HomeSecurityRansomware: FIN12 group gets much faster at encrypting networks

Ransomware: FIN12 group gets much faster at encrypting networks

Researchers at Mandiant examined ransomware attacks by a cyber‑criminal group referred to as FIN12 – responsible for one in five attacks investigated by the cybersecurity firm – and found that there was a significant reduction in the time between the initial intrusion into networks and the encryption with ransomware, most commonly Ryuk ransomware.

Ransomware: FIN12 group gets much faster at encrypting networks

According to data published in Mandiant's M-Trends 2022 report, the average dwell time of FIN12 campaigns – the time between hackers gaining initial access to the network and triggering the ransomware attack – has decreased from five days to less than two days.

One of the reasons the lifecycle of these attacks has been reduced so much is because FIN12 campaigns do not focus on finding sensitive data and stealing it before a ransomware attack is triggered.

Searching and stealing data has become a common tactic for many ransomware groups, who in addition to encrypting data, threaten to publish it if a ransom is not paid. It is a successful technique that many of the most high-profile ransomware gangs deploy to force the victim to pay the ransom.

However, despite the fact that it does not adopt this technique, the FIN12 group continues to be an extremely successful ransomware operation, which, apart from its rapid development, appears to target those it deems easy targets to demand ransom.

For example, the cybercriminal group is known to frequently target hospitals and healthcare – organizations that desperately need networks up and running to provide patient care. This means that victims in the healthcare sector may be more willing to submit ransom demands than victims in other industries.

The group also targets organizations that generate high revenues, a tactic that is also employed because the attackers believe they have the best chances of earning large monetary sums from ransoms.

FIN12 Ransomware

There are many methods that the FIN12 group uses to infiltrate networks, including gaining access through older backdoor malware infections such as TrickBot and BazarLoader. The malware is delivered to machines – sometimes via phishing – and it is common for ransomware groups to rent out or otherwise exploit this access to ultimately encrypt the network.

Researchers note that several FIN12 campaigns have leveraged legitimate usernames and passwords to log in to virtual environments, including Microsoft Office 365.It is possible that these credentials were purchased on dark forums.

The FIN12 group tends to focus attacks on North American victims – but Mandiant warns that the ransomware could potentially target a wider range of victims around the world.

Some of the steps organizations can take to avoid falling victim to ransomware attacks include applying security patchesso that cybercriminals cannot exploit known vulnerabilities to deliver malware and ensuring that any passwords known to have been compromised.

Organizations should also provide users with multi-factor authentication as an additional barrier against cyberattacks that attempt to misuse leaked credentials

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS