The average ransomware payment demanded by cybercriminals now tops $5.3 million, a 518% increase from last year, according to a new report from Palo Alto Networks’ Unit 42 consultants that investigated ransomware attacks in the first half of 2021.
Meanwhile, the average ransom paid reached $570,000, an 82% increase over 2020’s average paid of $312,000.
“We expect the ransomware crisis will continue to gain momentum over the coming months as cybercrime groups further hone tactics for coercing victims into paying and also develop new approaches for making attacks more disruptive,” the authors wrote in a blog post. “While we predict that ransoms will continue their upward trajectory, we do expect to see some gangs continue to focus on the low end of the market, regularly targeting small businesses that lack resources to invest heavily in cybersecurity.”
Palo Alto Networks Uncovers New Ransomware TrendsPalo Alto Networks’ Unit 42 researchers also detail a new trend they call “quadruple extortion,” as if double extortion ransomware attacks weren’t disturbing enough.
With double extortion, which became increasingly popular last year, attackers first encrypt data and demand victims pay a ransom to regain access to compromised systems. But then, they also steal that data and threaten to publicly release sensitive information and IP if the organization doesn’t pay up.
Quadruple extortion takes things two steps further. After the encryption and data exfiltration, the ransomware gang launches a denial-of-service attack that shuts down the victim’s public websites. And for step four — harassment — the criminals contact the organization’s customers, business partners, employees, and the media to let them know about the hack.
Ransomware’s crisis status and new tactics were also common themes throughout Black Hat last week, which included almost three dozen talks and panel discussions dedicated to ransomware and how to fight this ever-increasing threat.
“The ransomware crisis has intensified this year as cybercriminals implemented devious new cyber-extortion techniques, improved their hacking tools, and tweaked business models that helped the industry generate record ransoms in 2020,” said VMware’s Principal Cybersecurity Strategist Rick McElroy during a session about disrupting ransomware.
The Big Business of RansomwareMcElroy cited Atlas VPN’s data, which found cybercrime cost the world more than $1 trillion last year. Even more worrisome: Cybersecurity Ventures forecasts global cybercrime costs to hit $10.5 trillion by 2025.
“What they’ve done is created businesses,” McElroy said. “They understand their customers, they understand their products, and they also understand the intended targets.”
VMware’s 2021 Global Incident Response Threat Report, released early last week, found the severity of attacks thus far this year has skyrocketed, with destructive and zero-day attacks occurring 51% of the time, attackers deploying custom malware 52% of the time, and counter incident response occurring 61% of the time.
“You’ve dealing with a knife fight now,” said Tom Kellermann, VMware’s head of cybersecurity strategy who also sits on the U.S. Secret Service Cyber Investigations Advisory Board.
“You’re dealing with an adversary that refuses to leave the environment,” he added. “They are doing everything from wiping logs to undermining the efficacy of security controls to disabling those controls to all the way to the manipulation of time stamps.” In fact, VMware found that attackers manipulated time stamps in 58% of breaches. This is especially effective because it makes it more difficult for security teams to detect these attacks, and it also undermines the confidence that teams have in the data sets.
Defenders and security vendors need to make it harder for ransomware gangs to turn a profit, McElroy added. This includes using deception grids that divert attackers away from real corporate assets, segmenting networks to prevent lateral movement, deploying workload security tools, and conducting regular threat hunting.
“These steps will impact [attackers],” McElroy said. “They will have to go rewrite code. They will have to iterate, they will have figure out how to evade that technique you have on the defensive side. It’s too easy for them to work today. We’ve got to make them work way more manual than they are right now.”
Attackers ‘Uncomfortably Close to Critical Infrastructure’In a separate report, Accenture highlighted new ransomware trends as cybercriminals use more aggressive tactics to force victims to pay up. “The patterns have changed, and 2021 is looking very different from previous years,” said Patton Adams, strategic cyberthreat intelligence lead at Accenture, during a cyber threat landscape trends session at Black Hat.
“Ransomware actors are getting uncomfortably close to new targets that are part of critical infrastructure,” he continued, adding that the Colonial Pipeline attack is a “prime example,” and that these criminals increasingly target gateway services like virtual private networks (VPNs).
In the Colonial Pipeline breach, the ransomware gang used compromised VPN credentials to access the company’s IT system, not the operational technology (OT) control system that could shut down the physical fuel pipelines. However, “if they use VPN credentials that are compromised from an IT network, then in the future there’s nothing to prevent that same thing from happening directly to an OT network, and it’s very hard to detect that,” Adams said.
Threat actors have built an entire ecosystem around ransomware where they share and improve tactics on Dark Web forums and also buy and sell commodity malware, stolen credentials, and other tools to help them breach networks, he added.
But in addition to buying and selling malware on the Dark Web, cyber criminals are also misusing and pirating commercial technology like Cobalt Strike, which is a legitimate penetration testing product. “It’s hard to discern friend from foe when a threat actor is using a legitimate tool, and that makes detection difficult,” Adams said.
To identify maliscious Cobalt Strike in an organization’s environment, Adams suggests developing signatures from the Beacon backdoor watermark to increase threat visibility. “That way, if you identify all of the Cobalt Strike activity, then you can go and triage: Is this legitimate or is this not legitimate?”
When asked about the future of ransomware, Adams predicted “more of the same.” But, he added, “we can get through it if we get the right people on board and we prepare ourselves.”
Comments