HomeSecurityVirusTotal: What did the analysis of 80 million ransomware samples show?

VirusTotal: What did the analysis of 80 million ransomware samples show?

Google 's popular VirusTotal scanning service has published an interesting analysis of ransomware attacks , based on the analysis of more than 80 million samples uploaded from 140 countries worldwide . According to the report, as of 2020, at least 130 different ransomware families are active.

See also: Global ransomware meetings: Russia and China left out

Google VirusTotal ransomware

The countries most affected by ransomware samples uploaded to VirusTotal were Israel, South Korea, Vietnam, China, Singapore, India, Kazakhstan, the Philippines, Iran, and the United Kingdom.

See also: Pacific City Bank attacked by AvosLocker ransomware

According to the report, most ransomware samples were uploaded during the first two quarters of 2020.

Additionally, sample analysis showed that the most popular ransomware family targeting Windows systems since early 2020 is GandCrab.

The chart below shows the top 10 ransomware families based on the number of different samples:

VirusTotal: What did the analysis of 80 million ransomware samples show?

It is worth noting that a relatively young threat like Babuk ransomware, which appeared on the threat landscape in early 2021, occupies the second place on the list.

As for WannaCry, Google says it's on the list because of "old detection that still applies to some new ransomware families" and not because of a new wave of attacks.

See also: Yanluowang Ransomware: Used in attacks against businesses

Furthermore, according to Google, VirusTotal analysis revealed that 95% of the ransomware files detected were Windows-based executables or dynamic link libraries (DLLs).

VirusTotal: Key findings of the ransomware report:

  • While major ransomware campaigns are short-lived and appear sporadically, there is a steady stream of ransomware activity that never stops.
  • Attackers use many different approaches, including the use of known botnet malware and other RATs.
  • Attackers use exploits for privilege escalation and to spread their malware across internal networks.
  • Windows systems are the main target of ransomware attacks.

Source: Security Affairs

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS