{"id":8275,"date":"2025-04-29T14:49:09","date_gmt":"2025-04-29T07:49:09","guid":{"rendered":"https:\/\/pji.uma.ac.id\/?p=8275"},"modified":"2025-04-30T14:49:37","modified_gmt":"2025-04-30T07:49:37","slug":"ancaman-ransomware-2025-tren-taktik-dan-cara-menghadapinya","status":"publish","type":"post","link":"https:\/\/pji.uma.ac.id\/index.php\/2025\/04\/29\/ancaman-ransomware-2025-tren-taktik-dan-cara-menghadapinya\/","title":{"rendered":"Ancaman Ransomware 2025: Tren, Taktik, dan Cara Menghadapinya"},"content":{"rendered":"<p class=\"\" data-start=\"0\" data-end=\"246\">Ancaman ransomware di tahun 2025 menunjukkan perkembangan yang semakin kompleks dan merugikan. Berikut adalah rangkuman tren, taktik yang digunakan, serta langkah-langkah mitigasi yang direkomendasikan untuk menghadapi serangan ransomware modern:<\/p>\n<hr class=\"\" data-start=\"248\" data-end=\"251\" \/>\n<h2 class=\"\" data-start=\"253\" data-end=\"283\">\ud83d\udd25 <strong data-start=\"259\" data-end=\"283\">Tren Ransomware 2025<\/strong><\/h2>\n<ol data-start=\"285\" data-end=\"1269\">\n<li class=\"\" data-start=\"285\" data-end=\"546\">\n<p class=\"\" data-start=\"288\" data-end=\"319\"><strong data-start=\"288\" data-end=\"319\">Double dan Triple Extortion<\/strong><\/p>\n<ul data-start=\"323\" data-end=\"546\">\n<li class=\"\" data-start=\"323\" data-end=\"440\">\n<p class=\"\" data-start=\"325\" data-end=\"440\">Pelaku tidak hanya mengenkripsi data, tetapi juga mengancam untuk mempublikasikan data sensitif (double extortion).<\/p>\n<\/li>\n<li class=\"\" data-start=\"444\" data-end=\"546\">\n<p class=\"\" data-start=\"446\" data-end=\"546\">Beberapa kasus juga melibatkan ancaman kepada pelanggan atau mitra bisnis korban (triple extortion).<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li class=\"\" data-start=\"548\" data-end=\"742\">\n<p class=\"\" data-start=\"551\" data-end=\"585\"><strong data-start=\"551\" data-end=\"585\">Ransomware-as-a-Service (RaaS)<\/strong><\/p>\n<ul data-start=\"589\" data-end=\"742\">\n<li class=\"\" data-start=\"589\" data-end=\"742\">\n<p class=\"\" data-start=\"591\" data-end=\"742\">Model bisnis gelap ini memungkinkan aktor ancaman non-teknis untuk meluncurkan serangan melalui kit ransomware yang disediakan oleh pengembang malware.<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li class=\"\" data-start=\"744\" data-end=\"938\">\n<p class=\"\" data-start=\"747\" data-end=\"787\"><strong data-start=\"747\" data-end=\"787\">Targeting Infrastruktur Kritis &amp; SMB<\/strong><\/p>\n<ul data-start=\"791\" data-end=\"938\">\n<li class=\"\" data-start=\"791\" data-end=\"938\">\n<p class=\"\" data-start=\"793\" data-end=\"938\">Lembaga kesehatan, utilitas publik, dan bisnis kecil-menengah menjadi target utama karena sering kali memiliki pertahanan siber yang lebih lemah.<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li class=\"\" data-start=\"940\" data-end=\"1117\">\n<p class=\"\" data-start=\"943\" data-end=\"977\"><strong data-start=\"943\" data-end=\"977\">Pemanfaatan AI dan Otomatisasi<\/strong><\/p>\n<ul data-start=\"981\" data-end=\"1117\">\n<li class=\"\" data-start=\"981\" data-end=\"1117\">\n<p class=\"\" data-start=\"983\" data-end=\"1117\">Ransomware kini lebih cerdas dalam memilih file penting untuk disandera dan memanfaatkan AI untuk menghindari deteksi sistem keamanan.<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li class=\"\" data-start=\"1119\" data-end=\"1269\">\n<p class=\"\" data-start=\"1122\" data-end=\"1151\"><strong data-start=\"1122\" data-end=\"1151\">Eksfiltrasi Data ke Cloud<\/strong><\/p>\n<ul data-start=\"1155\" data-end=\"1269\">\n<li class=\"\" data-start=\"1155\" data-end=\"1269\">\n<p class=\"\" data-start=\"1157\" data-end=\"1269\">Data yang dicuri kini sering dipindahkan ke layanan cloud sebelum dienkripsi untuk mempercepat proses pemerasan.<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<hr class=\"\" data-start=\"1271\" data-end=\"1274\" \/>\n<h2 class=\"\" data-start=\"1276\" data-end=\"1319\">\ud83e\udde0 <strong data-start=\"1282\" data-end=\"1319\">Taktik Umum yang Digunakan Pelaku<\/strong><\/h2>\n<ol data-start=\"1321\" data-end=\"1989\">\n<li class=\"\" data-start=\"1321\" data-end=\"1435\">\n<p class=\"\" data-start=\"1324\" data-end=\"1361\"><strong data-start=\"1324\" data-end=\"1361\">Phishing dan Spear Phishing Email<\/strong><\/p>\n<ul data-start=\"1365\" data-end=\"1435\">\n<li class=\"\" data-start=\"1365\" data-end=\"1435\">\n<p class=\"\" data-start=\"1367\" data-end=\"1435\">Masih menjadi pintu masuk utama karena melibatkan kesalahan manusia.<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li class=\"\" data-start=\"1437\" data-end=\"1570\">\n<p class=\"\" data-start=\"1440\" data-end=\"1475\"><strong data-start=\"1440\" data-end=\"1475\">Eksploitasi Kerentanan Zero-Day<\/strong><\/p>\n<ul data-start=\"1479\" data-end=\"1570\">\n<li class=\"\" data-start=\"1479\" data-end=\"1570\">\n<p class=\"\" data-start=\"1481\" data-end=\"1570\">Aktor ancaman memanfaatkan celah keamanan perangkat lunak sebelum diperbaiki oleh vendor.<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li class=\"\" data-start=\"1572\" data-end=\"1703\">\n<p class=\"\" data-start=\"1575\" data-end=\"1612\"><strong data-start=\"1575\" data-end=\"1612\">Penggunaan Credential yang Dicuri<\/strong><\/p>\n<ul data-start=\"1616\" data-end=\"1703\">\n<li class=\"\" data-start=\"1616\" data-end=\"1703\">\n<p class=\"\" data-start=\"1618\" data-end=\"1703\">Akses awal sering kali didapatkan dari kredensial hasil kebocoran data atau phishing.<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li class=\"\" data-start=\"1705\" data-end=\"1828\">\n<p class=\"\" data-start=\"1708\" data-end=\"1743\"><strong data-start=\"1708\" data-end=\"1743\">Penyusupan Melalui Supply Chain<\/strong><\/p>\n<ul data-start=\"1747\" data-end=\"1828\">\n<li class=\"\" data-start=\"1747\" data-end=\"1828\">\n<p class=\"\" data-start=\"1749\" data-end=\"1828\">Serangan melalui vendor atau mitra bisnis yang memiliki akses ke sistem korban.<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li class=\"\" data-start=\"1830\" data-end=\"1989\">\n<p class=\"\" data-start=\"1833\" data-end=\"1876\"><strong data-start=\"1833\" data-end=\"1876\">Lateral Movement &amp; Privilege Escalation<\/strong><\/p>\n<ul data-start=\"1880\" data-end=\"1989\">\n<li class=\"\" data-start=\"1880\" data-end=\"1989\">\n<p class=\"\" data-start=\"1882\" data-end=\"1989\">Setelah masuk, pelaku menyebar ke seluruh jaringan dan meningkatkan hak akses untuk menguasai sistem kunci.<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<hr class=\"\" data-start=\"1991\" data-end=\"1994\" \/>\n<h2 class=\"\" data-start=\"1996\" data-end=\"2041\">\ud83d\udee1\ufe0f <strong data-start=\"2003\" data-end=\"2041\">Cara Efektif Menghadapi Ransomware<\/strong><\/h2>\n<h3 class=\"\" data-start=\"2043\" data-end=\"2064\">1. <strong data-start=\"2050\" data-end=\"2064\">Pencegahan<\/strong><\/h3>\n<ul data-start=\"2065\" data-end=\"2260\">\n<li class=\"\" data-start=\"2065\" data-end=\"2103\">\n<p class=\"\" data-start=\"2067\" data-end=\"2103\">Terapkan <strong data-start=\"2076\" data-end=\"2103\">Zero Trust Architecture<\/strong><\/p>\n<\/li>\n<li class=\"\" data-start=\"2104\" data-end=\"2151\">\n<p class=\"\" data-start=\"2106\" data-end=\"2151\">Gunakan <strong data-start=\"2114\" data-end=\"2151\">MFA (Multi-Factor Authentication)<\/strong><\/p>\n<\/li>\n<li class=\"\" data-start=\"2152\" data-end=\"2212\">\n<p class=\"\" data-start=\"2154\" data-end=\"2212\">Lakukan <strong data-start=\"2162\" data-end=\"2180\">patching rutin<\/strong> untuk semua sistem dan software<\/p>\n<\/li>\n<li class=\"\" data-start=\"2213\" data-end=\"2260\">\n<p class=\"\" data-start=\"2215\" data-end=\"2260\">Edukasi karyawan tentang ancaman <strong data-start=\"2248\" data-end=\"2260\">phishing<\/strong><\/p>\n<\/li>\n<\/ul>\n<h3 class=\"\" data-start=\"2262\" data-end=\"2297\">2. <strong data-start=\"2269\" data-end=\"2297\">Deteksi dan Respon Cepat<\/strong><\/h3>\n<ul data-start=\"2298\" data-end=\"2460\">\n<li class=\"\" data-start=\"2298\" data-end=\"2338\">\n<p class=\"\" data-start=\"2300\" data-end=\"2338\">Gunakan <strong data-start=\"2308\" data-end=\"2319\">EDR\/XDR<\/strong> untuk deteksi dini<\/p>\n<\/li>\n<li class=\"\" data-start=\"2339\" data-end=\"2388\">\n<p class=\"\" data-start=\"2341\" data-end=\"2388\">Monitoring log dan anomali secara <strong data-start=\"2375\" data-end=\"2388\">real-time<\/strong><\/p>\n<\/li>\n<li class=\"\" data-start=\"2389\" data-end=\"2460\">\n<p class=\"\" data-start=\"2391\" data-end=\"2460\">Siapkan <strong data-start=\"2399\" data-end=\"2425\">rencana respon insiden<\/strong> dan lakukan latihan secara berkala<\/p>\n<\/li>\n<\/ul>\n<h3 class=\"\" data-start=\"2462\" data-end=\"2495\">3. <strong data-start=\"2469\" data-end=\"2495\">Cadangan dan Pemulihan<\/strong><\/h3>\n<ul data-start=\"2496\" data-end=\"2636\">\n<li class=\"\" data-start=\"2496\" data-end=\"2585\">\n<p class=\"\" data-start=\"2498\" data-end=\"2585\"><strong data-start=\"2498\" data-end=\"2528\">Backup data secara berkala<\/strong>, terpisah dari jaringan utama (offline\/immutable backup)<\/p>\n<\/li>\n<li class=\"\" data-start=\"2586\" data-end=\"2636\">\n<p class=\"\" data-start=\"2588\" data-end=\"2636\">Uji kemampuan <strong data-start=\"2602\" data-end=\"2623\">disaster recovery<\/strong> secara rutin<\/p>\n<\/li>\n<\/ul>\n<h3 class=\"\" data-start=\"2638\" data-end=\"2673\">4. <strong data-start=\"2645\" data-end=\"2673\">Kerja Sama dan Pelaporan<\/strong><\/h3>\n<ul data-start=\"2674\" data-end=\"2824\">\n<li class=\"\" data-start=\"2674\" data-end=\"2750\">\n<p class=\"\" data-start=\"2676\" data-end=\"2750\">Laporkan serangan ke <strong data-start=\"2697\" data-end=\"2714\">CSIRT\/Kominfo<\/strong> atau lembaga keamanan siber terkait<\/p>\n<\/li>\n<li class=\"\" data-start=\"2751\" data-end=\"2824\">\n<p class=\"\" data-start=\"2753\" data-end=\"2824\">Bangun kerja sama dengan pihak ketiga untuk threat intelligence sharing<\/p>\n<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Ancaman ransomware di tahun 2025 menunjukkan perkembangan yang semakin kompleks dan merugikan. Berikut adalah rangkuman tren, taktik yang digunakan, serta langkah-langkah mitigasi yang direkomendasikan untuk menghadapi serangan ransomware modern: \ud83d\udd25 Tren Ransomware 2025 Double dan Triple Extortion Pelaku tidak hanya &hellip; <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[],"class_list":["post-8275","post","type-post","status-publish","format-standard","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/pji.uma.ac.id\/index.php\/wp-json\/wp\/v2\/posts\/8275","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pji.uma.ac.id\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pji.uma.ac.id\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pji.uma.ac.id\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/pji.uma.ac.id\/index.php\/wp-json\/wp\/v2\/comments?post=8275"}],"version-history":[{"count":1,"href":"https:\/\/pji.uma.ac.id\/index.php\/wp-json\/wp\/v2\/posts\/8275\/revisions"}],"predecessor-version":[{"id":8276,"href":"https:\/\/pji.uma.ac.id\/index.php\/wp-json\/wp\/v2\/posts\/8275\/revisions\/8276"}],"wp:attachment":[{"href":"https:\/\/pji.uma.ac.id\/index.php\/wp-json\/wp\/v2\/media?parent=8275"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pji.uma.ac.id\/index.php\/wp-json\/wp\/v2\/categories?post=8275"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pji.uma.ac.id\/index.php\/wp-json\/wp\/v2\/tags?post=8275"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}