Ransomware and fake ransomware: It used to be simple. Attacks were relatively easy to identify. Take Shamoon. When the attack was analyzed, it was clear that it was intended to disrupt its victims. In this case, the target was clearly Saudi Arabia, and the use of a Wiper in the malware components clearly indicated one of the attackers' goals. To wipe and destroy infected systems. 
Similarly, the use of ransomware was equally clear.
Its use is aimed at ransom payments. What we have seen so far shows that ransomware attacks are designed in such a way as to allow even people without the required technical expertise to participate in similar activities. With the availability of ransomware as a service, any wannabe malicious “hacker” can run their own attack.
But the attacks that took place a few months ago (WannaCry and Petya/NotPetya) illustrate a departure from the obvious targets of previous attacks.
Ask yourself: was the Petya/NotPetya successful?
As a ransomware attack, it probably failed since its revenue ($10,000) was insignificant compared to the size of the attack and the expertise used.
If the goal of the attack was to cause widespread disruption, the attack was probably successful as there are still some victims trying to restore full functionality to their systems.
In the case of WannaCry and Petya/NotPetya, every analysis can be questioned. What was the real motive and what was the real purpose of the attack.
Very often, answers from the Infosec community start with “maybe” or “probably,” while sometimes there is also “it depends.” Such answers are clearly inadequate when an attack disrupts the entire world and of course shows that the security community is weak in accurately reading what is happening, as was the case with previous attacks.
On the other hand, attackers have a vast arsenal of tools that can help them increase their ability to conceal their true purpose.
Is a DDoS attack intended to bring down a page? or is it an extortion attempt to make money for the attacker?
With such tactics, it is clear that the need for collaboration and coordination of research between the public and private sectors or private and private sectors is more important than ever. But can it be done?
One thing is clear:
The older assumption that paying a ransom after an infection could possibly lead attackers to relinquish control of victims' data is a thing of the past.
