HomeSecurityRansomware groups target top company executives to receive ransom!

Ransomware groups target top company executives to obtain ransom!

Ransomware groups are now prioritizing data theft from workstations used by top executives and company directors. Their goal is to steal important information, which they can later use to pressure and blackmail a company's top executives into paying large ransoms.

The hackers ' new tactic was uncovered by ZDNet last week after it made a phone call to a company that paid a multimillion-dollar ransom to the Clop ransomware gang. Similar calls with other Clop victims and email interviews with cybersecurity firms later confirmed that it's a technique the Clop gang has been perfecting in recent months.

Ransomware groups target top company executives to obtain ransom!

Over the past two years, ransomware groups have evolved, now primarily targeting high-profile companies rather than home consumers. Hackers breach corporate networks, steal sensitive files, which they then encrypt, and leave ransom notes on compromised computers.

In some cases, a ransom note informs companies that they must pay a ransom to receive a decryption key. In the case of data theft, some ransom notes also inform victims that if they do not pay the required ransom, the stolen data will be published on data leak sites.

Ransomware groups hope that companies will do everything they can to avoid publishing their confidential and sensitive data, which, if exposed, would be accessible to competitors. Therefore, they will be more willing to pay the ransom demanded, rather than attempting to restore from backups.

Ransomware groups target top company executives to obtain ransom!

There are also cases where ransomware groups have told companies that publishing their data would also amount to a breach , potentially leading to the victim being fined by the authorities, while also tarnishing their reputation. This is clearly something that companies also want to avoid.

However, ransomware groups do not always succeed in stealing data or sensitive information in attacks . This reduces their ability to negotiate and pressure victims. That is why, in recent attacks, a group that has frequently used the Clop ransomware strain specifically looks for workstations within a compromised company, used by its top executives.

Specifically, hackers search through a manager's files and emails, stealing data they believe could be useful to threaten or pressure a company's management. The same people who would likely be responsible for approving the ransom demand days later.

Ransomware groups target top company executives to obtain ransom!

Stefan Tanase, a cybersecurity expert at CSIS Group, told ZDNet: "This is a new modus operandi for ransomware gangs, but I can say that I'm not surprised. Ransomware groups usually target the 'jewels' of a business. It's usually file servers or databases when it comes to dumping data for the purpose of leaking it. It makes sense that the devices of top executives would follow if that would have an even bigger impact."

Furthermore, Brett Callow, a threat analyst at cybersecurity firm Emsisoft, told ZDNet that, so far, they have only seen such tactics in incidents related to the Clop ransomware. Callow added that over the past two years, the tactics used by ransomware groups have become increasingly extreme, as they now use every method possible to pressure their victims. Among the tactics they use are harassing and threatening phone calls to both executives and customers and business partners, Facebook, press outreach, and threats to expose companies’ “dirty money.”

Also, Evgueni Erchov, director of incident response and cyberthreats at Arete IR, reported that an associate of the REVil/Sodinokibi ransomware operations has already adopted this technique from the Clop gang. In particular, he managed to find documents regarding internal discussions of the victims. Then, using this information, he contacted the executives via email, threatening to make public the data of the alleged “misconduct” of the administration.

hackers

Bill Siegel, CEO and co-founder of security firm Coveware, pointed out that in many cases, the data used in extortion attempts aimed at managing a company is not always true. He also added that there has been no recorded case where the stolen data showed any real evidence of corporate or personal misuse. For the most part, it is simply a scare tactic to increase the likelihood of hackers paying the ransom. Finally, Siegel stressed that these are criminal extortionists who say a lot of “fantasy” things if it is going to bring them money.

This is information collected by ZDNet, with the help of security company “S2W Lab”.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS