HomeSecurityClop ransomware group will earn $75-100 million through attacks...

Clop ransomware group will earn $75-100 million through MOVEit attacks

It is expected that the Clop ransomware gang will earn around $75-100 million from extorting money from its victims, as part of the massive data theft campaign via the vulnerability in the MOVEit platform .

MOVEit Clop ransomware

In a new report, Coveware explains that the number of victims paying ransom has dropped significantly, forcing ransomware gangs to adapt their strategies to make their attacks more profitable.

Coveware explains that there are different attacks with different opportunity costs. This cost is derived from the degree of difficulty and investment required to carry out an attack, compared to the expected ransom amount.

See also: MOVEit Transfer customers warned to patch new, critical flaw

The following chart illustrates the relationship between the impact on the victim and the cost (time, effort, and investment) required to execute an attack (cost to the attacker). The vertical axis represents the impact on the victim, while the horizontal axis shows the cost of the threat.

Clop ransomware group will earn $75-100 million through MOVEit attacks
Clop ransomware group will earn $75-100 million through MOVEit attacks

The graph shows that low-sophistication ransomware attacks that use automation have a lower impact on victims, while the cost to the attackers is also lower. For attacks like these, ransom demands typically range from a few hundred dollars to thousands of dollars. The attackers hope to raise enough money if they get many victims to pay.

However, more complex and time-consuming attacks with a more significant impact on victims generate much larger ransom demands (perhaps in the millions).

Clop ransomware: Gang changes tactics as payouts decline

On May 27, the Clop ransomware gang launched widespread data, through the use of a zero-day vulnerability in the MOVEit Transfer file transfer platform.

See also: MOVEit attacks: Siemens Energy confirmed data breach

These attacks are expected to affect hundreds of companies around the world. Many large companies have already reported being victims and have notified customers of a data breach.

However, Coveware says that extortion attacks focused solely on data theft have reduced payouts, with victims revealing the attacks and issuing data breach notifications rather than paying the threat actors.

Coveware says that Clop has changed its strategy and is now asking for much more money, hoping that even if only a few victims pay, it will still be able to make a significant profit.

According to Coveware's estimate, only a few victims of the MOVEit attacks are likely to pay up. However, it is expected that the Clop ransomware group will collect an impressive sum of $75-100 million from these payments alone.

“It is possible that the CloP group earned $75-100 million from the MOVEit campaign alone, with this amount coming from a small portion of victims who succumbed to very high payouts,” explains Coveware.

Coveware CEO Bill Siegeltold BleepingComputer that the Clop ransomware gang's success in these attacks is significantly greater than the recent GoAnywhere. In those attacks, the group breached 130 victims and received ransom payments from only a handful of victims.

See also: MOVEit: Hackers steal data of 45,000 New York students

Clop ransomware group will earn $75-100 million through MOVEit attacks

The MOVEit attacks led to the breach of many more companies, and with the ransoms they have demanded, the hackers can make a lot of money, even if most companies decide not to pay.

In early June, the Clop ransomware gang told BleepingComputer that it was behind the MOVEit Transfer. A Clop spokesperson also said that the group had begun exploiting the vulnerability on May 27, during the long Memorial Day holiday in the US. The Clop ransomware operation is known to typically launch attacks during the holidays, when staffing levels are low. For example, it exploited a similar zero-day vulnerability in Accellion FTA on December 23, 2020, to steal data right at the start of the Christmas holidays.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS