A few days ago our engineers were contacted by one of our LAN and wireless network clients in the city of Pasto. The client quickly noticed that two of their computers could no longer access local data, and found a notepad file written in English inviting them to connect to a TOR VPN (deep web access) to pay the bitcoin ransom required to decrypt the information. They were also offered a trial decryption of a portion of their data.

Netmask engineers, certified in Cisco Security, began an analysis using the firewalls and access points in the client's infrastructure, and identified the file server as the bridge for ransomware across the network — fortunately, the data on those servers had not yet been encrypted, as the attack had started with client data. The destination IP addresses it was communicating with were blocked at the firewall but, as is typical behavior, it kept changing IPs. The quick decision was to deploy a Cisco Umbrella demo: simply changing the DNS settings in DHCP or in the clinic's Active Directory, a procedure that takes less than 10 minutes, allowed us to stop the attack at the DNS layer and restore the two computers, preventing the ransomware from spreading.

This is why an additional layer of protection at the DNS level is needed. It is worth remembering the global ransomware attack known as WannaCry, which — after infecting millions of companies — was halted by a user at home who bought the DNS domain the attack used to communicate with its servers. It is also worth keeping in mind that roughly 91% of companies have experienced some type of attack in the past 24 months; and, from experience, the other 9% did too, they just did not detect it.

Sebastián Castrillón Ospina