IBM Says TOR Network a Vehicle for Ransomware
Report from the X-Force group says attackers are using TOR to hide their crimes
According to a report from IBM's X-Force team, the anonymous TOR network is increasingly being used to support ransomware schemes and other Internet attack scenarios. Big Blue warned companies and ISPs to start blocking TOR traffic from their networks.
Ransomware, which encrypts the victim's hard drive and demands payment to release the data, is a growing phenomenon around the world. According to the report, attackers use the TOR network to communicate with the victim and transfer monetary payments.
The reports states that the success of the TOR network as a vehicle for petty end-user ransomware attacks and SQL injection has emboldened the perpetrators, and TOR is now used for botnet control and sophisticated industrial espionage.
Although TOR services are intended to be hidden and anonymous, organizations can still take steps to keep them off the network. The report includes recommendations such as:
- Prohibiting the use of unapproved encrypted proxy services
- Prohibiting the use of personally subscribed proxy services
- Prohibiting the download and installation of unapproved software
- Prohibiting the use of personally owned removable devices
- Prohibiting computers from booting to media other than the hard drive
- Using publicly available lists of proxy nodes to block network traffic to and from listed sites
- Implementing a comprehensive desk audit program
The TOR network also has legitimate functions, such as supporting the free speech rights of users in totalitarian countries. Many innocent users implement a TOR node for ideological or political reasons without realizing the node could also be used to stage criminal activities.
Issue 245/2021
Buy this issue as a PDF
News
-
GNOME 40 Beta has been Released
Anyone looking to test the beta for the upcoming GNOME 40 release can now do so.
-
OpenMandriva Lx 4.2 has Arrived
The latest stable version of OpenMandriva has been released and offers the newest KDE desktop and ARM support.
-
Thunderbird 78 is being ported to Ubuntu 20.04
The Ubuntu developers have made the decision to port the latest release of Thunderbird to the LTS version of the platform.
-
Elementary OS is Bringing Multi-Touch Gestures to the OS
User-friendly Linux distribution, elementary OS, is working to make using the fan-favorite platform even better for laptops.
-
Decade-Old Sudo Flaw Discovered
A vulnerability has been discovered in the Linux sudo command that’s been hiding in plain sight.
-
Another New Linux Laptop has Arrived
Slimbook has released a monster of a Linux gaming laptop.
-
Mozilla VPN Now Available for Linux
The promised subscription-based VPN service from Mozilla is now available for the Linux platform.
-
Wayland and New App Menu Coming to KDE
The 2021 roadmap for the KDE desktop environment includes some exciting features and improvements.
-
Deepin 20.1 has Arrived
Debian-based Deepin 20.1 has been released with some interesting new features.
-
CloudLinux Commits Over 1 Million Dollars to CentOS Replacement
An open source, drop-in replacement for CentOS is on its way.