HomeSecurityHow the REVIL ransomware group has increased its profits in...

How has the REVIL ransomware group increased its profits in the last year?

The developers of REVIL ransomware say they earned more than $100 million in one year by extorting large businesses from various sectors around the world.

Their goal is profit and they constantly adopt the most profitable market trends.

A REvil spokesperson who uses the aliases “UNKN” and “Unknown” on a cybercrime forum spoke to Russian tech blog OSINT, offering some details about the group’s activity and hints at what attacks they will carry out in the future.

Like almost all ransomware gangs today, the REvil group operates a ransomware-as-a-service (RaaS) operation. Under this model, developers provide file-encrypting malware to partners, who earn the lion's share of the money they receive from extortionate victims.

The REvil team developers take 20-30% and the rest of the ransom goes to the partners, who carry out the attacks, steal data and launch the ransomware on corporate networks.

This means that the developers set the ransom amount, conduct the negotiations, and collect the money which is later shared with the partners.

REVEL

Long list of victims

The cybercriminal enterprise has encrypted computers at major companies, including Travelex, Grubman Shire Meiselas & Sacks (GSMLaw), Brown-Forman, SeaChange International, CyrusOne, Artech Information Systems, Albany International Airport, Kenneth Cole, and GEDIA Automotive Group.

"Unknown" says that REvil associates managed to breach the networks of Travelex and GSMLaw in just three minutes by exploiting a vulnerability in Pulse Secure VPN that was left unpatched for months after the patch was released.

REVIL's spokesperson says the group hit the network of a "major gaming company" and will announce the attack.

They also say the REvil group was responsible for the September attack on Chile's public bank, BancoEstado. The incident prompted the bank to close all of its branches for a day, but did not affect online banking, apps, or ATMs.

Along with managed service providers (MSPs) that have access to multi-organization networks, the most profitable targets for the REvil team are companies in the insurance, legal, and agricultural sectors.

Regarding initial access, "Unknown" mentioned brute-force attacks as well as Remote Desktop Protocol (RDP) in conjunction with new vulnerabilities.

The REvil team initially collected its profits from victims paying the ransom to unlock their encrypted files. Since the attackers also locked down backup servers, victims didn't have many options for recovery and paying was the quickest way.

The ransomware business changed last year when attackers seized a new opportunity to steal data from compromised networks. Then they began threatening victims with catastrophic leaks that could have a much worse impact on the company.

Even if it takes longer and causes significant disruption, large enterprises can recover encrypted files from offline backups. Having sensitive data publicly available or sold to interested parties, however, can be synonymous with loss of competitive advantage and reputational damage that is difficult to rebuild.

This method proved so profitable that the REvil team now makes more money from not publishing stolen data than from the ransom it receives from decryption.

“Unknown” says that one in three victims is currently willing to pay the ransom to prevent the company’s data from being leaked. This could be the next step in the ransomware business.

The REvil team is also considering adopting another tactic designed to increase the chances of victims paying: hitting victims with distributed denial-of-service (DDoS) attacks to force them (at least) to start negotiating on the ransom payment.

The SunCrypt recently used this tactic on a company that broke off negotiations. The attackers made it clear that they launched the DDoS attack and ended it when negotiations. The REVIL team plans to implement this idea.

REVIL's money- making model is working, and the gang has already raised a lot. In their search for new partnerships, they deposited $1 million in bitcoin on a Russian-language forum.

The move was designed to show that their operation is profitable. According to Unknown, this step is to recruit new blood to distribute the malware, as the ransomware space is filled with professional cybercriminals.

Despite having a lot of money, REvil's developers are limited to the borders of the Commonwealth of Independent States (CIS, countries of the former Soviet Union).

Source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS