</pubDate>
				<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[Education]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[how to buy bitcoins]]></category>
		<category><![CDATA[how to buy crypto]]></category>
		<category><![CDATA[how to turn off password protected sharing]]></category>
		<category><![CDATA[how to turn off smb]]></category>
		<category><![CDATA[how to turn on password protected sharing]]></category>
		<category><![CDATA[turn off smb protocol]]></category>
		<category><![CDATA[what is MARS ransomware]]></category>
		<category><![CDATA[what is MARS virus]]></category>
		<guid isPermaLink="false">https://infinitydatatel.com/?p=4318</guid>

					<description><![CDATA[When you get sick of all the other ransomware attacks that make you WANNACRY and make your GrandCrab itch, there&#8217;s a new ransomware in town that takes you to a place you can&#8217;t breathe in. That&#8217;s the world of the MARS ransomware. &#160; Why is it so bad? First, this is one of the rare [&#8230;]]]></description>
										<content:encoded><![CDATA[<p><strong>When you get sick of all the other ransomware attacks that make you <a href="https://infinitydatatel.com/2020-ransomware-safety-guide/">WANNACRY</a> and make your <a href="https://www.slashgear.com/grandcrab-ransomware-authors-retire-after-earning-2-billion-17580852/" target="_blank" rel="noopener">GrandCrab</a> itch, there&#8217;s a new ransomware in town that takes you to a place you can&#8217;t breathe in. That&#8217;s the world of the MARS ransomware. </strong></p>
<p>&nbsp;</p>
<p><strong>Why is it so bad? First, this is one of the rare advanced ransomware infections that you can find very little (but often duplicated content) about this nasty ransomware installed on your computer. According to the information that you get with the virus in the infamous <em>!!! MARS_DECRYPT.TXT</em> file that goes into every folder and attacks your Microsoft Office files. But wait, there&#8217;s more.</strong></p>
<p>&nbsp;</p>
<h2>What is this MARS Ransomware Virus?</h2>
<p>&nbsp;</p>
<p>The MARS ransomware acts similarly to other ransomware viruses out there. You can get it in numerous ways, but the most common practice these days is thanks to the SMB: <a href="https://infinitydatatel.com/alarming-windows-vulnerabilities/">CVE-2020-0796 exploit in Windows 10</a>. Fortunately, Windows versions 1903 and 1909 have these patches available in the Windows Update store. Still, there is only a workaround (which isn&#8217;t even guaranteed to work) using a PowerShell command that ends up blocking SMB protocols.</p>
<div style="width: 1034px" class="wp-caption aligncenter"><img decoding="async" src="https://infinitydatatel.com/wp-content/uploads/2020/12/Screenshot-70-1024x950.png" alt="The easiest way to deter the MARS ransomware is to turn off your computer's SMB." width="1024" height="950" /><p class="wp-caption-text">The easiest way to deter the MARS ransomware is to turn off your computer&#8217;s SMB.</p></div>
<p>&nbsp;</p>
<p>Want another workaround? Turn off SMB in your Microsoft Windows system. No. Really. All of it. Unfortunately for businesses and even home office networks, this makes file sharing between computers a pain in the butt. You can also disable Windows Services (or <a href="https://www.upguard.com/blog/smb-port" target="_blank" rel="noopener">port 445</a>) on your router network – but then this also can break the ability for Windows to download data from Windows services.</p>
<p>&nbsp;</p>
<p>The virus is installed, and apparently, it seems that it is a Russian hacker with complete access. It tells you that you have so many of your office files and infects different file types. They list all that the virus is supposedly encrypting – but this isn&#8217;t all the files that get encrypted on your device. The virus then installs other malware into browsers and causes chrome to go haywire in the background, loading extremely malicious websites and installing other viruses.</p>
<p>&nbsp;</p>
<p>However, the tricky thing is that you don&#8217;t even see what websites open because the windows are invisible (Malwarebytes can catch this happening if you&#8217;re infected in real-time).</p>
<p>&nbsp;</p>
<h2>What&#8217;s MARS Ransomware&#8217;s Goal?</h2>
<div style="width: 1034px" class="wp-caption aligncenter"><img decoding="async" src="https://infinitydatatel.com/wp-content/uploads/2020/12/dark-3123582_1280-1024x682.jpg" alt="Like most ransomware, the MARS ransomware is after Bitcoin." width="1024" height="682" /><p class="wp-caption-text">Like most ransomware, the MARS ransomware is after Bitcoin. Image by <a href="https://pixabay.com/users/aaronjolson-4628445/?utm_source=link-attribution&amp;utm_medium=referral&amp;utm_campaign=image&amp;utm_content=3123582" target="_blank" rel="noopener">Aaron Olson</a> from <a href="https://pixabay.com/?utm_source=link-attribution&amp;utm_medium=referral&amp;utm_campaign=image&amp;utm_content=3123582" target="_blank" rel="noopener">Pixabay</a></p></div>
<p>&nbsp;</p>
<p>The goal of these types of ransomware is to steal bitcoin. These days, small businesses have been getting hit harder and more often regarding ransomware. The reason? It&#8217;s much easier to charge many small companies, LLCs, and freelancers these days a small amount than to go after a big company with more robust security. More people get infected for no reason – more people pay smaller amounts. This is a business tactic on its own (think about customer service. Charge less, get more customers).</p>
