Vietnam Newsroom & Threat Intelligence
Clear sources · Careful assessments
NOTEDo not attribute a ransomware family from a file extension or a single ransom note.Vietnam time · UTC+7
No.Ransomware.VN

Ransomware prevention

Prepare with testable controls, practical knowledge and regular exercises.

Backup 3-2-1-1-0Secure configurationRDP securityNAS securityESXi securityMFA and privileged accountsIncident responseOperations checklistTabletop exerciseUser awareness
Education & awareness

No.Ransomware.VN is the initiative's education and prevention branch. Adapt these checklists to each organization's assets, staffing and operational capabilities.

No Ransomware initiative
Prevention

Keep multiple copies of data with appropriate separation. Test recovery regularly and record unresolved errors.

  • Identify the data and recovery point required.
  • Separate backup administration privileges from everyday accounts.
  • Test application and data recovery in an isolated environment.
Prevention

Reduce unnecessary functions and manage changes by asset.

  • Inventory operating systems, services and responsible owners.
  • Apply patches according to vendor guidance and check compatibility.
  • Monitor configuration changes and special privileges.
Prevention

Control remote access according to business needs.

  • Avoid exposing RDP directly to the Internet.
  • Use a managed access gateway, MFA and appropriate source restrictions.
  • Monitor failed and anomalous logins and unused accounts.
Prevention

Protect both the data and the device management interfaces.

  • Review accounts, applications and administration ports.
  • Restrict administrative access to trusted networks.
  • Check snapshots and independent copies against the actual permission model.
Prevention

Treat the hypervisor as a critical system component.

  • Inventory versions and relevant security notices.
  • Review administrator groups, directory integration and account permissions.
  • Store logs outside the host and practice virtual machine recovery.
Prevention

Apply MFA together with account lifecycle management.

  • Prioritize phishing-resistant methods where supported.
  • Control recovery methods and exception accounts.
  • Revoke sessions and privileges when personnel or roles change.
Prevention

Prepare roles, communication channels and decision-recording procedures.

  • Isolate affected connections according to the response procedure.
  • Preserve evidence before actions that could alter data.
  • Assess the scope before reconnecting recovered systems.
Prevention

Turn requirements into tasks with an owner and evidence of completion.

  • Record the asset, review date, result and outstanding gaps.
  • Prioritize controls that protect critical systems.
  • Review again after architectural changes or an incident.
Prevention

Practice decisions before handling a real incident.

  • Choose a scenario involving loss of access to systems or backups.
  • Assign technical, operations, management and communications roles.
  • Record bottlenecks, responsible owners and a date for the next exercise.
Prevention

Help people recognize reportable warning signs and know whom to contact.

  • Explain how to verify unusual login or file-transfer requests.
  • Provide an easy-to-use, blame-free reporting channel.
  • Do not ask staff to open suspected malware samples themselves.
Ransomware prevention requires multiple layers of control rather than reliance on a single security product. The priorities are reducing entry points, limiting privileges, detecting activity early, protecting backups and practicing recovery under realistic conditions.

Reduce the attack surface

Enable MFA, patch internet-facing systems, restrict RDP/VPN and control privileged accounts.

Limit the extent of damage

Segment networks, separate backup accounts and apply least privilege.

A backup must be recoverable

Apply 3-2-1-1-0, use offline or immutable copies and test restores regularly.

Understanding ransomware
CISA — #StopRansomware GuideGuidance on prevention, response and recovery.
Veeam — Protect: the 3-2-1-1-0 backup ruleThe vendor's backup design guidance.
Microsoft Threat Intelligence — CVE-2024-3708529/07/2024 · Analysis of ESXi exploitation observed by Microsoft.

Each source's scope and date are recorded separately when available. A citation does not independently verify every assessment.