# The rising risk of encrypted malware
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2019-03-12
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: Why Financial Firms Need to Address the Threat of Encrypted
Meta Description: Learn how encryption, intended to safeguard sensitive data in the financial sector, is now being exploited by cybercriminals through hidden malware attacks.
URL: https://financedigest.com/the-rising-risk-of-encrypted-malwarehtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/fd071217-1-1-1736839099658-compressed.jpg)

By **Omar Yaacoubi,** CEO **,** Barac

The financial sector has long been a prime target for cybercriminals. The kudos associated with breaking into a financial organisation, coupled with lure of harvesting and selling on high-value customer data, means the industry finds itself under near-constant attack. According to the Government’s 2018 Cyber Security Breaches Survey, some 57 percent of financial services companies experienced a cybersecurity breach or attack in the previous year. Across all business sectors, the figure was considerably [lower](https://www.financedigest.com/eu-countries-consider-lower-gas-price-cap-documents.html "EU countries consider lower gas price cap – documents"), at 43 percent.

![Omar Yaacoubi](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/omar-yaacoubi-barac-jpeg-450x451-1736839099650-compressed.jpg)

Omar Yaacoubi

Financial firms understand that they are being singled out by the criminal underworld and spend a small fortune [protecting their networks from these attacks](https://www.financedigest.com/finance-industry-and-ddos-attacks-how-can-the-most-targeted-vertical-industry-protect-itself-from-ddos-attacks.html "Finance industry and DDoS attacks: how can the most targeted vertical industry protect itself from DDoS attacks?"). Encryption, in particular, has [emerged as a key](https://www.financedigest.com/cup-holder-market-emerging-industries-challenges-and-threats-faced-by-key-vendors-and-global-business-outlook-till-2031.html "Cup Holder Market Emerging industries, Challenges and Threats Faced by Key Vendors and Global Business Outlook till 2031") defence. It ensures that, even if a hacker does penetrate a network, they cannot access or make use of the sensitive data.

Moving to the cloud and the introduction of stricter [compliance regulations](https://www.financedigest.com/are-compliance-and-anti-money-laundering-aml-regulations-hurting-your-sales.html "Are compliance and anti-money laundering (AML) regulations hurting your sales?") and privacy laws – most notably, GDPR – has accelerated the adoption of encryption solutions. Google estimates that, this year, some 80 percent of internet traffic will be encrypted as organisations attempt to avoid the large fines associated with non-compliance and, of course, [protect their sensitive data](https://www.financedigest.com/modern-data-protection-how-organisations-can-protect-against-cyber-attacks.html "Modern Data Protection: How organisations can protect against cyber attacks") from external threat actors.

**Encryption [poses new security](https://www.financedigest.com/london-police-say-queens-funeral-poses-biggest-ever-security-test.html "London police say queen’s funeral poses biggest ever security test") risks**

While encryption undoubtedly [plays a critical role](https://www.financedigest.com/the-role-embedded-finance-systems-will-play-as-commerce-goes-increasingly-digital.html "The Role Embedded Finance Systems Will Play as Commerce Goes Increasingly Digital") in protecting financial and customer data, its growing popularity has spawned a new risk for the financial sector: encrypted malware.

Just as encrypted traffic makes it harder for [hackers to access valuable data](https://www.financedigest.com/frances-thales-says-hackers-claim-to-have-stolen-data.html "France’s Thales says hackers claim to have stolen data"), it also makes it more difficult for organisations to identify and block malware. PWC [estimates that by the end](https://www.financedigest.com/western-europe-medical-recruitment-market-is-estimated-to-be-valued-at-us-21-22-billion-by-the-end-of-2028.html "Western Europe Medical Recruitment Market is estimated to be valued at US$ 21.22 Billion by the end of 2028") of 2019, some 60 percent of all malware will be hidden inside encrypted traffic flows. Many organisations have seen this first-hand. A CIO survey by Vanson Bourne found that 90 percent of organisations had experienced – or expect to experience – a network attack using the commonly deployed Secure Sockets Layer (SSL) encryption or its successor, [Transport Layer Security](https://www.financedigest.com/transport-operator-go-ahead-flags-cyber-security-breach.html "Transport operator Go-Ahead flags cyber security breach") (TLS) encryption during the course of this year.

The biggest example is Equifax where hackers used the cover of SSL and encrypted traffic to exfiltrate the valuable [data in order to avoid](https://www.financedigest.com/the-race-to-avoid-data-dinosaur-extinction.html "THE RACE TO AVOID DATA DINOSAUR EXTINCTION") detection by the company’s security tools.

**Why encrypted malware is hard to spot**

Encrypted malware has become the hacker’s attack vector of choice because [traditional](https://www.financedigest.com/fiat-republic-the-specialist-baas-platform-that-bridges-the-gap-between-web3-and-traditional-banks-announces-it-has-become-an-electronic-money-institution-emi-in-the-uk.html "Fiat Republic, the specialist BaaS platform that bridges the gap between web3 and traditional banks, announces it has become an Electronic Money Institution (EMI) in the UK.") security tools have become ineffectual in protecting against it. Simply put, many of [today’s popular cybersecurity](https://www.financedigest.com/the-state-of-cybersecurity-in-todays-financial-services-sector.html "The state of cybersecurity in today’s financial services sector") solutions are unable to see inside encrypted traffic. To check for malicious code, they first have to decrypt all of the network traffic, before performing a scan, re-encrypting it and then forwarding the data packets on to the intended recipient. This process is the most commonly used approach to catch hidden malware, yet it comes with many flaws.

The decryption process is extremely [compute intensive and can negatively affect the performance of the network](https://www.financedigest.com/hackers-hit-italian-oil-company-enis-computer-networks.html "Hackers hit Italian oil company Eni’s computer networks"), limiting the capabilities of nearly all firewall and Intrusion Prevention Solutions (IPS) available on the market today. [Growing volumes of encrypted traffic](https://www.financedigest.com/traffic-management-systems-growing-at-a-cagr-of-22-5-for-2022-28.html "Traffic Management Systems growing at a CAGR of 22.5% for 2022 – 28") mean there are more and more data packets to decrypt, scan and re-encrypt. These increased loads can stop devices from functioning altogether. As a result, some organisations give up [following this process](https://www.financedigest.com/seven-golden-rules-to-follow-when-implementing-kyc-process.html "Seven golden rules to follow when implementing KYC process"), and allow encrypted traffic flows onto their networks without scanning for malware.

The same decryption [process](https://www.financedigest.com/how-decentralized-finance-can-aid-in-the-acquisition-process.html "How Decentralized Finance can aid in the acquisition process") could also be placing financial institutions in breach of the very compliance regulations that encryption was deployed to address. In decrypting the traffic, there will be a short period when the [data is in plaintext and visible to all, putting a mass amount of sensitive data at risk](https://www.financedigest.com/omicron-poses-very-high-risk-but-data-on-severity-limited.html "Omicron poses ‘very high’ risk but data on severity limited").

Decryption might not even be technically possible for too much longer. The introduction of the new Transport Layer Security (TLS) 1.3 protocol – which, includes stronger encryption [processes in order to prevent hackers from snooping on sensitive data](https://www.financedigest.com/crowdsourcing-of-data-to-drive-the-high-throughput-process-development-market.html "Crowdsourcing of data to drive the High Throughput Process Development Market") – will also prevent the decryption of traffic to search for malware. Whilst the previous TLS 1.2 protocol allowed for clients and servers to decrypt and scan traffic, the newer version, introduced in August 2018, has stricter regulations [meaning this ‘passive mode’ encryption is no longer](https://www.financedigest.com/why-fundraising-no-longer-means-kissing-a-lot-of-frogs.html "Why fundraising no longer means kissing a lot of frogs") possible.

**New problems require new solutions**

[Banks need](https://www.financedigest.com/could-the-npa-be-the-catalyst-banks-need-to-transform-their-payment-networks.html "Could the NPA be the catalyst banks need to transform their payment networks?") to find alternatives to decryption as a way of protecting against the hidden threat of encrypted malware. While many organisations are aware of the critical importance of investing in new technology for the future, it’s another thing to bite the bullet and adopt these types of solutions. Indeed, Accenture’s 2018 State of Cyber Resilience Report found that although 83 percent of organisations agree that new [technology is an essential](https://www.financedigest.com/why-anti-spoofing-fingerprint-technology-is-essential-for-the-continued-growth-of-digital-payments.html "Why anti-spoofing fingerprint technology is essential for the continued growth of digital payments") tool, only two out of five are investing in AI, machine learning and automation technologies.

Yet encrypted malware is one threat that can already be nullified by these new technologies.

Using machine learning techniques and behavioural analytics to scan the metadata of encrypted traffic (rather than the actual contents), new tools are emerging that learn the difference between ‘good’ and ‘bad’ traffic. This provides financial organisations with the ability to block encrypted malware without the [need](https://www.financedigest.com/global-crises-that-need-the-finance-industry.html "Global Crises That Need The Finance Industry") for decryption, all in real-time and with no concerns over compliance or network performance.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

