Skip to content
NGTEdu Logo

NGTEdu

A PRODUCT OF NGTECH.CO.IN

NGTEdu Logo

NGTEdu

  • Home
  • Cyber Attacks
  • Malware
  • Vulnerabilities
  • Data Breach
  • Home
  • Cyber Attacks
  • The Evolving Threat of Ransomware
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

The Evolving Threat of Ransomware

4 years ago Tripwire Guest Authors
The Evolving Threat of Ransomware

Currently, ransomware is the most prominent cyber threat to businesses and individuals. Ransomware attacks are growing more prevalent as cybercriminals find new ways to profit from them. According to CyberEdge’s 2021 Cyberthreat Defense Report, 62% of organizations were victimized by ransomware in 2019—up from 56% in 2018 and 55% in 2017. This rise is arguably fueled by the dramatic increase in ransomware payments. More than half (58%) of ransomware victims paid a ransom last year, which is up from 45% in 2018 and 39% in 2017.

There are three key factors that make ransomware more profitable for attackers: cryptocurrencies, Ransomware as a Service (RaaS), and geopolitical safe-havens.

Cryptocurrencies provide a safe mechanism for threat actors to be paid while reducing the likelihood of authorities being able to track the money. All contemporary ransomware will ask the victim to send the ransom money to a cryptocurrency wallet address. Ransomware as a Service permits sophisticated ransomware gangs to sell their harmful services to anyone who wants to participate in this criminal enterprise. RaaS providers charge a percentage of the profit generated by the purchaser of the service. The malevolent organization “REvil” promoted RaaS by carrying out multiple ransomware attacks as well as supporting and giving tools to individuals interested in using its service.

Geopolitical safe havens allow governments to turn a blind eye to their citizens’ cybercrime activities as long as the cybercriminal isn’t targeting domestic companies or persons. Russia and China are the most notable countries in the geopolitical cybercriminal sector since they are notorious for not pursuing recognized cybercriminals for cyberattacks that they commit or assist in on a global scale.

Since the first incidence of ransomware in 1989, which is known as the “AIDS Trojan,” the threat of ransomware has evolved, aided by technological advancements and globalization. The AIDS Trojan demanded a $189 ransom payment from its victims in order to recover their data. While $189 may not seem like much, when compared to the time and effort spent developing the ransomware and the incurred risk, infecting many victims may drastically shift the motivation. In 2020, the average ransomware payment to threat actors was $200,000, with the highest reported payment being $40 million. Keep in mind that these figures may not be exact because they are based on publicly available information. For fear of damaging their public image and reputation, many corporations do not disclose these types of activities. Large ransoms, coupled with reduced or non-existent prosecutions, are an attractive incentive for threat actors.

How Ransomware Works

Ransomware is more than just the mere technical mechanics of unleashing malicious software to a wide audience and hoping for a payout to follow. The most successful ransomware criminals perform a lot of due diligence in order to maximize the payment.

Prior to an attack, threat actors perform reconnaissance on their target to learn about the infrastructure they are working with in order to discover exploitable flaws. Cybercriminals may spend months learning about their target, gaining a better understanding of a company’s operations. Certain vulnerabilities such as operating system flaws can be exploited by cybercriminals to deliver the harmful payload.

In many cases, the attackers will also aim to discover effective avenues of social engineering against the staff to unleash the ransomware. A social engineering operation will aim to influence an employee targets into unknowingly assisting the attacker.

Organized attackers will plan their assaults with care and patience, waiting for the right time to strike. The reconnaissance performed by the cybercriminals is the key to any successful instance of cybercrime.

Most ransomware is designed using public-key cryptography. Public-key cryptography is a cryptographic algorithm that encrypts and decrypts data using a pair of keys to prevent unwanted access or usage. Typically, ransomware encrypts as much of the victim’s data as possible using the public key, which can only be decrypted with the threat actor’s private key. The malicious actor will threaten and demand money from the victim in order to expedite the ransom procedure. The most common threats include deleting the victim’s data if they do not cooperate within a specific time frame, damaging the device, or publicly disclosing the victim’s data.

