Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • The Simple, UGLY Truth of Ransomware current page
Link copied

The Simple, UGLY Truth of Ransomware

Jul 18, 2019
Author:
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor
Blog banner default
The Simple, UGLY Truth of Ransomware
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor

There is an ugly truth of ransomware that the cybersecurity community neglects to discuss. It is not about the crime committed, the cyber threat actors trying to monetize your misfortune, nor about the potential loss of systems or data. It is the simple fact that ransomware is really just a computer virus.

Regardless of whether you refer to it as malware or ransomware, it is essentially an undesirable program that you did not intend to execute and that has potentially dire consequences for your systems. As with most malware, it is a maliciously designed piece of software intended to compromise your systems by exploiting vulnerabilities, administrative rights, office macros, lateral movement, and social engineering to extract funds from your organization, or otherwise inflict harm.

So, What Does this Mean for Your Cyber Defense Plan?

As just another computer virus, ransomware must be treated as such. This is just a simple truth and why going above and beyond traditional virus countermeasures actually provides an effective cyber defense strategy that can prevent infection. Consider the following:

  1. Ransomware, despite have a unique name branded to it, is just a computer virus (the ugly truth)
  2. Computer viruses execute on a computer only if they have privileges to execute, leverage methods to launch remote code (MS Office Macros or PowerShell), or they exploit a vulnerability or misconfiguration (a realistic truth about how they infect a system).
  3. An unauthorized program, like ransomware, cannot execute on a host that has implemented good allow listing and block listing application control. This includes blocking anything not properly digitally signed (an honest truth about a possible defensive strategy).
  4. Ransomware is not traditionally a targeted attack. The weak are generally infected and, recently, state and local governments have been taking the brunt of the attacks due to aging systems, lack of funding, limited personnel resources, and poor basic cybersecurity practices (another ugly truth).

So, where does this leave the typical organization or information technology professional? Just remember the U.G.L.Y. truth:

  • U. is for Users: Ransomware succeeds because end users typically fall victim to their primary method of delivery, social engineering via phishing / spear phishing attacks. Educate and train your users to identify these malicious emails so they don’t fall victim to the malicious payloads.
  • G. is for Grant Access: Only grant access to trusted applications and properly digitally signed macros and PowerShell scripts. You can accomplish this by using application control technology. Application control can mute the viral portion of ransomware by stopping its execution from the start.
  • L. is for Least Privilege: Remove administrative rights from end users. In 2018, 81% of all Microsoft Vulnerabilities could be mitigated by removing administrative rights and exploits that are used to propagate ransomware can be stopped dead in their tracks too with this basic policy change. You can actually enforce least privilege and application control with the best endpoint privilege management solutions.
  • Y. is for You: You can be a victim of ransomware—no one is immune. Implementing these basic procedures in addition to cybersecurity fundamentals like vulnerability, patch, end-of-life, and configuration management. These will help ensure YOU are not a victim of ransomware.

And, the next time another ransomware attack is in the news, consider how UGLY it could be for your organization and what you can do to prevent it.

Latest Posts
  • Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Jun 12, 2026 Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Blog
    7m
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
Related
  • Privileged Password Management Explained Part 2: Managing Passwords & Attack Techniques
    Apr 27, 2017 Privileged Password Management Explained Part 2: Managing Passwords & Attack Techniques
    Blog
    1m
  • Passwordless Administration Explained
    Jul 6, 2020 Passwordless Administration Explained
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.