Respond to Business-threatening Ransomware with AhnLab MDS
Ransomware is a compound word consisting of "ransom" and "software." It refers to the hacking technique that infects the PC with malware to encrypt saved documents or files and demand money for their recovery. Breach incidents and reports regarding ransomware are increasing every year, but treatment or recovery after infection is far from easy due to the characteristics of ransomware. This post will cover the trends and attack paths of ransomware and examine security measures that can be taken through AhnLab's sandbox-based ransomware and intelligent threat response solution, 'AhnLab MDS.'

What Are the Latest Ransomware Trends?
In 2022, ransomware groups worldwide experienced difficulty continuing their activities. REvil, a major ransomware group, was apprehended, and Conti ceased operations. A war also broke out between Ukraine and Russia. In particular, multiple ransomware groups consisting of Russian members faced restrictions in their activities due to the impact of the war.
However, the number of companies that suffered harm due to ransomware has seen a steady rise. Over 50 ransomware groups have been active since 2022, and more than 23 of them are identified as new. These groups have expanded their attack targets to various industries, including medicine, communications, insurance, and manufacturing. Even global corporations with some level of security competence had to suspend their business due to ransomware attacks, suffering losses totaling tens of billions in Korean won. The recent emergence of the 'Gwisin ('ghost' in Korean)' ransomware has become a grave issue in Korea. Small and medium-sized companies with insufficient budgets to respond to ransomware and lacking security solutions and operation personnel have become primary targets.
Ransomware groups are also diversifying through the dark web. Since the rise of Ransomware as a Service (RaaS) in 2020, ransomware groups began trading 'Stealer' logs on the dark web, the key information stolen from individuals and companies using the information theft-type malware, Infostealer. As a result, the number of ransomware groups active on the dark web and their victims has increased continuously over the last two years. Stealer logs are used as ransomware groups' information theft tools or as the initial access process.
As such, ransomware groups are still highly active and regarded as serious threats to corporate business. Aside from encryption, the traditional method of attack, threat actors have constantly been causing leakages by using critical data of target institutions as subsidiary means of threat, requiring measures to be taken to maintain business continuity. Patterns of attacking corporations' partner companies or affiliates with comparatively weaker security levels are also causing severe damage to manufacturers, demanding ransomware to be considered a part of the supply chain threat and countermeasures to be sought.
AhnLab MDS, Optimized for Response to Ransomware
Ransomware can infiltrate through all sections handled by the user, such as email, network, endpoint, and network connection. In particular, email is the best attack vector for distributing ransomware to unspecified masses. Threat actors propagate ransomware disguised as work-related attachments or practice ransomware attacks using social engineering techniques. Ransomware strains are also disguised as pirated copies of work-related programs, cracks, and security update files. External USB storage devices are not free from ransomware risks either.
As the optimum security solution to defend against ransomware, AhnLab proposes AhnLab MDS, AhnLab MDS Agent, and AhnLab MDS Agent control services. The services collect and suspend the execution files flowing in from various routes, determine whether they are malware strains through signature-based static and reputation detection and the sandbox-based dynamic analysis, a signature-less method, and take measures accordingly.

Figure 1. AhnLab MDS configuration diagram
Role of AhnLab MDS
On top of offering mirror traffic detection and block configurations, AhnLab MDS can also activate its Mail Transfer Agent (MTA) license to be configured to a piece of equipment exclusive to mail server detection and block. MTA includes the static and dynamic analysis features of MDS and provides mail transmissions, filtering/quarantine, and response to phishing/scam mail. When AhnLab MDS (MTA) is implemented at the front end of the tenant's mail server, the solution parses the attachment and main text upon the arrival of email to execute a behavior analysis, which includes detection of malicious URLs, securing crucial keywords based on AI, and similarity comparison with phishing email DB. Afterward, the email suspected of being malicious is quarantined within the device so that only normal emails can arrive at the server, and a notification is sent to the email recipient and security admin.
AhnLab MDS Agent
As an optional feature, AhnLab MDS Agent is installed in the user's PC to collect and suspend the execution of new files that bypassed the detection of AhnLab MDS or did not pass the network. This feature for suspending execution is also called 'Execution Holding (EH).' It disallows files without analysis results to be executed on the PC, preventing ransomware infection. Such files are collected by MDS to be analyzed, and files determined to be malware or have unclear analysis results can be restricted from being executed on the PC or deleted.
AhnLab MDS Agent Control Service
AhnLab recently released the AhnLab MDS Agent control service. This service is specialized for small-scale organizations and companies who find it challenging to purchase MDS devices or lack security experts. When a user runs an executable or script-based file on their PC, AhnLab MDS Agent suspends file execution for a moment while simultaneously sending it to the AhnLab MDS established in AhnLab's internal infrastructure. The service immediately deletes files determined to be malware and sends a response report, including real-time summaries, details, and TI reputation information via email to the security admin. Because file execution is suspended until the analysis is complete, initial infection of malware strains such as ransomware can be blocked.

Figure 2. AhnLab MDS Agent control service configuration diagram
When the AhnLab MDS Agent control service is used alongside antivirus products, both sides can complement each other by allowing the antivirus to respond to known malware and the control service to prevent unknown threats. Also, the control service can be immediately utilized with the installation of AhnLab MDS Agent, requiring no implementation of additional equipment. This advantage enables small and medium-sized companies to secure response capabilities against endpoint threats without any burden of furnishing implementation costs or the lack of operation personnel.
What Has Changed in the New AhnLab MDS Model?
In May 2023, AhnLab MDS was upgraded from Model A to Model B. Equipped with a high-performance packet processing library, Model B has been improved to process twice as much traffic as Model A and can perfectly defend against ransomware attacks that temporarily increase traffic flow.
Figure 3. Improvements in AhnLab MDS Model B
The top-tier equipment of Model B can process 10 Gbps of traffic. Performance improvements were facilitated through a CPU upgrade; the number of CPU cores increased by 60%, enhancing CPU performance by 43%. The previous SD card, SATA3 SSD, and HDD storage were replaced with NVMe GEN4 M.2 SSD and SATA3 SSD, reinforcing the analysis performance.
As a result, the number of virtual machines (VM) that can operate on Model B increased from 128 to 168 based on the equipment with the highest specifications, and the number of agents that the MDS can individually manage also increased from 5,000 to 6,000.
Furthermore, AhnLab MDS tenants can receive a malware expert analysis service. It is a charged service, but the first three sessions from the latest MDS firmware version launched in May this year will be provided for free. When the files collected by AhnLab MDS are uploaded through the malware expert analysis service, AhnLab's analysis expert checks the file and provides a report, including content on malware inflow paths, attack techniques, and response measures.
Conclusion
Preventing ransomware attacks is the utmost priority, as treatment or recovery after infection is difficult. First, key data must be backed up regularly and stored in a location separated from the Internet to prevent such attacks. All software must be updated to their latest versions, security software such as antivirus solutions must be installed, and scans must be performed periodically. Also, URL links from unknown sources must not be opened, and security vulnerability checks must be performed on corporate systems with the application of patches to ensure safety. Implementing AhnLab MDS, AhnLab MDS Agent, and AhnLab MDS Agent control services after complying with these security guidelines will allow companies to guard themselves more safely against ransomware based on AhnLab's professional malware analysis and response capabilities.