{"id":43277,"date":"2021-05-19T10:43:00","date_gmt":"2021-05-19T02:43:00","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=43277"},"modified":"2021-05-18T13:45:31","modified_gmt":"2021-05-18T05:45:31","slug":"kaspersky-sheds-light-on-ransomware-ecosystem","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2021\/05\/19\/kaspersky-sheds-light-on-ransomware-ecosystem\/","title":{"rendered":"Kaspersky sheds light on ransomware ecosystem"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Ransomware is on the tip of everyone\u2019s tongue every time businesses discuss cyberthreats they are likely to face in 2021. Attackers have built their brands and are bold in their advances like never before, with the news about organizations being hit with ransomware consistently on newspaper front pages. But by placing themselves under the spotlight, such groups hide the actual complexity of the ransomware ecosystem.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To help organizations understand how the ransomware ecosystem operates and how to fight it, the latest report by Kaspersky researchers dug into darknet forums, took a deep look at REvil and Babuk gangs and beyond and debunked some of the myths about ransomware. And when you dig into this underworld, you have to expect that it has many faces.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Like any industry, the ransomware ecosystem comprises many players that take on various roles. Contrary to the belief that ransomware gang are actually gangs \u2013 tight, have been through it all together, Godfather-style groups, the reality is more akin to the world of Guy Ritchie\u2019s \u201cThe Gentlemen\u201d, with a significant number of different actors \u2013 developers, botmasters, access sellers, ransomware operators \u2013 involved in most attacks, supplying services to each other through dark web marketplaces.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These actors meet on specialized darknet forums where one can find regularly updated ads offering services and partnerships. Prominent big-game players that operate on their own do not frequent such sites, however, well-known groups such as REvil that have increasingly targeted organizations in the past few quarters, publicize their offers and news on a regular basis using affiliate programs. This type of involvement presumes a partnership between the ransomware group operator and the affiliate with the ransomware operator taking a profit share ranging from 20-40%, while the remaining 60-80% stays with the affiliate.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/ecp.yusercontent.com\/mail?url=https%3A%2F%2Flh5.googleusercontent.com%2Fom2SQWWNq_IWDS_cUyMZvo66--WF2InN-pubQUCjAr0sUH5NJU8z95usDCSa9tQKShMEjl7wph4Avge-DUu-Bxdt94PhcrTQXH_FHsHIWsZOp0jaBUSmj_lJZbcd9QMLQgUx9fJa&amp;t=1621316253&amp;ymreqid=27f3344f-c727-c29c-1cc2-cd0094016e00&amp;sig=BsXBa6Sk4lNOPg0E1o_rlg--~D\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><em>REvil announces a new capability to organize calls to the media and target\u2019s partners to assert additional pressure on paying the ransom<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/ecp.yusercontent.com\/mail?url=https%3A%2F%2Flh4.googleusercontent.com%2FPsxABPF47b11ZtHp75MdY_-QkPk89IxdJF37AOkyRZ-6-IOG0sx8yy9BL2Hanpmu9TdJ-EpgYI3wLzHPlzCSJOzt3ctazKaZ3Vb_gRYw10Iazzpwuy_SIGvOEPoICPZKjE_5W85N&amp;t=1621316253&amp;ymreqid=27f3344f-c727-c29c-1cc2-cd0094016e00&amp;sig=_qO2dB1r_9U.Q4Qr_re9Vw--~D\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Examples of offers listing payment conditions in the partner programs<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Selection of such partners is a finely-tuned process with ground rules set by the ransomware operators from the start \u2013 including geographical restrictions and even political views. At the same time, ransomware victims are selected opportunistically.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As the people who infect organizations and the ones who actually operate ransomware are different groups, only formed by the desire to profit, the organizations infected most are often low-hanging fruit \u2013 essentially, the ones that the attackers were able to gain easier access to. It could be both actors that work within the affiliate programs and independent operators that later sell access \u2013 in an auction form or as a fix, starting as low as 50 USD. These attackers, more often than not, are botnet owners who work on massive and wide-reaching campaigns and sell access to the victim machines in bulk, and access sellers on the lookout for publicly disclosed vulnerabilities in internet facing software, such as VPN appliances or email gateways, which they can use to infiltrate organizations.