HomeSecurityThree emerging trends currently shaping the ransomware landscape

Three emerging trends currently shaping the ransomware landscape

Despite high awareness and significant investments in security measures, ransomware remains one of the biggest security challenges facing organizations worldwide.

According to the latest WatchGuard Internet Security Report, endpoint ransomware threat detections increased by 627% in the fourth quarter of last year, highlighting the need for security teams to strengthen their protection level.

Continuous vigilance is a vital part of achieving effective protection. Part of this vigilance must be continuous monitoring of the constantly evolving tactics and methods used to carry out ransomware attacks.

Three emerging trends currently shaping the ransomware landscape

There are currently three major ransomware trends that security teams need to understand and consider when implementing protective measures. These are:

  1. The emergence of “pseudo‑ransomware”

Since Russia invaded Ukraine, there has been a significant increase in cyber attacks in both countries. In many cases, the attacks have included a technique called “pseudo ransomware”.

A pseudo-ransomware is a conventional ransomware attack, however the actors aim to cause disruptions and losses rather than demand payment for decryption keys.

Such attacks are called 'wipers', as their goal is to delete or destroy data on a victim's IT infrastructure. In some cases a ransomware note is provided, but no details are given on how the ransom. In other cases, the files were encrypted in a way that did not allow for decryption.

Examples include WhisperGate, PartyTicket (also known as HermeticRansom), Azov, Somnia and RU Ransom. All of these were new wipers discovered in Ukraine and disguised as ransomware. In the meantime, CryWiper is an example of pseudo-ransomware found in Russian government networks.

  1. The rise of Rust code

Another interesting trend is the growing trend of ransomware gangs using the Rust programming language to develop ransomware. Rust is a multi-paradigm, general-purpose language that emphasizes performance and concurrent execution.

The first known group that used Rust was the Alphv group (also known as BlackCat or Noberus), before other groups followed their example. RansomExx created a new variant in Rust and updated it as RansomExx2.

Meanwhile, other groups such as Agenda, Luna, Nokoyawa, and Hive have also used variants of the Rust programming language. This emerging trend primarily affects threat analysts and researchers , but also affects endpoints, as anti-virus engines may not detect newer programming languages ​​as effectively.

  1. The increasing popularity of double-extortion attacks

Double-extortion attacks involve a cybercriminal encrypting a target's files while simultaneously stealing a copy. It therefore threatens that if the ransom amount is not covered, those files will be made public.

Unfortunately, double-extortion incidents are occurring at an increasing rate. Some groups are threatening victims with denial-of-service (DDoS) attacks or have contacted customers to force payment.

Ransomware attacks continue to grow in both complexity and number, making it vital for security teams to remain vigilant and take the necessary steps to ensure their organization has the best possible protections in place .

Source: itwire.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS