What are the ransomware gangs that target the world's largest companies?
In the past year, some of the most recognizable companies in the United Kingdom, from the Guardian to Royal Mail, have been hit by the defining cybercrime of our era: ransomware. The hackers who locked computer networks and demanded payment for the keys to restore them have blocked operations and left victims trying to recover.
See also: Gamaredon hackers steal data in less than an hour afterbreach

See also: Genesis Market administrators sold the store to a hacking forum
Almost every sector of society, including healthcare, businesses, government, and education, has now been targeted by ransomware gangs that demand sums reaching tens of millions. Ironically, a few months before the release of my own book on ransomware, my publisher suffered a severe attack, resulting in my co-author and I being unable to contact our publishers by phone or email.
In the United Kingdom, only in the last weeks, distinct attacks are reported to have put at risk NHS employee files and confidential emails, as well as data for more than one million patients. In the United States, the death of an infant was attributed to a ransomware attack in 2019 at a hospital in Alabama, which took offline the screens that displayed fetal heart rate monitoring information at a nursing station.
Just a decade ago, ransomware was a relatively unknown crime that mainly targeted home computer users. Hackers would demand a few hundred pounds worth of crypto for the return of locked family photos and other personal files. They would mostly operate alone or in small groups, spreading ransomware via spam emails that were distributed indiscriminately to large numbers of potential victims – only a small fraction of whom actually opened the malicious links or attachments. So how did this criminal enterprise become a global fear?
Although the profits from this early “spray and pray” model were modest, ransomware nevertheless attracted hackers, who were drawn in part by the simple nature of the crime. Traditional data breaches required painstaking effort to find buyers for files, such as credit card numbers, in order to cash in. Ransomware made the breach itself profitable.
Criminals seeking the path of least resistance rushed to invade the extortion economy, and as ransomware matured as a business, gangs began to organize in ways that mirrored legitimate companies. Many seemed to find safe haven in places like Russia, North Korea , and Iran. But large parts of Eastern Europe also became hotbeds for gang cyber operations, and hackers now operate around the world.
The most ambitious, such as Ryuk and REvil , hired workers who had the expertise to introduce their ransomware into large organizations that had much more money than home users—a strategy known as “big game hunting.” In job postings on the dark web, prospective “employers” described the qualifications they were looking for, such as proficiency in Cobalt Strike, a legitimate tool that hackers partner with and is used to identify system vulnerabilities . The postings asked candidates to submit examples of their previous attacks , and promising candidates were invited to online interviews.

See also: GTA 6 hacker accused of blackmailing Rockstar
Just as a legitimate company might hire other companies to handle logistics or website design, ransomware gangs began outsourcing tasks beyond their own responsibilities. They hired experts via the dark web to steal credentials and find vulnerabilities in target networks. They hired others to ensure that their ransomware could not be detected by standard anti-malware scanners. Outsourcing allowed the gangs to focus on improving the quality of their ransomware, and their success—and the devastation of their victims—accelerated.
Source of information: theguardian.com