<p>&nbsp;</p>
<p>The MARS ransomware infection attacks your system when malicious attachments containing malicious files are downloaded, demanding bitcoin (usually anywhere from $500-800. The encryption process happens swiftly, and you are in big trouble if you don&#8217;t have a cloud backup. They tell you to send the unique id and three files for test decryption to an outlook or Russian email address. After decryption, they send you the decrypted files and give you a bitcoin wallet to send the money to.</p>
<p>&nbsp;</p>
<h2>What Files Are Affected?</h2>
<p><img decoding="async" src="https://infinitydatatel.com/wp-content/uploads/2020/12/mars-txt-e1606788061910.png" alt="All your important files are encrypted. To recover encrypted files, you need: 1. Buy bitcoins. The easiest way to buy bitcoins is the LocalBitcoins site. You must register, click “Buy Bitcoins” and select a seller by payment method and price. https://localbitcoins.com/buy_bitcoins You can also find other places to buy bitcoins and a beginner’s guide here: http://www.coindesk.com/information/how-can-i-buy-bitcoins/ write to google how to buy bitcoin in your country? to guarantee the availability of our key we can decrypt three files for free. 2. Send bitcoins to the address you receive in the mail. After payment, we will send a decryption program Do not try to decrypt your files using third-party programs, decoders. You only damage your data and lose them forever. Only we can decrypt your data! Contact email address rootcopper@aol.com or rootcopper@tutanota.com or rootcopper@protonmail.com" width="700" height="256" />&#8220;All your important files are encrypted.<br />
To recover encrypted files, you need:1. Buy bitcoins. The easiest way to buy bitcoins is the LocalBitcoins site. You must register, click &#8220;Buy Bitcoins,&#8221; and select a seller by payment method and price. https://localbitcoins.com/buy_bitcoins</p>
<p>You can also find other places to buy bitcoins and a beginner&#8217;s guide <a href="https://www.coindesk.com/learn/how-can-i-buy-bitcoin/" target="_blank" rel="noopener">here:</a></p>
<p>&#8220;They claim that they&#8217;re only infecting office documents, but it gets much worse than that. According to their &#8220;ransom note,&#8221; they encrypt the following filetypes:</p>
<div style="width: 710px" class="wp-caption aligncenter"><img decoding="async" src="https://infinitydatatel.com/wp-content/uploads/2020/12/remove-mars-ransomware.png" alt="The MARS ransomware digs its heels into your data and encrypts more files than you think." width="700" height="410" /><p class="wp-caption-text">The MARS ransomware digs its heels into your data and encrypts more files than you think.</p></div>
<p>&nbsp;</p>
<p>XLS, XLSX, DOC, DOCX, PPT, PPTX, ODT, ODS, PDF, PSD, FPT, PHP, and MDB files. However, it gets much deeper than that. If the virus runs for a while, then you may notice that even these files get encrypted: .bmp, .jpg, .mp4, .sav (emulator saved games), .dat, .ini, .txt, .rtf, .dotm, .cs (C#), visual studio files, .wav, .mp3, .wma, and many others.</p>
<p>&nbsp;</p>
<h2>So What Am I Supposed to Do to Be Safe?</h2>
<div style="width: 1034px" class="wp-caption aligncenter"><img decoding="async" src="https://infinitydatatel.com/wp-content/uploads/2020/12/Screenshot-71-1024x799.png" alt="Want to keep the MARS ransomware away? Make sure your password protection is turned on." width="1024" height="799" /><p class="wp-caption-text">Want to keep the MARS ransomware away? Make sure your password-protected sharing is turned on.</p></div>
<p>&nbsp;</p>
<p>If you think you may be at risk, we already gave you a basic idea. Ensure that you don&#8217;t have password-protected sharing turned off, but most importantly, disable the <a href="https://searchnetworking.techtarget.com/definition/Server-Message-Block-Protocol" target="_blank" rel="noopener">SMB protocol</a> on your computer. You can do this currently (until the future Windows Update) in Control Panel &gt; Programs and Features &gt; Windows Features and uncheck both boxes showing SMB in the title. Restart your computer after this and apply the changes. But this doesn&#8217;t necessarily mean that you&#8217;re safe.</p>
<p>&nbsp;</p>
<h2>Can I Restore the Encrypted Files?</h2>
<p>&nbsp;</p>
<p>There are numerous types of file decryption programs released by multiple companies. This ranges from Kaspersky Labs to even Trend Micro and more – but they haven&#8217;t created a decryption key for this virus, and we don&#8217;t recommend one decryption program over another. It was just discovered this month, and while some say you can use things like <a href="https://www.stellarinfo.com/" target="_blank" rel="noopener">Stellar Data Recovery</a>, many users complain that it doesn&#8217;t work to recover their files after decryption.</p>
<p>&nbsp;</p>
<p>If you have a Shadow Copy from the Windows Shadow Volume Copy service, you may be lucky enough to get some of these files back if you restore them to a specific date. However, you may end up losing some files in the process still.</p>
<p>&nbsp;</p>
<p>While a restore point may restore your programs before the attack, this may leave you vulnerable. This is why we urge all of our users to perform a cloud backup daily and, at worst, a weekly backup because it makes the recovery process much more straightforward. In many cases, the only way to fix the solution is to reset your computer using the Windows 10 Recovery Tool.</p>
<p>&nbsp;</p>
<h2>Mars Ransomware Removal</h2>
<p><img decoding="async" class="aligncenter size-full wp-image-6060" src="https://infinitydatatel.com/wp-content/uploads/2020/12/spyhunter-helpdesk.jpg" alt="Using SpyHunter might be your best bet if you want to get tings back to normal relatively quickly." width="700" height="582" srcset="https://infinitydatatel.com/wp-content/uploads/2020/12/spyhunter-helpdesk.jpg 700w, https://infinitydatatel.com/wp-content/uploads/2020/12/spyhunter-helpdesk-480x399.jpg 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 700px, 100vw" /></p>
<p>There are two ways to remove Mars Ransomware from your system. One method involves removing the malware manually with <a href="https://www.malwarebytes.com/premium" target="_blank" rel="noopener">Malwarebytes Anti-Malware Premium</a> or a similar program. Another option is to purchase an anti-malware tool such as <a href="https://www.spyhunter.com/" target="_blank" rel="noopener">SpyHunter</a>, which has been proven effective against similar threats. Both methods require downloading software onto your PC. We highly advise against installing any unknown applications found online without first reading about what they do.</p>
<p>Manual removal requires opening each folder where the malicious application resides and deleting everything. This method is time-consuming and risky since there&#8217;s no guarantee that you&#8217;ll delete every single piece of data associated with the threat. If you&#8217;re unsure how to proceed, contact us immediately to help guide you through the steps involved.</p>
<p>Spyhunter will scan your entire hard drive and display a list of items detected during its analysis. Click &#8220;Next,&#8221; review the results, and &#8220;Remove Selected.&#8221; The program should automatically reboot when complete. Note: SpyHunter does not provide real-time protection; therefore, please ensure you run scans regularly.</p>
<p>&nbsp;</p>
<h2>There Are Still Infinite Solutions</h2>
<p>&nbsp;</p>
<p>Suppose you feel that your cybersecurity is lacking or that your systems may be threatened by the MARS ransomware(or the possibility of getting it). In that case, you&#8217;ll want to get ahold of your<a href="https://infinitysol.com/contact/" target="_blank" rel="noopener"> local service provider</a> and ensure that they have a full-circle IT solution ready for you to stop the attackers at the gates and not let them in. An advanced threat protection solution that offers active anti-ransomware protection is a good start.</p>
<p>&nbsp;</p>
<p>You may even have the date on local cloud backups with your MSP provider to help you get your old files back. But suppose you see that you get infected with the MARS ransomware. In that case, you must first disconnect that infected device completely, possibly even disable or shut down your internet, and call your service provider. They can help you with the proper steps from there!</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>There&#8217;s a New Worm Phishing Campaign and Only 1 Way to Protect Yourself</title>
		<link>https://infinitydatatel.com/worm-phishing-campaign/</link>
		
		<dc:creator><![CDATA[Chad Elliott]]></dc:creator>
		<pubDate>Thu, 15 Oct 2020 09:54:31 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[how to install 2fa]]></category>
		<category><![CDATA[how to secure your network]]></category>
		<category><![CDATA[how to spot a phishing email]]></category>
		<category><![CDATA[how to stop a worm phishing campaign]]></category>
		<category><![CDATA[is 2fa safe]]></category>
		<category><![CDATA[what is 2fa]]></category>
		<category><![CDATA[what is a worm phishing campaign]]></category>
		<category><![CDATA[what is two factor authentication]]></category>
		<guid isPermaLink="false">https://infinitydatatel.com/?p=3645</guid>

					<description><![CDATA[In recent months, the COVID-19 pandemic has made phishing attacks and other cyberattacks to another level in intensity and how many people are getting infected. With the world embracing remote work, there have been so many people that weren’t prepared. This led to a lot of training for large and small businesses that needed to [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>In recent months, the COVID-19 pandemic has made phishing attacks and other cyberattacks to another level in intensity and how many people are getting infected. With the world embracing remote work, there have been so many people that weren’t prepared. This led to a lot of training for large and small businesses that needed to have professionals put specific IT infrastructure in place to defend themselves against data loss and security breaches.</p>
<p>&nbsp;</p>
<p><strong>However, in the past month, there has been a new phishing attempt, a worm phishing campaign that went out of the way tenfold compared to regular attempts. It ended up being flagged by a frequent writer and exploit finding specialist for the site <a href="https://medium.com/swlh/phishing-with-worms-the-greatest-password-theft-ive-ever-seen-26d6ad4658f9" target="_blank" rel="noopener">Medium.com</a>.</strong></p>
<p>&nbsp;</p>
<h2>What Was the Attack?</h2>
