Cisco's Talos intelligence team analyzed months of chat logs between Conti and Hive ransomware gangs and their victims, uncovering a willingness on behalf of those gangs to negotiate lower payments and overall poor operational security.
Conti and Hive are two of the biggest ransomware players. Talos' intelligence analysts noted in a blog post that through open source research they obtained more than 40 separate conversations from the two groups and analyzed the communication strategies, ransom negotiation styles, operational information, tactics, techniques, and procedures (TTPs).
The chat logs indicated that Conti determines ransom amounts based on the victim's annual revenue, but that the gangs always offered or accepted a reduced ransom amount. This showed a strong willingness to negotiate, with the initial ransom demand set as a starting point.
In some cases the reduced amounts were more than 74% of the initial demand. In one case, the group dropped the demand five times from $50 million to $1 million. The group also was also flexible on payment dates.
However, the Conti gangs did threaten to expose a victims data and also held firm on a final figure. The lowest amount in one case was $100,000.
“These behaviors suggest Conti operators are highly opportunistic cybercriminals who ultimately would prefer some payment as opposed to none, even if that means capitulating to repeated requests by the victim,” the Talos team wrote in the blog.
Hive actors also were open to ransom negotiations and willing to offer reductions. The chat logs indicate Hive typically asked for ransom demands valued at between 1% adn 2% of the victim’s annual revenue.
Both groups targeted entities indiscriminately, likely depending on their assessment of the easiest victim to compromise, Talos found.
Conti, Hive Differ in Communication StylesDespite similar negotiation styles, Conti’s communications with victims were more structured, formal, and scripted than Hive’s, the Talos team found.
Conti employed various marketing tactics such as holiday discounts and “IT support” to help prevent future attacks and also persuasion strategies based on fear and coercion. They reminded victims of the reputational, financial, legal, and regulatory damage from a data leak.
Hive actors, on the other hand, almost never used those tactics and their conversations structure varied. Hive actors exhibited poor operational security in the chat, revealing a surprising amount of information about its operation such as its encryption process, Talos pointed out.
Cisco Talos Offers Guidance on MitigationThe chat logs revealed that opportunistic actors like Conti and Hive groups “likely seek to compromise victims through the easiest and fastest means possible, which often include exploiting known vulnerabilities."
The Cisco Talos team suggests organizations implement a strong patch management system, keep systems up to date, monitor for suspicious network traffic, close unnecessary ports and services, and consider hardening devices.
Plus, “organizations should require employees to use multi-factor authentication (MFA) to provide a higher level of security and ensure that leaked or stolen credentials cannot be used to access systems and resources,” the team wrote.
Comments