「勒索軟件」警號再響 ESET呼籲及時行動保護個人數碼資產

香港 – 2016年2月26日 –最近 ESET 研究人員發現「勒索軟件」(Ransomware)這種惡意軟件有再次肆虐的跡象。科技愈趨普及,幾乎每人都會把自己的檔案,例如相片、文件等儲存到電腦或手機,不法份子因而有機可乘,勒索您的數碼資產。

勒索軟件屬惡意軟件的一種,一旦入侵作業系統,會使用戶無法正常的開啟檔案,甚至失去對系統的控制權。簡言而之,就是透過病毒鎖住檔案,並留下勒索訊息,如要解鎖,就得向黑客付上「贖金」。而新型態的勒索軟件,更進一步由電腦走到 Android 智能手機的層面。唯有提高個人的安全意識,配合防毒軟件的定時更新,才是應對上策。

如何避免 

1. 慎防可疑電郵及附件,特別是壓縮檔(zip、rar)或執行檔(exe)。 
2. 切勿點擊可疑電郵內的網站連結。 
3. 使用可靠的防毒軟件,並定時更新。 
4. 定期為電腦或手機的作業系統安裝更新軟件。 
5. 定期為檔案備份,儘可能將檔案儲存至另一個安全的裝置。 

ESET NOD32防毒軟件,每4小時完整更新一次! ESET 病毒研究中心,每秒鐘無間斷收集世界各地出現的可疑病毒資料,並每4小時完整更新軟件的病毒資料庫;配合ESET Live Grid雲端偵測技術,如在下一個更新推送之前,發現並確認為屬於嚴重級別的病毒案例,即會將該病毒列入雲端系統的「黑名單」之中,用戶的電腦亦會自動與名單進行對比,大幅加強零時差的檢測和攔截表現。ESET 的進階記憶體掃描器及程式漏洞防護這兩項新技術,亦能強化ESET對這類「勒索」軟件的檢測。

有關ESET NOD32個人防毒軟件系列的詳細資料,請瀏覽網址: www.eset.hk/home/

關於Version 2 Limited

Version 2 Limited是亞洲最有活力的IT公司之一,公司發展及代理各種不同的互聯網、資訊科技、多媒體產品,其中包括通訊系統、安全、網絡、多媒體及消費市場產品。透過公司龐大的網絡、銷售點、分銷商及合作夥伴,Version 2 Limited 提供廣被市場讚賞的產品及服務。Version 2 Limited 的銷售網絡包括中國大陸、香港、澳門、台灣、新加坡等地區,客戶來自各行各業,包括全球1000大跨國企業、上市公司、公用機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於ESET

ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為「德勤高科技快速成長500 強」(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布里斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

Fitbit遭到黑客攻擊,對於可攜式設備和物聯網意味著什麼?

(1月13日更新):Fitbit 公司代表已經聯絡了ESET官方博客We Live Security,討論提供一份關於Fitbit 公司遭電腦黑客攻擊的陳述報告,該報告被安排在本文的結尾部分。

正如Fitbit公司所開發的其他裝置一樣,可攜式活動追蹤裝置是過去一年的假日季節中最暢銷的禮物,電腦黑客們似乎也正在關注。根據布萊恩·克雷布斯(Brian Krebs)及巴茲費德(Buzzfeed)的報告, Fitbit公司的一些帳戶近期發現被盜用。

該事件中,客戶帳戶資料庫/伺服器雖被盜用,但並未帶來大規模的損害,據說只是個人帳戶密碼被盜、被猜測或被攻擊。不法分子能夠從黑市獲得被盜用的記帳憑證,有時也能從電腦黑客處獲得被盜用的記帳憑證。這些電腦黑客能夠使用鍵盤記錄惡意軟體攻擊電腦,也能夠使用先前通過攻擊不同的電腦系統獲取的用戶名/密碼,並瞭解這些用戶名/密碼能否被用於目標網站。請注意,沒有任何跡象表明黑客從Fitbit公司系統中盜用了帳戶密碼或通過該公司的系統盜用了帳戶密碼。

當上述不法分子獲得帳戶後,就會篡改帳戶上的資訊,從而阻止帳戶的真正持有人成功登錄。然後,不法分子會使用其所盜用的帳戶,在設備的保修期內要求用新的設備取代 「出現錯誤」的設備。結果不出所料,較高端的設備也遭到了黑客攻擊。

正如克雷布斯先生報告的那樣,Fitbit的電腦資訊安全團隊近期將風險等級調整到適合未來需要的等級。克雷布斯先生引用了Fitbit公司的首席執行官馬克·鮑恩(Marc Bown)先生的講話:「如果我們發現帳戶的使用存在疑點,或者從一小部分人群中收到大量登錄帳戶的請求,我們將鎖定該帳戶,並讓客戶重新確認具體資訊。Fitbit公司已經制定了相關計劃,引入雙因素認證以對抗黑客通過Fitbit公司網站對Fitbit 公司帳戶進行的攻擊。

值得注意的是,雖然此前發生過一些攻擊(比如去年10月報告的對Fitbit公司的惡意軟體攻擊,但是Fitbit公司對於該攻擊事件存在爭議),但該起事件並不是對Fitbit公司設備的攻擊。雖然慣於攻擊保質期內設備的黑客們並未攻擊Fitbit公司的設備,但是該事件卻表明了人們為甚麼關注可攜式設備所生成資料的私隱,這些資料中的一部分具有很強的個人私隱。

很明顯,活動追蹤裝置需要建立一個安全的操作環境。這意味著這些追蹤裝置需要高於平均水準的安全操作環境,比如高於基本的「用戶名及密碼」認證。實際情況是Fitbit公司只是在最近才採用了上述的防禦手段,這表明生產線或許並未按照設計上規定的私隱保護原則進行建造。

可攜式設備的出現讓使用者設備與醫療設備的界限變得模糊,使得上述一切問題變得更為棘手。如果人們已經充分認識到可攜式設備設備技術能夠帶來的益處,那麼每個使用可攜式設備的人都應認真考慮制定一套設計原則以杜絕上述資訊安全危害。根據設計原則,向公眾出售儲存大量個人資訊的設備,這些個人資訊中包含健康資訊,然後將保護資料安全的責任推給公眾,這種做法讓人無法接受。對於任何用戶來說,不論他們在何種程度上掌握上述技術,設備的預設設置都應保護資料的安全性及私隱。

作為用戶,我們需要重視使用上述設備所帶來的風險,並應該清楚我們需要部分地承擔保護上述設備免遭黑客攻擊的責任。我們一定要遵守網路安全規則,相關内容如下:

– 在購買可攜式設備或安裝可攜式設備應用程式時,應在Google網站中輸入裝置或程式的名字以及黑客、詐騙、欺詐等字樣進行搜索,以此警惕那些已公佈的問題,並獲得更多相關資訊以最終決定是否購買該設備或應用程式。

– 建立您的可攜式設備及任何相關的線上帳戶時,使用隱蔽的用戶名及獨特的密碼,用戶名及密碼應不易被猜出。

– 仔細閱讀使用的任何設備及應用程式的保護個人私隱規定,明確知道生產上述設備及應用程式的公司能夠在何種程度上保護個人私隱。

– 如果認為某些特有功能或應用程式的提供商在保護私人資訊安全方面不夠可靠,有可能暴露個人敏感資訊,就不要使用該特有功能或應用程式。

可攜式設備的銷售商可以獲得以下經驗:預先制定應急計劃,從而當資料安全遭到破壞時,無論該破壞所影響的範圍如何,其都能夠採取適當措施加以應對。請記住,喜歡使用健康追蹤器的人也同樣是社交媒體的積極參與者。當出現問題時,資訊將傳播得非常快,而你需要獲得使用者的正面評價。

如果個人私隱方面出了問題,應進行比用戶檢查更為仔細的檢查。美國聯邦貿易委員會及美國食品及藥品管理局對該領域都進行了密切關注。可以找到關於可攜式設備及相關安全性問題的更多討論。

Fitbit公司的陳述
「說這起事件是Fitbit公司的電子郵件或伺服器遭受了黑客攻擊是不準確的。我們的調查結果發現未經授權的一方登錄了帳戶,該方使用了之前從其他與Fitbit無任何聯繫的協力廠商地址中盜取或盜用的證書(電子郵箱或密碼)」

 「我們非常重視我們客戶的帳戶安全,也立即採取了保護我們客戶的行動。我們重新為受到影響的客戶設置帳戶密碼,並要求這些客戶創建新的密碼。作為一種有效的方法,我們建議客戶避免重複使用與其電子郵箱或其他帳戶相關的密碼,因為如果使用了這些密碼,就會更容易受到上述種類的惡意攻擊。值得注意的是,當前此類帳戶侵權行為已經成為很多熱門網站及商業經營中的常見問題。」

ESET Virtualization Security Is Now Available

ESET’s new agentless security solution for VMware vShield environments avoids troublesome AV storms.

ESET®, a global pioneer in IT security for more than two decades, today announces the launch of ESET Virtualization Security. This brand new VMware vShield-based agentless solution combines an ESET Virtualization Security appliance with ESET Remote Administrator to deliver ESET’s award-winning scanning core allied with proven management capability.