One of the reasons not to pay the ransom is because the victim cannot be certain that the threat actor will send a decryption key or keep the data private. While the victim cannot be certain that the threat actor will keep their part of the agreement, according to the CyberEdge Report, “Cybercriminals have learned that withholding data following payment receipt is bad for business.” Unfortunately, the usual reactions to ransomware have become a self-fulfilling prophecy, propelling ransomware’s influence over organizations. The three data sets that show the self-fulfilling cycle of ransomware are as follows:

“The ransomware vicious cycle: increased odds of recovering data … entice more victims to pay ransoms … which motivates more ransomware attacks.”
CyberEdge 2021 CDR Report v10 ISC2 Edition, page 21, figure 15.

Businesses need to prepare and protect themselves before they are victimized. One of the main goals in balancing risk management and cybersecurity isn’t to be invincible to cyber threats. The goal is to not be an easy target so that the criminal can find “easy pickings” elsewhere.

Today’s Ransomware

Not only has today’s malware evolved exponentially from prior incarnations, but it is also far more powerful and widespread than preceding ransomware variants. Due to characteristics incorporated by malware creators in the new varieties of ransomware, modern ransomware can have disastrous consequences and be more difficult to analyze and detect. Previously, ransomware such as the “AIDS Trojan” featured a simple workaround that allowed the victim to decrypt the symmetric key and avoid paying the ransom. Today’s malware, on the other hand, is far more sophisticated. One can imagine future ransomware with greater, more nefarious capabilities.

To protect against these types of risks as a corporation, a few cybersecurity fundamentals must be in place such as tools for avoiding, identifying, and remediating cyber threats. Basic cybersecurity fundamentals such as the principle of least privilege, separation and segregation of duties, secure on-boarding and off-boarding processes, multi-factor authentication, and cybersecurity awareness training are a few of the most crucial cybersecurity fundamentals that every firm should adopt.

Of course, Tripwire is here to help you on your organization’s journey to a robust cybersecurity
environment, as well.


Robin Chan

About the Author: Robin Chan is a 3rd-year student at Fanshawe College working towards an Ontario College Advanced Diploma in Cyber Security. When he’s not working or in school, he’s learning about various technologies and evolving IT threats, tinkering with tech, playing video games, and watching Studio Ghibli films.

LinkedIn

Editor’s Note: The opinions expressed in this guest author article are solely those of the contributor, and do not necessarily reflect those of Tripwire, Inc.

The post ” The Evolving Threat of Ransomware” appeared first on TripWire

Source:TripWire – Tripwire Guest Authors

Tags: Encryption, Finance, Malware, Medium Severity, Ransomware, TripWire

Continue Reading

Previous RedCurl Corporate Espionage Hackers Return With Updated Hacking Tools
Next VERT Research Tips: Understanding Word Splitting

More Stories

  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking, Malware Delivery

2 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

CISA Orders Removal of Unsupported Edge Devices to Reduce Federal Network Risk

3 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities

4 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach

How Samsung Knox Helps Stop Your Network Security Breach

6 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware

8 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Data Breach
  • Vulnerabilities

Claude Opus 4.6 Finds 500+ High-Severity Flaws Across Major Open-Source Libraries

11 hours ago [email protected] (The Hacker News)

Recent Posts

  • China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking, Malware Delivery
  • CISA Orders Removal of Unsupported Edge Devices to Reduce Federal Network Risk
  • Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities
  • How Samsung Knox Helps Stop Your Network Security Breach
  • Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware

Tags

Android APT Bug CERT Cloud Compliance Coronavirus COVID-19 Critical Severity Encryption Exploit Facebook Finance Google Google Chrome Goverment Hacker Hacker News High Severity Instagram iPhone Java Linux Low Severity Malware Medium Severity Microsoft Moderate Severity Mozzila Firefox Oracle Patch Tuesday Phishing Privacy QuickHeal Ransomware RAT Sim The Hacker News Threatpost TikTok TripWire VMWARE Vulnerability Whatsapp Zoom
Copyright © 2020 All rights reserved | NGTEdu.com
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Read More here.Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT