Bitglass and Cylance have identified ShurL0ckr, a new strain of Gojdue ransomware.ShurL0ckr is a ransomware-as-a-service that enables hackers to generate a ransomware payload and distribute it via phishing or drive-by-download, according to Bitglass. That way, hackers can encrypt files on disk in a background process until a Bitcoin ransom is paid.Neither Google Drive nor Microsoft SharePoint were able to detect ShurL0ckr, Bitglass indicated. In addition, only 7 percent of tested engines (five in 67) detected ShurL0ckr.Forty-four percent of organizations have some form of malware in at least one of their cloud applications, according to research from Bitglass and Cylance.
Most cloud services providers (CSPs) fail to deliver malware protection, and those that do struggle to detect zero-day threats, Bitglass VP of Product Management Mike Schuricht said in a prepared statement. However, AI-based threat prevention solutions now enable organizations to quickly detect new malware and ransomware, Schuricht stated, and keep their cloud data secure.
Malware Pervasive in the Cloud
Other notable findings from the Bitglass-Cylance "Malware, P.I., Tracking Cloud Infections" report included:- The average organization held nearly 450,000 files in the cloud, with one in 20,000 files containing malware.
- One in three corporate instances of software-as-a-service (SaaS) apps contained malware.
- Of the four major SaaS applications – Microsoft OneDrive, Google Drive, Box and Dropbox – OneDrive had the highest rate of malware infection at 55 percent, followed by Google Drive (43 percent) and Box and Dropbox (33 percent each).
- Scripts and executables (42 percent) used to launch malicious apps with the click of a button were the most common infected file type. Microsoft Office files (21 percent) ranked second.
