Last week, cybersecurity agencies from the UK, US and Australia published a joint advisory warning and reported on the increased ransomware attacks during 2021.
According to a report published by Chainalysis ,organizations have paid at least $602 million in cryptocurrency to ransomware gangs in 2021. This marks a relative decrease compared to the previous year, when organizations paid $692 million in cryptocurrency, but Chainalysis experts warn thatmore ransom payments could be identified in the near future.
See also: Maze/Egregor ransomware: Decryption keys released

Experts stressed that the numbers are changing as they continually learn about attacks and payments they were previously unaware of. “As of January 2022, we have now identified just over $692 million in ransomware payments in 2020 — nearly double the amount we initially identified when writing last year’s report.”
“There is a slight time lag in ransomware data, so we expect that when these numbers are updated in a few months, 2021 will have higher numbers than 2020,” the company added.
According to the report, the most cryptocurrencies in 2021 (ransom) were given to the Conti. The hackers managed to extort at least $180 million from victims.
The Conti ransomware operators operate a private Ransomware-as-a-Service (RaaS). The malware appeared in late December 2019 and began distributing via TrickBot infections. Experts speculate that the hackers are members of a Russia-based cybercrime group known as Wizard Spider.
Since August 2020, the group has opened a data leak site to threaten victims with the publication of stolen data (the data is stolen before the systems are encrypted).
Conti operators offer the services/malware to other hackers and keep 20-30% of the ransom.
CISA and the FBI observed that Conti ransomware was used in more than 400 attacks on US and international organizations.

Darkside was the second-highest-grossing gang in 2021. Experts estimated the group's profits at around $85 million. The gang's most famous attack was on the Colonial Pipeline facility in May 2021, which caused chaos in the US .
Following the attack, the Darkside gang ceased operations, fearing a law enforcement response. The group also claimed that federal authorities seized some of its infrastructure and some wallets it used for its activities.
In July, the ransomware group resurfaced under the name BlackMatter.
Among the top 10 ransomware groups for 2021 (based on revenue), are Phoenix Cryptolocker and REvil.
The researchers' report also shows an increase in the amounts of money demanded by gangs in 2021. The average amount of money in 2021 was over $118,000, while in 2020 it was $88,000 and in 2019 it was $25,000.
See also: Qbot and Lokibot target Windows Regsvr32 again
One reason for the increase in ransom sizes is the focus of ransomware attackers on conducting attacks against large organizations, the report says. This strategy, known as “big game hunting,” and in such cases, ransomware groups are taking tools from third-party providers to make their attacks more effective.
Ransomware attacks can bring in a lot of profit for attackers, which is why they are a threat that continues to grow. Chainalysis reported that at least 140 ransomware operators received payments from victims in 2021.
Researchers also observed that many groups cease their activities for a period of time and then reappear in the threat landscape under a new name.

“Increasingly in 2021, we saw threat actors publicly ‘shut down’ their infrastructure before relaunching under a new name, presenting themselves as a separate group.” However, in most cases, researchers are discovering evidence that allows them to connect new ransomware to older ones.
These changes are usually made to avoid detection by law enforcement agencies.
See also: Spain: Police arrest suspects for participation in SIM-swapping scheme
The report also highlights that while most ransomware attacks appear to be financially motivated, government-backed groups use this practice for multiple purposes, including deception, espionage, defamation and fundraising. Experts believe that the attacks are often launched by groups linked to Iran, Russia, China and North Korea.
Experts expect the above trends to continue to increase in 2022.
Source: Security Affairs