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/ecp.yusercontent.com\/mail?url=https%3A%2F%2Flh6.googleusercontent.com%2FjkC4CqP8_nbZl_qjTA79XaDC2ZOzbQr0cVpczdfygvEljJysM8FpnYM9H8u5fG1_F419gyk2kxctyLdjsl82cznoUPvgQkPLMuxSTyCl-G2ZK_65Le8QTKAIWgw-OHvg2x1PsGFx&amp;t=1621316253&amp;ymreqid=27f3344f-c727-c29c-1cc2-cd0094016e00&amp;sig=qBq5yvrZoi8nR2fI8DmCug--~D\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><em>An example of an offer to sell access to an organization\u2019s RDP<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ransomware forums are home to other types of offers too. Some ransomware operators sell malware samples and ransomware builders for anything from 300 to 4,000 USD, others offer Ransomware-as-a-Service \u2013 the sale of ransomware with continued support from its developers, which can range from 120 USD per month to 1,900 USD per year packages.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThe ransomware ecosystem is a complex one with many interests at stake. It is a fluid market with many players, some quite opportunistic, some \u2013 very professional and advanced. They do not pick specific targets, they may go after any organization \u2013 an enterprise or a small business, as long as they can gain access to them. Moreover, their business is flourishing, it is not going away anytime soon,\u201d comments Dmitry Galov, security researcher at Kaspersky\u2019s Global Research and Analysis Team.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThe good news is that even rather simple security measures can drive the attackers away from organizations, so standard practices such as regular software updates and isolated backups do help and there is much more that organizations can do to secure themselves,\u201d adds Galov.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Effective actions against the ransomware ecosystem can only be decided once its underpinnings are truly understood. With this report, we hope to shine a light on the way ransomware attacks are truly organized, so that the community can set up adequate countermeasures,\u201d comments Ivan Kwiatkowski, senior security researcher at Kaspersky\u2019s Global Research and Analysis Team.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kaspersky encourages organizations to follow these best practices to help safeguard their businesses against ransomware:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Always keep software updated on all the devices you use, to prevent attackers from infiltrating your network by exploiting vulnerabilities.\u00a0<\/li><li>Focus your defense strategy on detecting lateral movements and data exfiltration to the internet. Pay special attention to the outgoing traffic to detect cybercriminals\u2019 connections. Set up offline backups that intruders cannot tamper with. Make sure you can quickly access them in an emergency when needed.\u00a0<\/li><li>Enable ransomware protection for all endpoints. There is a free Kaspersky Anti-Ransomware Tool for Business that shields computers and servers from ransomware and other types of malware, prevents exploits and is compatible with already installed security solutions.\u00a0<\/li><li>Install anti-APT and EDR solutions, enabling capabilities for advanced threat discovery and detection, investigation and timely remediation of incidents. Provide your SOC team with access to the latest threat intelligence and regularly upskill them with professional training. All of the above is available within Kaspersky Expert Security framework.<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>To help organizations understand how the ransomware ecosystem operates and how to fight it, the latest report by Kaspersky researchers dug into darknet forums, took a deep look at REvil and Babuk gangs and beyond and debunked some of the myths about ransomware. And when you dig into this underworld, you have to expect that it has many faces.<\/p>\n","protected":false},"author":6,"featured_media":41885,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[101,3826,54,2103,53,4100],"class_list":["post-43277","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-kaspersky","tag-kaspersky-security-network","tag-security","tag-security-breach","tag-security-risk-management","tag-security-solutions"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/43277","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=43277"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/43277\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/41885"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=43277"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=43277"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=43277"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}