TechBizWebTechBizWeb

    Subscribe to Updates

    Get the latest news about Technology and Business from all around the web..

    What's Hot

    Amazon says it has ‘hundreds’ of Rivian electric vans making deliveries in the US

    November 7, 2022

    Ryanair swings to first-half profit and raises passenger forecast

    November 7, 2022

    Devialet brings its sci-fi design aesthetics to a $790 portable speaker

    November 7, 2022
    Facebook Twitter Instagram
    • About Us
    • Privacy Policy
    • Guest Post
    • Terms
    • Contact
    Facebook Twitter Instagram
    TechBizWebTechBizWeb
    Subscribe
    • Home
    • Technology

      Amazon says it has ‘hundreds’ of Rivian electric vans making deliveries in the US

      November 7, 2022

      Devialet brings its sci-fi design aesthetics to a $790 portable speaker

      November 7, 2022

      Elon Musk’s response to fake verified Elon Twitter accounts: a new permanent ban policy for impersonation

      November 7, 2022

      The iPhone 14 Pro and Pro Max will come with ‘longer wait times’ due to factory lockdown

      November 6, 2022

      Meta’s reportedly planning to lay off ‘thousands’ of workers this week

      November 6, 2022
    • Business
    • Cyber Security
      National Security News

      List of 620 Russian spies, featuring one alleged agent at the centre of one of the biggest personal scandals in Wall Street history.

      September 24, 2022

      Cybersecurity ranked most serious enterprise risk in 2022

      August 31, 2022

      Registration open for CISA virtual summit on K-12 school safety

      August 31, 2022

      What do the Trickbot leaks reveal about Russian cybercrime?

      August 31, 2022

      What cybersecurity measures do CISOs outsource?

      August 30, 2022
    • Blockchain
    • Vulnerabilities
    • Social Engineering
    • Malware
    • Cyber Security Alerts
    TechBizWebTechBizWeb
    Home»Cyber Security»Increasing Involvement of Nation-states in Ransomware Attacks
    Cyber Security

    Increasing Involvement of Nation-states in Ransomware Attacks

    February 14, 2019Updated:February 14, 2019No Comments7 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Business is Now the Primary Target for Ransomware, and Nation-States are Among the Attackers

    The revenue gap in ransomware distribution is continuing to grow. The successful are getting more successful — but there are more and more unsuccessful ransomware campaigns. Successful ransomware tends to be targeted — typified by SamSam throughout the greater part of 2018. Spray and pray commodity ransomware, while still growing in numbers, is getting less successful in use.

    In his latest analysis of ransomware trends, Recorded Future’s threat intelligence analyst Allan Liska points out that the ransomware market is still growing, but the number of successful ransomwares is declining. He cites Cryptgh0st. “It was first discovered in May 2018 and by the end of August, virtually all mentions of the ransomware disappeared,” he writes. The bitcoin wallet associated with this ransomware shows only two incoming transactions — one for around $370 and the other for $6.

    Nevertheless, the market is growing in terms of numbers. In 2017, Recorded Future tracked 635 ransomware campaigns. In February 2018, the number had grown to 1,105 — and in January 2019 it had reached 1,463. But, says Liska, there are dozens of campaigns similar to Cryptgh0st, where the biggest noise comes from the fake ‘how to remove ransomware’ websites. 

    At the other end of the financial spectrum — the successful end — are the targeted campaigns aimed at specific organizations rather than consumers. Compare SamSam’s estimated profits of more than $5.9 million by mid-2018, to Cryptgh0st’s $376. The more elite and successful criminals are migrating from consumer ransomware to corporate network ransomware, often using RDP as the entry point.

    The only exception to this rule is GandCrab. GandCrab still spreads primarily via phishing and exploit kits — but it is unique. It is ransomware as a service focusing on consumer delivery backed by effective and efficient development. As anti-virus vendors get better at detecting and defending against it, the developers evolve their product and move on. For example, In October 2018, BitDefender released a decryptor for GandCrab versions 1, 4 and 5. But within 12 hours, a new version of the ransomware with no available decryptor was released.

    At the same time as BitDefender released its decryptor, it blogged, “Considering the lowest ransom note is $600 and almost half of infected victims give in to ransomware, the developers might have made at least $300 million in the past couple of months alone.” Liska thinks this estimate may be a little high. “I think their estimate is… optimistic,” he told SecurityWeek, “but it wouldn’t surprise me if they earned in the $100 million range.”

    Whichever figure is correct, GandCrab is an immensely successful ransomware, dwarfing even SamSam’s income. “The team behind GandCrab doesn’t appear to be slowing down at all,” warns Liska, “so expect to see more from them in 2019.”

    Apart from GandCrab, the ransomwares that thrived in 2018 were the targeted attacks from malware such as SamSam, BitPaymer and CrySiS. The most common entry point was via RDP. “Once the attackers have successfully gained access to the exposed system, they use it as a jumping off point into the core of the network, installing their ransomware onto target machines and often disabling backups and other protections.”

    The iconic SamSam attack is that against the City of Atlanta in early 2018. Atlanta declined to pay a ransom believed to be set at around $50,000 — but the disruption caused has been extensive. The city has estimated that incident response and security overhaul costs could hit $17 million. Cities are, to a certain extent, replacing healthcare as the target of choice. Liska told SecurityWeek that healthcare has had the budget to fix its security issues, and has become a harder target. Cities, however, are notoriously bad at security, and the politicians have been reluctant to spend taxpayer dollars on ‘invisible’ projects.

    Two relatively new trends that Liska expects to expand are blended ransomware attacks, and an increasing involvement of nation-states in ransomware attacks. He does not believe that nation-states will directly attack the utility side of the critical infrastructure for fear of cyber or even kinetic reprisals from the West. However, sanction-affected states — such as North Korea — will use ransomware as a way of generating funds. They will also likely experiment with ransomware as a wiper attack tool; but will be very careful where, and even if, such tools will be used.

    This makes WannaCry interesting. The WannaCry outbreak is believed — Liska has no doubt of it — to be the work of the North Korean Lazarus group. Lazarus, he suggests, is really the collective name for multiple North Korean government hacking groups. WannaCry appears to be contrary to his belief that nation-states will be careful in their use of destructive malware. “I suspect,” he told SecurityWeek, “that it was effectively a proof of concept that got away from its developers.” This would explain the existence of the kill switch, and the poor coding of the ransom collection part of the initial WannaCry. It does, however, show the potential of ransomware used as a destructive weapon.

    Despite sanctions against Iran, Liska does not believe that SamSam has any connection to the Iranian government. Notably, there has been no SamSam incidents since the U.S. government indicted two Iranian citizens. The indictment does not link the two to the Iranian state. Perhaps more tellingly, an earlier investigation by Recorded Future into Iranian hacker forums — the Iranian government’s recruiting ground for its own hackers — showed no trace of this pair. “I don’t believe SamSam or its developers were attached to the Iranian state apparatus,” Liska told SecurityWeek; “but I think the two people concerned may well be in the future.”

    The second development is the growing use of targeted and blended ransomware attacks. Here ransomware is added to the mix of malware installed on a compromised network. Its primary purpose is not the ransom, but to create a distraction and possibly destroy forensic evidence on discovery. Liska expects to see this use of ransomware to grow. Where the attacker is a nation-state group, he expects the developers to borrow code from the criminal world. “Nation-state actors may very well use cybercriminal code to build their ransomware variants,” he writes.

    The primary purpose will be to obfuscate the source of the attack — and he cites the confusion over the source of Ryuk attacks as an example. Ryuk shares code with Hermes, which has been used by Lazarus. Many people immediately assumed that Ryuk must also be linked to Lazarus. “However,” writes Liska, “further research determined that the Ryuk actors are most likely located in Russia and they had built Ryuk ransomware using (most likely stolen) Hermes code.”

    The key takeaway from Recorded Future’s analysis of ransomware trends is that any appearance that the ransomware threat may be diminishing because of reducing effectiveness against consumers would be a dangerous assumption for business. Ransomware is migrating from consumers to business. This isn’t a new observation; but Liska points out that it is not merely migrating, it is becoming more sophisticated and is attracting the attention of elite nation-state actors.

    Related: SamSam and GandCrab Illustrate Evolution of Ransomware 

    Related: The Evolution of Ransomware: Part 1 

    Related: The Evolution of Ransomware: Part 2 

    Related: The Rapid Evolution of Ransomware in the Enterprise 

    Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

    Previous Columns by Kevin Townsend:
    Tags:



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    National Security News

    List of 620 Russian spies, featuring one alleged agent at the centre of one of the biggest personal scandals in Wall Street history.

    September 24, 2022 Cyber Security

    Cybersecurity ranked most serious enterprise risk in 2022

    August 31, 2022 Cyber Security

    Registration open for CISA virtual summit on K-12 school safety

    August 31, 2022 Cyber Security

    What do the Trickbot leaks reveal about Russian cybercrime?

    August 31, 2022 Cyber Security

    What cybersecurity measures do CISOs outsource?

    August 30, 2022 Cyber Security

    SIA announces Women in Security Forum scholarship recipients

    August 30, 2022 Cyber Security
    Editors Picks

    Ryanair swings to first-half profit and raises passenger forecast

    November 7, 2022

    Devialet brings its sci-fi design aesthetics to a $790 portable speaker

    November 7, 2022

    Google Cloud Says Running Validator on Solana Blockchain

    November 7, 2022

    European stocks rise as investors boosted by China speculation

    November 7, 2022
    Trending Now

    Evergrande creditors sell ‘Versailles mansion’ plot in Hong Kong

    By techbizweb

    OpenSea Creates Tool for NFT Creators to Enforce Royalties On-Chain

    By techbizweb

    FTSE chairs warn of declining relations with institutional investors

    By techbizweb

    https://www.nationalsportsacademy.com

    slot gacor hari ini

    http://www.inadesfo.org/

    http://www.eueomgbissau.org/

    http://www.congo-mai-mai.net/

    http://www.angelesdelafrontera.org/

    http://fifaworldcup2018schedule.com/

    http://tony4gtrmcr.co.uk/

    http://www.standrewsagreement.org/

    http://www.bob-russell.co.uk/

    http://davidmulholland.co.uk/

    http://railwayhotelenniskillen.com/

    http://www.fantasysportstrades.com/

    http://www.rainleaf-flooring.com

    http://mothersagainstguns.org/

    http://ma-coc.org/

    slot online

    http://www.paradoxmag.com/situs-judi-slot-online-gampang-menang-2021/

    http://www.paradoxmag.com/situs-judi-slot-online-terbaru-2021/

    http://slot-terbaru.net/

    Slot Gacor

    Slot Online

    Situs Slot Gacor

    http://www.appdexterity.com/

    https://cars4kids-deutschland.de/

    https://www.stretchingculture.com/

    https://www.b-123-hp.com/slot-gacor/

    https://denzstaffing.nl/

    https://ezbbqcooking.com/slot-gacor/

    https://www.mbahelp24.com/slot-gacor

    https://minhtanstore.com/slot-jackpot-terbesar/

    https://njbpusupplierdiversity.com/slot-gacor-gampang-menang/

    https://www.floridaspecialtycropfoundation.org/slot-gampang-menang/

    https://childrenscornerpreschool.org/slot-gacor-gampang-menang/

    https://cryptoquoter.com/slot-online-terbaik/

    https://alorkantho24.com/slot-gacor/

    https://ellas.xyz/slot-gacor/

    https://it.dougamatome.xyz/slot-online/

    https://www.daltercume.com/slot-gacor/

    https://josi-ana.dougamatome.xyz/slot88/

    https://josi-ana.dougamatome.xyz/slot-gacor/

    https://fastobserver.com/slot-jackpot-terbesar/

    https://www.planetexperts.com/slot-gacor/

    https://bfsolution.group/slot-bet-kecil/

    https://rustleva.co/slot/

    https://bfsolution.group/slot-bet-kecil/

    https://www.hotelcalimareal.com/togel-online/

    https://anime-game.dougamatome.xyz/slot-gacor-gampang-menang/

    https://anime-game.dougamatome.xyz/togel-online/

    https://bourbonbarrelfoods.com/slot/

    http://suneo39.wp.xdomain.jp/slot/

    https://techbizweb.com/slot-gacor/

    https://www.generalcatalyst.com/18-daftar-slot-gacor-terbaik-gampang-menang-jackpot-hari-ini/

    https://www.hotelcalimareal.com/slot-online/

    https://www.blockgates.io/slot-gacor/

    https://l12.com.br/slot-gacor/

    slot paling gacor

    https://www.donalds-hobby.com/slot-online/

    https://thecryptodirt.com/slot-gacor-hari-ini/

    http://iseta.edu.ar/aulavirtual/app/upload/users/1/1205/my_files/sbobet.html

    http://escuelavirtual.mincit.gov.co/app/upload/users/1/194/my_files/slot.html

    https://www.dev.medecinesfax.org/courses/JUDICASINO/document/slot.html

    http://www.e-archivos.org/cursos/courses/JUDICASINO/document/slot-gacor.html

    http://iesma.com.br/ead/main/upload/users/4/447/my_files/slot.html

    https://www.fundacoop.org/chamilo/app/upload/users/1/1185/my_files/slot.html

    https://fata-aatf.org/eskola/main/upload/users/3/31/my_files/slot.html

    https://uancv.edu.pe/ofinvestigacion/app/upload/users/3/328/my_files/slot-terlengkap.html

    https://micost.edu.my/EL/app/upload/users/2/209/my_files/slot-gacor.html

    https://www.academiacoderdojo.ro/elearningdev/app/upload/users/2/2442/my_files/slot-online.html

    http://campus-cidci.ulg.ac.be/courses/JUDICASINO/document/slot-termurah.html

    https://www.escueladerobotica.misiones.gob.ar/aula-ste/courses/LIVECASINO/document/slot-tergacor.html

    http://ccdipeepccqqfar.usac.edu.gt/chamilo/app/upload/users/3/358/my_files/slot-online.html

    https://cunori.edu.gt/campus/app/upload/users/7/7334/my_files/slot-online.html

    http://u-rus.com.ar/aula/app/upload/users/1/1322/my_files/slot.html

    http://icrodarisoveria.edu.it/chamilo/app/upload/users/1/1855/my_files/slot.html

    https://iestpliliagutierrez.edu.pe/clarolgm/courses/CASINO/document/slot.html

    http://pva.cobach.edu.mx/app/upload/users/7/7379/my_files/slot.html

    http://www.imb-pc-online.edu.gt/PL/app/upload/users/3/373/my_files/slot.html

    http://avcs.upeu.edu.pe/main/upload/users/3333/my_files/slot.html

    https://chamilo.fca.uas.edu.mx/app/upload/users/1/11186/my_files/slot-online/

    TechBizWeb
    Facebook Twitter Instagram Pinterest Vimeo YouTube
    • Home
    • Guest Post
    • About Us
    • Privacy Policy
    • Our Authors
    • Terms and Conditions
    • Contact
    © 2023 Tech Biz Web. Developed by Sawah Dev.

    Type above and press Enter to search. Press Esc to cancel.