<div id="attachment_3708" style="width: 710px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-3708" class="wp-image-3708 size-full" src="https://infinitydatatel.com/wp-content/uploads/2020/10/590b2b8dfcd8ebe3028b4edf-e1602737567576.png" alt="The worm phishing camapiagn started out innocently enough, but soon spiralled out of control affecting" width="700" height="422" /><p id="caption-attachment-3708" class="wp-caption-text">The worm phishing campaign started innocently enough but soon spiraled out of control affecting every account and mass emailing every contact in their database.</p></div>
<p>&nbsp;</p>
<p>The attack was initially considered to be another regular attack, so the IT team ended up locking things down as usual to investigate. However, within just a matter of minutes, numerous other alerts were reaching their email inbox. The emails managed to sneak their way through all of the filtering rules, and countless people were attacked and infected quickly. The next thing they know, they realized that while they worked on a couple of the compromised accounts and recovered them, a whole slew of accounts had indeed been taken over.</p>
<p>&nbsp;</p>
<p>All of the accounts were accessed throughout the world and sending out mass emails. Therefore, the <a href="https://infinitydatatel.com/disaster-recovery-plan/">phishing attack</a> happened faster than usual. The company realized that either someone had been working on their accounts for a long time, or the phishing attack was instrumental. However, nobody ended up receiving an email from any new contacts on that day that seemed suspicious.</p>
<p>&nbsp;</p>
<p>However, the emails that ended up being the worm <a href="https://infinitydatatel.com/phishing-emails-to-steer-clear-of/">phishing emails</a> ended up being legitimate emails that were exchanged within the network as regular emails. How could this happen? Well, it’s a bit tricky, but it had a rapid worm-like method of operation. When an email account for the company was compromised, the account information ended up being sent to a bot remotely that would sign in and take a good look at the emails sent in the most recent days.</p>
<p>&nbsp;</p>
<p>Every time it found a particular email chain, it would reply to the most recent one with a link to a <a href="https://safebrowsing.google.com/safebrowsing/report_phish/?hl=en" target="_blank" rel="noopener">phishing page</a> to steal the person’s information. Compared to most phishing campaigns, the words fit just about any scenario, so the link to a document didn’t seem too strange. It would then use a reply-all method using a real email account. People had trouble figuring out which emails were different from the employees’ actual emails.</p>
<p>&nbsp;</p>
<h2>The Worm Phishing Campaign is Caught</h2>
<div id="attachment_3709" style="width: 710px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-3709" class="wp-image-3709 size-full" src="https://infinitydatatel.com/wp-content/uploads/2020/10/attackers-unleash-oauth-worm-via-google-docs-app-showcase_image-10-a-9888-scaled.jpg" alt="Luckily, over time, the bot grew so large that it expanded out of the original organization raising red flags." width="700" height="423" srcset="https://infinitydatatel.com/wp-content/uploads/2020/10/attackers-unleash-oauth-worm-via-google-docs-app-showcase_image-10-a-9888-scaled.jpg 700w, https://infinitydatatel.com/wp-content/uploads/2020/10/attackers-unleash-oauth-worm-via-google-docs-app-showcase_image-10-a-9888-480x290.jpg 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 700px, 100vw" /><p id="caption-attachment-3709" class="wp-caption-text">Luckily, the bot grew so large that it expanded out of the original organization and</p></div>
<p>&nbsp;</p>
<p>Over time, bots retain memory, and they end up having bugs in them that most attackers don’t think about – when they increase in size and memory after taking over so many accounts, they begin to slip. Rather than just sending the emails internally in a network, other people outside of the network will get the emails, which is how the red flags and alarms are sounded.</p>
<p>&nbsp;</p>
<h2>What Can I Do to Protect Myself?</h2>
<div id="attachment_3234" style="width: 710px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-3234" class="wp-image-3234 size-full" src="https://infinitydatatel.com/wp-content/uploads/2020/05/file-9hn5yfRcl2-e1602738087283.png" alt="Something as simple as using 2FA can help keep you safe from a worm phishing attack." width="700" height="571" /><p id="caption-attachment-3234" class="wp-caption-text">Something as simple as using 2FA can help keep you safe from a worm phishing attack.</p></div>
<p>&nbsp;</p>
<p>One thing you can do is to put <a href="https://infinitydatatel.com/email-security-to-keep-you-safe/">2FA</a>, two-factor authentication, on all of your local email accounts in your company’s network. If you need help doing this, you can get ahold of your local IT managed solutions office so that they can incorporate the smart tech solutions you’ll need to have the best protection possible.</p>
<p>&nbsp;</p>
<p>Along with the ability to protect your accounts and your local business’s technology, you’ll be able also to have ways that you can combat cyberattacks before they ever happen using the right tools – and using <a href="http://infinitysol.com" target="_blank" rel="noopener">a managed service provider</a> can help you save more money on costs than other corporations and regular professional IT services.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>10 Reasons Why Backups Are More Important Than You Think</title>
		<link>https://infinitydatatel.com/data-backups-for-your-business-phoenix/</link>
		
		<dc:creator><![CDATA[Chad Elliott]]></dc:creator>
		<pubDate>Wed, 04 Sep 2019 06:02:02 +0000</pubDate>
				<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Cloud Backup]]></category>
		<category><![CDATA[Cloud Restore]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Education]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[can my business use a cloud backup]]></category>
		<category><![CDATA[cloud backup]]></category>
		<category><![CDATA[cloud services]]></category>
		<category><![CDATA[cloud storage]]></category>
		<category><![CDATA[do i need a data backup]]></category>
		<category><![CDATA[do i need a disaster recovery plan]]></category>
		<category><![CDATA[does my business need a server]]></category>
		<category><![CDATA[how do i back up my computer]]></category>
		<category><![CDATA[how often should i back up]]></category>
		<category><![CDATA[how to use a cloud backup]]></category>
		<category><![CDATA[recovery plan]]></category>
		<category><![CDATA[what are cloud services]]></category>
		<category><![CDATA[what is a cloud backup]]></category>
		<category><![CDATA[what is a disaster recovery plan]]></category>
		<category><![CDATA[what is cloud storage]]></category>
		<guid isPermaLink="false">https://infinitydatatel.com/?p=1324</guid>

					<description><![CDATA[Ransomware has the power to cripple businesses in a heartbeat, but it doesn&#8217;t have to be. Crypto viruses can be easy to recover from with little downtime. All it takes is a little preparation and understanding. Today, we will discuss what your business needs to do to prepare for an inevitable ransomware attack. We need [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Ransomware has the power to cripple businesses in a heartbeat, but it doesn&#8217;t have to be. Crypto viruses can be easy to recover from with little downtime. All it takes is a little preparation and understanding. Today, we will discuss what your business needs to do to prepare for an inevitable ransomware attack. We need to discuss crash plans and backups.</p>
<p>&nbsp;</p>
<h2>Backup Strategies You Can Count On</h2>
<div id="attachment_2754" style="width: 710px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-2754" class="wp-image-2754" src="https://infinitydatatel.com/wp-content/uploads/2019/09/backup-strategy-4-steps-to-foll.png" alt="Creating and sticking to a backup strategy can save your business if and when things go awry." width="700" height="565" srcset="https://infinitydatatel.com/wp-content/uploads/2019/09/backup-strategy-4-steps-to-foll.png 700w, https://infinitydatatel.com/wp-content/uploads/2019/09/backup-strategy-4-steps-to-foll-480x387.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 700px, 100vw" /><p id="caption-attachment-2754" class="wp-caption-text">Creating and sticking to a backup strategy can save your business if and when things go awry.</p></div>
<p>&nbsp;</p>
<p>First, let&#8217;s discuss your backup strategy. We will jump into this topic because you can&#8217;t have a crash plan without a proper backup strategy. Creating a backup scheme is fundamental to recovering from any significant incident. Your business could be hit by ransomware or an act of God like a hurricane. Either way, with a bit of preparation and testing, these things become less threatening.</p>
<p>&nbsp;</p>
<p>There&#8217;s a tried and true rule for creating backups. That is called the 3-2-1 rule. It&#8217;s simple. Make three backups of everything. Two of those backups need to be on different media, like a tape backup and a cloud backup. One of those backups needs to be kept off-site, preferably in a different city or region.</p>
<p>&nbsp;</p>
<p>Following this rule used to be a lot more complicated. With the availability of cloud services today, there is no reason not to follow this rule. Even better, all your backups can be completely automated and still follow this rule.</p>
<p>&nbsp;</p>
<h2>What Software Should We Use?</h2>
<div id="attachment_2755" style="width: 710px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-2755" class="wp-image-2755" src="https://infinitydatatel.com/wp-content/uploads/2019/09/Office-365-vs-G-Suite-Which-one-suits-best-for-your-business-i.png" alt="Office 365 and Google's G Suite are both viable options when it comes to backups." width="700" height="281" srcset="https://infinitydatatel.com/wp-content/uploads/2019/09/Office-365-vs-G-Suite-Which-one-suits-best-for-your-business-i.png 700w, https://infinitydatatel.com/wp-content/uploads/2019/09/Office-365-vs-G-Suite-Which-one-suits-best-for-your-business-i-480x192.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 700px, 100vw" /><p id="caption-attachment-2755" class="wp-caption-text">Office 365 and Google&#8217;s G Suite are both viable options when it comes to backups.</p></div>
<p>&nbsp;</p>
<p>Let&#8217;s start with user PCs. These are the computers that each business assigns to employees to get work done. Today, most companies subscribe to <a href="https://www.office.com/" target="_blank" rel="noopener">Office 365</a> or <a href="https://gsuite.google.com/" target="_blank" rel="noopener">Google&#8217;s G Suite</a>. Both subscriptions include a cloud syncing service with an important feature.</p>
<p>&nbsp;</p>
<p>Office 365 has a syncing feature called OneDrive. G Suite has its Backup and Sync service, also called Drive. Both applications will sync data stored within a designated folder on a user&#8217;s PC to the cloud. Once in the cloud, employees can access their data on the go. They can also easily send and share files stored in the cloud with customers and co-workers.</p>
<p>&nbsp;</p>
<h2>Syncing Data</h2>
<div id="attachment_2756" style="width: 710px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-2756" class="wp-image-2756" src="https://infinitydatatel.com/wp-content/uploads/2019/09/Sync-1-scaled-1.jpg" alt="Syncing your data regularly will keep your files and backups up to date in case an emergency were ever to occur." width="700" height="354" /><p id="caption-attachment-2756" class="wp-caption-text">Syncing your data daily or even weekly will keep your files and backups updated if an emergency occurs.</p></div>
<p>&nbsp;</p>
<p>Both cloud syncing services offer two powerful features. First, if a user&#8217;s PC needs to be re-imaged or replaced, restoring those synced files is easy. The applications must be configured and given a little time to restore these files.</p>
<p>&nbsp;</p>
<p>It&#8217;s important to note that both services will only sync data stored in those configured folders for each app. Make sure that employees are saving their data to these folders. It might be wise to set this specific sync folder as the standard Documents library in Windows. That way, files are saved to this location automatically.</p>
<p>&nbsp;</p>
<p>The second important feature that both apps have is a file versioning feature. This is especially important for ransomware. If files are encrypted and synced, or if a user accidentally saves a file after making an unwanted change, data can be rolled back from the cloud to previous working versions.</p>
<p>&nbsp;</p>
<h2>Server Talk</h2>
<div id="attachment_4959" style="width: 710px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-4959" class="size-full wp-image-4959" src="https://infinitydatatel.com/wp-content/uploads/2019/09/602b25d75dd3e-scaled.jpg" alt="Some businesses choose to back up their files on a dedicated server. Others like to use both local storage and cloud services." width="700" height="466" srcset="https://infinitydatatel.com/wp-content/uploads/2019/09/602b25d75dd3e-scaled.jpg 700w, https://infinitydatatel.com/wp-content/uploads/2019/09/602b25d75dd3e-480x320.jpg 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 700px, 100vw" /><p id="caption-attachment-4959" class="wp-caption-text">Some businesses choose to back up their files on a dedicated server. Others like to use both local storage and cloud services.</p></div>
<p>Now, let us discuss servers. Servers can take a bit more work to back up, but they are not challenging. Applications like Veam can make images of current servers and backup specific folders. These features can also be used for essential computers that employees regularly use.</p>
<p>&nbsp;</p>
<p>You will want to spend a little time deciding which computers and servers need to be backed up, and you need to determine how regularly they need to be backed up. There are many strategies to discover the answers to these questions, but the easiest way to decide is to figure out how much data you could lose before your business is impacted. Is it one day, three days, or a week?</p>
<p>&nbsp;</p>
<p>After backups are made, they need to be stored somewhere. Thankfully, data storage has become very cheap today. There are various solutions, whether you are a small, medium, or large business. For small businesses, a simple <a href="https://en.wikipedia.org/wiki/Network-attached_storage" target="_blank" rel="noopener">NAS</a> might work best. They can be purchased or built for about the price of a laptop. They can also hold a lot of data!</p>
<p>&nbsp;</p>
<p>Once that data is saved somewhere locally, you need to think about getting it off-site. <a href="https://www.infinitydatatel.com">Your IT staff</a> can help you decide on the best solution for that. There are a lot of useful applications that will save backups to online storage facilities. With services like AWS S3, Azure, and Wasabi, plenty of reasonable solutions would work for your business.</p>
<p>&nbsp;</p>
<h2>Have You Prepared for a Crash?</h2>
<div id="attachment_2757" style="width: 710px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-2757" class="wp-image-2757" src="https://infinitydatatel.com/wp-content/uploads/2019/09/Business-Computer-Crash.jpg" alt="Restoring your information from your backup only works if you know how to do it and have a plan in place ahead of time." width="700" height="416" /><p id="caption-attachment-2757" class="wp-caption-text">Restoring your information from your backup only works if you know how to do it and have a plan ahead of time.</p></div>
<p>&nbsp;</p>
<p>Now, let&#8217;s talk about your crash plan. Backing up data doesn&#8217;t mean much unless you know how to restore it. So, it would help if you created a plan to restore your data.</p>
<p>&nbsp;</p>
<p>Unfortunately, giving everyone a concrete recovery plan is beyond the scope of this article. Creating a crash plan depends on the methods you use to back up your data. Create a program built around how you would retrieve that data from wherever you are storing it. Keep in mind that you may also need to get your off-site copies.</p>
<p>&nbsp;</p>
<p>After you have made that plan, break things down. It&#8217;s not suggested to break computers that are in active operation, so use a spare computer. Better yet, try your crash plan on different hardware as well. Let&#8217;s say a server has a hardware problem and goes down. That hardware can no longer be replaced, and you are forced to buy new computers. Can you restore your data and configure that new machine?</p>
<p>&nbsp;</p>
<p>This is the point of testing your crash plan. Make sure it works. Chances are, your crash plan will never work on the first attempt. You need to find the holes in that plan and fill them. If you are having difficulty and can&#8217;t find the holes to fix, you can <strong><a href="https://infinitydatatel.com/contact-us/">contact us</a>,</strong> and we&#8217;ll find them for you.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>So, You&#8217;ve Been Hacked. 6 Things You Need to do Immediately After</title>
		<link>https://infinitydatatel.com/ive-been-hacked/</link>
		
		<dc:creator><![CDATA[Chad Elliott]]></dc:creator>
		<pubDate>Wed, 31 Jul 2019 06:03:58 +0000</pubDate>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[how to avoid a cyberattack]]></category>
		<category><![CDATA[how to prevent a cyberattack]]></category>
		<category><![CDATA[how to spot a phishing email]]></category>
		<category><![CDATA[what is a crypto locker]]></category>
		<category><![CDATA[what is a cryptovirus]]></category>
		<category><![CDATA[what is the crypto virus]]></category>
		<guid isPermaLink="false">https://infinitydatatel.com/?p=1212</guid>

					<description><![CDATA[&#8220;I&#8217;ve been hacked! What do I do now?&#8221; This is a question you never want to ask yourself, but someday you might have to. Hacks are becoming more and more of an everyday occurrence. What does it mean to be &#8216;hacked,&#8217; though, and what should a business do after it happens? &#160; &#8216;Being Hacked&#8217; comes [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>&#8220;I&#8217;ve been hacked! What do I do now?&#8221; This is a question you never want to ask yourself, but someday you might have to. Hacks are becoming more and more of an everyday occurrence. What does it mean to be &#8216;hacked,&#8217; though, and what should a business do after it happens?</p>
<p>&nbsp;</p>
<p>&#8216;Being Hacked&#8217; comes in many forms. The term hacked is a catch-all statement that encompasses many attack vectors. These can include:</p>
<p>&nbsp;</p>
<ul>
<li>Having data stolen</li>
<li>Having your website taken over</li>
<li>Being infected by a cryptovirus</li>
<li>Having an intruder snooping around your network</li>
<li>Etc.</li>
</ul>
<p>&nbsp;</p>
<p>While it&#8217;s impossible to answer every single response a business should take after being hacked within this article, we can discuss some basic strategies to consider.</p>
<p>&nbsp;</p>
<h3>Identify How You Have Been Hacked</h3>
<div id="attachment_3063" style="width: 710px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-3063" class="wp-image-3063" src="https://infinitydatatel.com/wp-content/uploads/2019/07/pngfuel.com_.png" alt="The first thing to do after you've been hacked is to get ahold of your Managed Service Provider or IT security team. The second thing you should do is figure out how it happened." width="700" height="918" srcset="https://infinitydatatel.com/wp-content/uploads/2019/07/pngfuel.com_.png 700w, https://infinitydatatel.com/wp-content/uploads/2019/07/pngfuel.com_-480x630.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 700px, 100vw" /><p id="caption-attachment-3063" class="wp-caption-text">The first thing to do after you&#8217;ve been hacked is to get ahold of your <a href="http://infinitysol.com" target="_blank" rel="noopener">Managed Service Provider</a> or IT security team. The second thing you should do is figure out how it happened.</p></div>
<p>&nbsp;</p>
<p>This may seem like such a &#8216;duh&#8217; statement, but sometimes the answer isn&#8217;t always obvious. Do you have a cryptovirus spreading through your network? Was your website taken over? If you had data stolen, what was taken?</p>
<p>&nbsp;</p>
<p>Accurately identifying the issue will help develop the solution. Each of these hacks listed can have very different diagnostics and remediation methods. Fully understanding what is happening within your IT infrastructure will help develop those solutions.</p>
<p>&nbsp;</p>
<h3>Create and Implement a Mitigation Plan</h3>
<div id="attachment_3064" style="width: 710px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-3064" class="wp-image-3064" src="https://infinitydatatel.com/wp-content/uploads/2019/07/Organization-Security-Plan-1024x775.jpg" alt="After you've been hacked you'll need to make a plan on how to not get hacked again." width="700" height="530" /><p id="caption-attachment-3064" class="wp-caption-text">After you&#8217;ve been hacked, you&#8217;ll need to make a plan on how not to get hacked again.</p></div>
<p>&nbsp;</p>
<p>Here&#8217;s where the process starts to get tricky. After a business identifies precisely what happened, they need to develop a plan to mitigate any further damage. That mitigation plan then needs to be implemented quickly to prevent any further damage from occurring. Aside from preventing further damage, the business also needs to ensure any evidence isn&#8217;t destroyed. That evidence will be required for both filing police reports, if required, and analysis to create future mitigation steps.</p>
<p>&nbsp;</p>
<p>Many hacks could be considered what&#8217;s known as an advanced persistent threat. This is what happened to Sony in their hack years ago. Sony had intruders walking through their network for four years before they realized they had an issue. Sony had everything from trade secrets, to employee information, to games and movies stolen from them.</p>
<p>&nbsp;</p>
<p>Crypto viruses, also known as ransomware, are now a popular attack method. They are designed to extort businesses. One of the reasons crypto viruses are such potent attacks is that they hop from PC to PC and server to server by themselves. Crypto viruses then attempt to <a href="https://www.businessnewsdaily.com/9391-computer-encryption-guide.html" target="_blank" rel="noopener">encrypt important files</a> on each of these systems. The more data a cryptovirus can encrypt throughout the network, the more devastating the attack becomes.</p>
<p>&nbsp;</p>
<h3>Identify How the Hack Occurred</h3>
<p>&nbsp;</p>
<p>Now comes the arduous work. After the threat has been neutralized, the business must identify how the attack occurred. How did an intruder break into the network? How did a cryptovirus sneak its way in?</p>
<p>&nbsp;</p>
<p>Unfortunately, answering this question can sometimes be impossible. Though it&#8217;s always best to know exactly what happened, sometimes businesses must rely on theories. Trained professionals and cybersecurity experts can develop very accurate ideas on how an attack occurred and what the most likely attack vectors were. Businesses will need to know this to create a strategy to prevent another attack from happening.</p>
<p>&nbsp;</p>
<h3>Implement a Solution</h3>
<div id="attachment_3065" style="width: 710px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-3065" class="wp-image-3065" src="https://infinitydatatel.com/wp-content/uploads/2019/07/solution.jpg" alt="After you've identified how you were hacked and made a plan to not get hacked again you'll need to execute said plan." width="700" height="445" srcset="https://infinitydatatel.com/wp-content/uploads/2019/07/solution.jpg 700w, https://infinitydatatel.com/wp-content/uploads/2019/07/solution-480x305.jpg 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 700px, 100vw" /><p id="caption-attachment-3065" class="wp-caption-text">After you&#8217;ve identified how you were hacked and made a plan not to get hacked again, you&#8217;ll need to execute said plan.</p></div>
<p>&nbsp;</p>
<p>The hack has been mitigated, and the businesses now have a pretty good idea of how it happened. So, what&#8217;s next? Now the company needs to start fixing things, so this doesn&#8217;t happen again.</p>
<p>&nbsp;</p>
<p>Solutions can come in all shapes and sizes. This is why all of those previous steps are so important. It helps to understand the entire situation, identify the stakeholders, and create an effective solution.</p>
<p>&nbsp;</p>
<p>For instance, if a cryptovirus hit your business, that virus most likely entered the network through social engineering. Someone probably tricked an employee into downloading a file. That file launched the cryptovirus on their computer.</p>
<p>&nbsp;</p>
<p>Once on the computer, that virus started encrypting all the essential files on that employee&#8217;s drive. While it started this process, the virus found other vulnerable PCs and storage drives on the network and spread.</p>
<p>&nbsp;</p>
<h4>The solution for a cryptovirus is complex and will require multiple steps. Here&#8217;s a broad overview of some of them:</h4>
<p>&nbsp;</p>
<ol>
<li>Wipe and restore any affected machines. It&#8217;s better to wipe a device altogether and start from scratch. Some viruses will go dormant and emerge again later.</li>
<li>Perform <a href="https://searchsecurity.techtarget.com/definition/social-engineering" target="_blank" rel="noopener">social engineering</a> audits on employees. This will identify which employees may need extra training. On-going training for all employees will also need to be provided.</li>
<li>Ensure backups are working and are not affected. At the same time, many businesses don&#8217;t invest in backup solutions. This is a mistake. Backup solutions don&#8217;t have to be pricey. On the other hand, by not having a backup solution when one is needed, it could be a costly mistake.</li>
<li>Test backups. Just because a business has a backup doesn&#8217;t mean it will work properly. They need to be tested regularly.</li>
<li>A security audit of all PC configurations must be performed. The original crypto viruses depended on SMB 1.0 to spread. Making sure these types of protocols are turned off and aren&#8217;t needed, plus making sure user account permissions are correctly set, will go a long way towards preventing a cryptovirus from striking. Ensuring PCs are correctly configured, and proper permissions are set for user accounts can prevent viruses than most anti-virus software can.</li>
</ol>
<p>&nbsp;</p>
<p>This plan will change drastically, depending on the type of hack that occurred. Creating mitigation and remediation plans is a complex subject. It&#8217;s best to seek outside help to analyze the hack and figure out how to resolve it when one occurs. Better yet, start planning for that eventual hack now. Planning for it before that hack happens can help mitigating it from it ever occurring in the first place.</p>
<p>&nbsp;</p>
<p>For more information about what you can do before/after you are hacked, please <strong><a href="https://infinitydatatel.com/contact-us/">send us a message</a></strong> or call 480-493-5999 today!</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
