Despite a significant uptick in law enforcement takedowns over the last year, ransomware remains the top attack type, and its sophistication, aggressiveness, and impact are increasing as attackers followed enterprises moving the cloud, according to two recent reports by IBM X-Force and Fortinet’s FortiGuard Labs.
There were more law enforcement actions against ransomware gangs in 2021 than the course of multiple years prior, said Charles DeBeck, senior cyber threat intelligence analyst at IBM Security X-Force.
For example: a multi-government operation took down ransomware group REvil, which was responsible for 37% of all ransomware attacks in 2021. But the gang persisted over four years through rebrands, suggesting the likelihood of it resurfacing, according to IBM’s annual X-Force Threat Intelligence Index.
“The average lifespan of a ransomware group before shutting down or rebranding is about 17 months,” DeBeck said. This reminds the defender that most of the current active ransomware groups have a history, and that can be used to better inform the defense.
Plus, the lifespan means “we should focus less on specific brand names of ransomware, and more on broader tactics, techniques, and procedures,” he said, adding that using a zero-trust model can help protest against a whole array of attacks.
In general, in spite of active takedowns, IBM X-Force saw “no real signs of ransomware slowing down or stopping,” DeBeck said. “The big thing here is that we're seeing ransomware actors continuing to invest and be active in this space.”
As long as attackers continue to make a profit and upgrade their malware, “I don't think that ransomware is going to be going away anytime soon,” he added.
FortiGuard Labs’ data echoed IBM X-Force’s finding and showed the stride change. It reported a 10.7-time increase year over year in the number of sensors detecting ransomware variants in the first half of 2021, and ransomware remained at an elevated level over the second half of last year.
The latest FortiGuard Labs Global Threat Landscape Report also showed that some previously-seen ransomware strains were actively updated and enhanced, while others are evolving to adopt ransomware-as-as-service business models.
Attackers Follow Organizations Moving to CloudOver the last year, IBM X-Force observed early warning signs of cyber crisis in the cloud with a 146% increase in Linux ransomware that has new code.
“Organizations are continuing to move into cloud environments … threat actors are aware of this shift and are shifting in the same way,” DeBeck warned.
The threat researchers found “a dual focus component” for threat actors: they have been developing new malware to more effectively target the cloud while exploring new capabilities to leverage cloud environments for malicious activity, he added. “This indicates a medium to long term interest in targeting cloud environments,” DeBeck said.
In addition, X-Force found more attackers shifted their targets to containers like Docker and continued investment into Linux malware.
“We saw a whole host of new Docker-focused malware from botnets, to crypto miners, to other malware strains that are effective at taking advantage of Docker environments,” DeBeck said.
To address the threats in the cloud, DeBeck suggested using a penetration testing service, host-based or user-based analysis, and zero-trust architecture.
Comments