One of the most active ransomware gangs — LockBit — updated its ransomware strain earlier this year to include new tactics and a bug bounty program, highlighting changes to the threat landscape transiting into a cybercrime-as-a-service economy.

Ransomware has increasingly become an important tool used by organized crime gangs to extort money, Ryan Kovar, distinguished security strategist and leader of Splunk SURGe security research team, told SDxCentral. “It's very effective, but it's only one of them.”

Many ransomware groups are moving toward double extortion in which attackers first encrypt data and demand victims pay a ransom to regain access to compromised systems. They then also steal that data and threaten to publicly release sensitive information if the organization doesn’t pay up.

“I think we're even going to move into a phase, if we haven't already, where they're going to skip the ransomware altogether and just go straight to the extortion, and then we won't hear about it because businesses will probably just pay,” Kovar said. “At that point, you're not even dealing with ransomware, it's just crime.”

Kovar added that people should stop talking about ransomware and instead say "that this is crimeware weaponization.”

Cybercrime-as-a-service is sophisticated, as the ecosystem includes different criminal organizations and third parties for perpetration, spearfishing, data theft, ransomware binary installing, and extortion. 

Kovar suggests defenders “stop thinking about this as a separate problem and start looking at this as an identical solution for what they're already implementing to defend against traditional networks.”

“The biggest thing is people seem very consistently trying to find a silver bullet for ransomware and I think if the silver bullet exists it is eating your cyber vegetables: MFA, patching, doing the hard work of just really good practitioner things,” he said, adding that organizations should also make sure they have qualitative risk assessment and disaster recovery plans. 

LockBit’s Bug Bounty Program

LockBit was the first ransomware-as-a-service operation to offer a bug bounty program. It rewards $1,000 to $1 million for reporting bugs in its website (cross-site scripting or XSS), locker (encryption), vulnerabilities in Tox messenger, and the Tor Network. 

Kovar hasn’t seen a big impact on this program since it launched in June. “I have seen a lot of talk about it. I haven't seen anyone actually claim that they've got paid off, which I think makes a lot of sense because you may not want to go ahead and tell the FBI that you've been collaborating with crimeware gangs.”

“I haven't seen a big impact other than I have seen some vendors almost shamed by the costs of their own bug bounty program,” he added. But, “it's very easy for the bug bounty program of LockBit to be a very high number because who's ever gonna say that they got paid off by it? So I think it's a little bit of a trade off.”

The gang aims to use this program to help remain on top of the competition. Kovar doubts if other gangs are at the same business sophistication level as LockBit.

SURGe’s recent research showed that LockBit was the fastest variant among the 10 major ransomware strains to encrypt on any system, with speeds 86% faster than the median. The fastest sample encrypted close to 25,000 files per minute.

“The marketing and the business side of LockBit is arguably the most advanced of the ransomware gangs that are public,” Kovar said, adding that while others don't appear to be as advanced, it “doesn't mean it isn't happening.”