Previous All Posts Next

PayPal's New Ransomware Detection

Posted: April 23, 2019 to Cybersecurity.

Tags: Ransomware, Data Breach, Malware

By now everyone should know that ransomware is a huge threat. PayPal aims to do something about that. What we can figure out from the patent filed by the online transaction company is that PayPal seems to have found a way to detect ransomware before all your files are locked away, and in that time they can either prevent the encryption process or they can make copies of files and store them safely away before they get encrypted. How does PayPal intend to detect ransomware before it springs into action? A lot of ransomware variants follow the same general pattern: They duplicate a file, encrypting the new one, then delete the original. PayPal's new anti-ransomware will watch for files to be loaded in the memory cache and look for the usual file shenanigans ransomware undertakes, allowing only processes that are on a whitelist to go through while blocking processes that are not on the list.
Craig Petronella
Craig Petronella
CEO & Founder, Petronella Technology Group | CMMC Registered Practitioner

Craig Petronella is a cybersecurity expert with over 24 years of experience protecting businesses from cyber threats. As founder of Petronella Technology Group, he has helped over 2,500 organizations strengthen their security posture, achieve compliance, and respond to incidents.

Related Service
Protect Your Business with Our Cybersecurity Services

Our proprietary 39-layer ZeroHack cybersecurity stack defends your organization 24/7.

Explore Cybersecurity Services
Previous All Posts Next