ESET Virtualization Security will be available from today in all regions except North America, where it will be launched on March 1st, 2016.

According to a Gartner Magic Quadrant* survey in 2015, “about 75% of x86 server workloads are virtualized”.  Virtualization brings countless benefits to companies, but without adequate protection of virtual systems it can be more dangerous than it seems.

ESET Virtualization Security was developed to protect sensitive data and to solve the main problems that companies experience when adopting virtualization, such as unprotected virtual servers, the need for multiple vendors to protect physical and virtualized environments, potential performance impacts and complicated licensing.

 “ESET Virtualization Security was developed for virtualized environments, meaning that as a GUI-less appliance it is easy to deploy, set up and operate. Its trademark light system footprint make the solution ideal for avoiding AV storms,” said Michal Jankech, Product Manager at ESET. “Moreover, ESET Virtualization Security is easy to manage thanks to ESET Remote Administrator, which gives IT administrators unlimited access anywhere, anytime.” 

ESET Virtualization Security is compatible with VMware vSphere 5.0 + with installed vCloud Networking and Security. It is consistent with ESET’s next-generation business products and its web-based console ESET Remote Administrator.

Learn more about ESET Virtualization Security and visit on our site.

* Gartner Magic Quadrant for x86 Server Virtualization Infrastructure:http://www.gartner.com/technology/reprints.do?id=1-2JFZ1KP&ct=150715&st=sb

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET Releases Latest Version of ESET Remote Administrator

The service release of ESET Remote Administrator provides businesses with iOS device management, agentless security and ESET SysInspector®, a proven diagnostic tool.

ESET®, a global pioneer in proactive protection for more than two decades, today starts delivering to businesses its latest service release of ESET Remote Administrator. With features such as ESET Mobile Device Management for iOS and management of ESET Virtualization SecurityESET Remote Administrator now boasts even wider market appeal.

ESET Mobile Device Management for iOS allows customers to fully embrace the BYOD trend (Bring Your Own Device, i.e. allowing employees to use their own devices at work). Administrators can now conveniently configure the security-related settings of iOS devices alongside other devices in their business network.

ESET Mobile Device Management for iOS is easy to set up and allows administrators to manage, configure, remotely lock or even wipe mobile iOS devices,” said Michal Jankech, Business Product Manager at ESET. “Adding this feature to ESET’s remote management console makes ESET Remote Administrator a real single pane of glass for their environment.”

ESET Remote Administrator supports ESET Virtualization Security, ESET’s brand new product providing agentless protection for VMware vShield, which was launched today.

To manage and install ESET Virtualization Security in a network, administrators need only install a GUI-less ESET Virtualization Security Appliance in their VMware virtualized infrastructure and link it to ESET Remote Administrator. This will enable remote configuration of the solution and execution of tasks on virtual machines, which are protected in agentless form.

Moreover, ESET SysInspector® is now integrated into ESET Remote Administrator. This helps admins track-back security incidents and system changes for each endpoint, using ESET SysInspector’s snapshots.

ESET Remote Administrator is a platform-independent remote management console designed to minimize downtime, while allowing actions to be performed automatically based on dynamic group membership.

Learn more about ESET Remote Administrator or check out ESET’s complete offer for businesses.  

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET Earns ‘Top Rated’ Award from AV-Comparatives

ESET Smart Security 9 was named Top Rated in the AV-Comparatives Summary Report 2015, receiving six Advanced+ ratings from the independent testing organization.

AV-Comparatives, an independent anti-malware testing organization, today publishes its annual Summary Report 2015 summarizing its tests and providing a market-wide overview of security products.


ESET Smart Security 9 received six Advanced+ awards in 2015, won a Silver Award in the False Positives category and a Bronze in Proactive Protection. ESET products, along with five from other vendors, were awarded AV-Comparatives’ Top Rated badge.

“ESET has been a constant part of our Summary Reports since 2006. With each new version, ESET Smart Security retains its clean trademark detection and sustains its low performance impact. With improved graphic design and finger-friendly controls, we believe thatESET products are suitable for use on touchscreens,” said Andreas Clementi, CEO at AV-Comparatives.

In 2015, AV-Comparatives subjected 21 Windows security products from a range of vendors to rigorous investigation. All were tested for their ability to protect against real-world Internet threats, identify thousands of recent malicious programs, and provide protection without slowing down the PCs on which they ran. 

 Learn more about ESET or read more about ESET products in the AV-Comparatives’ Summary Report 2015.