Ransomware continues to be the top security threat to corporations as cybercriminals cash in on COVID-19 themed campaigns.

In fact, VMware’s first United States-focused cybersecurity threat report ranks ransomware (13%) as the third most common cause of breaches in the U.S. behind OS vulnerabilities (27%) and web application attacks (13.5%).

And according to a slew of other recent cybersecurity reports as well as new high-profile attacks almost every day — such as the reported $10 million ransom attackers demanded from Garmin— ransomware doesn’t show any signs of slowing down during the second half of 2020.

SonicWall’s mid-year threat report found a 20% (121.4 million attacks) jump in ransomware globally in the first half of 2020 compared to mid-year 2019, with a staggering 109% (80 million attacks) spike in the United States during that same period.

While the threat researchers can’t definitely determine what’s causing the rise in attacks, they note that correlation between ransomware and the patterns of COVID-19 infections. In Asia, for example, which saw the first cases of the virus, ransomware spiked in January and March. Next, the pandemic hit Europe, and SonicWall reports corresponding spikes there in February and April.

Ransomware ‘Rifles, Not Shotgun Blasts’

In North America and particularly the U.S., COVID-19 rates are rising faster than ever. So is ransomware. “If this pattern holds true, North America may soon be dealing with the one-two punch of COVID-19 and rampant ransomware,” the report says.

On a video call with reporters, SonicWall CEO Bill Conner said ransomware has become more targeted with attackers using “rifles, they’re not doing shotgun blasts, and they’re getting much smarter.”

About 19% of the ransomware directly used COVID-19 or stay-at-home order themes to lure victims, Conner added. And attackers are not only asking for higher ransom amounts in the millions of dollars, but they are also stealing COVID-19 related intellectual property.

With employees working from home, “spear phishing just got a lot easier,” he said. “Ransomware is all about going in through an individual and then climbing into the organization. With more people working at home, spear phishing becomes more effective and efficient because it’s easier to get in.”

COVID-19 Expands the Attack Surface

Once attackers gain access to enterprise networks via, say, employees’ home devices, it tends to be easier for them to move laterally through the network and access corporate systems and applications because most companies don’t provide the same layered security and segmentation outside of the office.

“And couple that with they’re being way more strategic in their targets,” Conner said. “They know where they can get higher dollars. They are following the money. And right now, education, health care, and governments, state or local, are target-rich environments.”

While ransomware in the U.S. is much worse than any other country, Conner said he expects to see ransomware ramp up across Europe as cybercriminals target COVID-19 research and frontline organizations. “Most of the pharmaceuticals are in Germany and Switzerland. In Italy we do a lot with the advanced research there in pharma and in the secondary universities. I’m on weekly calls with some of those clients that literally are fighting this war, day by day, week by week, and almost every one of them are seeing the value of [SonicWall's Capture Advanced Threat Protection] and how this war is changing in real time.”

Double-Extortion Ransomware

Additionally, this illustrates a new tactic used by threat actors. “They’re not just encrypting the data and holding it for ransom, but they’re also exfiltrating the data, and then threatening to leak it if you don’t pay on time,” said Dmitriy Ayrapetov, VP of platform architecture at SonicWall. “And the European companies will probably be more vulnerable to that type of extortion because they are more directly subject to GDPR. You put double pressure on the victim: you’re not just holding up their data, but you’re also threatening to release their data and unleash further consequences on them.”

A new Check Point report also points to this type of double-extortion attack as a new form of ransomware that wasn’t widely used until this year. This trend is now used by most major cybercriminals, and it’s particularly egregious because it potentially turns every ransomware attack into a data breach. “Payment of the ransom money no longer guarantees the end of the attack as the victims can never be certain that the stolen information was actually deleted,” the report says.

In addition to storing stolen data for potential future use, the way attackers monetize ransomware attacks is changing, said CrowdStrike CTO Mike Sentonas. “We’re seeing examples of ransomware where the demands escalate the longer you wait to pay,” he said, adding that cyber criminals can ask for multi-million-dollar ransoms because they have done their homework.

“With these bigger attacks, the adversary has targeted the organization or the government department, they found an entry point into the organization and then escalated their credentials,” he said. “They’ve prepared the environment. And then when they ask for the demand, they’re ready to cause maximum damage. So managed hunting is critical today, even more than it ever was.”

Playing the Long Game

As their attacks become more sophisticated, ransomware actors are increasingly playing the long game, said Wendi Whitmore, VP of IBM X-Force, in a recent interview with SDxCentral. While the average time spent in companies’ IT environments before an attack used to be between 60 and 90 days, “now we’re seeing it more like three to six months that an attacker can stay in an organization observing things before they deploy the ransomware,” she said. “That additional time then gives them an opportunity to target a very specific department, for example, and know that the data that they’ve now taken was not backed up in other places. So they’re more confident in the [ransom] figures that they’re asking for.”

For this reason, Whitmore suggests companies develop ransomware-specific playbooks. IBM’s latest cloud security survey found that only one-third of companies with a formal security response plan (that’s 17% of total respondents) had also developed specific playbooks for common attack types. And among organizations using attack-specific playbooks, only 45% had plans for ransomware attacks, which IBM’s 2020 X-Force Threat Index found has spiked nearly 70% in recent years.

“If you have no other playbook, at least have one for ransomware,” Whitmore said. “Understand what you’re going to do, where your most sensitive data is, how it can be accessed, where it’s backed up, and ideally have it backed up in an offline capacity that’s not connected to the network so that you can have access to that in the event that it does become encrypted by a ransomware attack.”