HomeSecurityRansomware attacks: Hackers secretly blackmail victims!

Ransomware attacks: Hackers secretly blackmail victims!

Threat intelligence analysts have noticed an unusual trend in ransomware attacks, reporting that the initial stages of extortion of victims are becoming more “secretive” as hackers tend to use hidden or anonymous logins. By not immediately revealing the victim’s name, ransomware operations give their targets an opportunity to negotiate a ransom payment in secret, while maintaining a level of pressure in the form of future data leaks.

Threat analysts observe unusual tactics of ransomware groups

KELA, an Israeli cybersecurity intelligence company ,published its ransomware attack report for the first quarter of 2022 that illustrates this trend and highlights various changes in the sector.

In the first quarter of 2022, the total number of ransomware victims decreased significantly by 40% from 982 in the fourth quarter of 2021 to 698. This was partly due to the gradual decline and eventual exit of Conti and also due to newer groups not producing the same attack as those that departed in the previous quarter.

Topping the list for this period is LockBit, the most dangerous ransomware threat, revealing 226 victims, almost the same as the previous quarter. Of the new threats, Alphv accounted for 8% and Karakurt for 5% of published victims, which are significant but nowhere near LockBit's 32% or even Conti's 18%.

The financial sector saw a 40% increase in the number of victims quarter-on-quarter, while professional services, healthcare, manufacturing and technology remained consistently in the top five most targeted sectors.

The United States topped the list of most targeted countries with 40%, followed by the United Kingdom, Italy, Germany and Canada. France, which was in the top five in the past, has not been as targeted in recent months.

Home access

Front-end access brokers remain a critical link in the ransomware attack chain, with 116 such vendors identified in Q1 2022, a 15% increase compared to the previous quarter. Some brokers like “Novelli” have been active on cybercrime forums since 2019, primarily selling RDP access , while others like “Chiftlocal” first appeared on the scene in March 2022.

Ransomware attacks: Hackers secretly blackmail victims!

Another prominent vendor spotted by KELA threat analysts is “Pumpedkicks,” also known as “Mont4ana,” who offers SQL flaws and login credentials to corporate networks. This malicious user recently added VPN to US companies and government entities.

Hiding victims' names

A somewhat strange trend that has unfolded in Q12022 is ransomware gangs hiding the names of their victims and describing them only by their industry, size, and stolen data. KELA observed this tactic from Midas, Lorenz, and Everest, who threatened their victims that they would add their brand to the Tor extortion if they did not pay the ransom.

This tactic is also used by other ransomware gangs, who prepare hidden web pages on their data-leakage sites and give the URL only to the victim. This was to show proof of stolen data without damaging their bargaining position. When a ransomware group immediately publishes the victim’s name, it destroys any chance of reaching a successful negotiation outcome and receiving money. By exposing the incident to the authorities, they make it impossible to informally receive large sums.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS