Ransomware Activity to 2022

This is an archive of my earlier work. It’s important to be look back to see patterns and historical context. A lot happened in just a couple of years of rapid evolution.

  • Highly targeted attacks on corporations vs ransom individuals
  • Big Game Hunting – knowing how much that corporation can pay and scaling the demands higher
  • RaaS – Ransomware as a Service
  • Setting affiliates up for success with access brokering
  • The unholy trinity of cybercrime operators Emotet, Trickbot, QBot to get a stake in the game and deliver ransomware payloads
  • Ryuk: big targets especially hospitals and healthcare
  • Maze: the originator of extortion tactics to steal data then encrypt systems and threaten publication
  • Extortionist Ransomware
  • Name & Shame sites.
  • Nation states get in on the action
  • The rise and fall and rebirth of groups: Ryuk/Conti, Maze/Egregor
  • Add some DDoS in there for extra incentive
  • OMFG Egregor

Going into 2021, the landscape has changed a bit. There were a couple major takedowns with Netwalker and Egregor removed for now. Both were prolific in their attacks. Emotet malware was also taken down. But time will tell how long that lasts as TrickBot came back fairly quickly.

What should we expect this year? Ransomware operators will go where the money is, following the principle of pain pays. Expect to see more targeting of industry, manufacturing, refineries- where operational tech or OT is used over IT. And where downtime is damaging. These groups are targeting law firms and legal services more, not surprising given how valuable that data is.

Tracking the top ransomware groups and attacks from 2020 onward

From Unit42 report

Palo Alto’s Threat Intel specialist Unit42 have released their 2021 Ransomware Report. By the numbers:

  • 16 variants engage in double extortion, stealing data to force payment
  • Ransom amounts demanded doubled from $15 million in 2019 to $30 million in 2020
  • Ransom amounts paid doubled from a high of $5 million in 2019 to $10 million in 2020
  • The average ransom demand in 2020 was $312,493, tripling from $115,123 in 2019

Analysis of Darkside Ransomware and anatomy of attack per Varonis 03/18/2021

Ryuk ransomware self-spreads to other Windows LAN devices per Bleeping Computer O2/26/21

This new variant has wormlike capabilities so it can spread to other devices on that local network using scheduled tasks. Saw a lot of abuse of scheduled tasks by ransomware in 2020.

Hotarus Group ransomware gang hacks Ecuador’s Ministry of Finance and largest bank per Bleeping Computer 02/26/21 The group used commodity ransomware, Ronggolawe, and stole data. They claim access by compromising third party code used for the bank’s web apps. Lots of third party code compromise across 2020.