Consistent patterns of behavior across ransomware groups can help security teams understand and prepare for attacks more effectively.

Cybersecurity analysts typically analyze ransomware attacks in isolation, looking at the tactics, techniques, and procedures (TTPs) that are unique to each incident. However, new research from Sophos demonstrates why it’s critical for defenders to look beyond the surface, as attacks carried out by different hacking groups often exhibit interesting similarities.
So-called ransomware clusters offer insight into generalized patterns and common features among attacks, which can be used to better prepare for and protect against ransomware exploits in the future, according to research.
The research, titled “Clustering Attacker Behavior Reveals Hidden Patterns,” examines patterns over a three-month period, from January to March 2023. The Sophos X-Ops team investigated four distinct ransomware attacks involving Hive, two incidents linked to Royal, and one attributed to Black Basta.
The Royal ransomware group, known for its secrecy and avoidance of publicly inviting collaborators to underground forums, revealed a surprising degree of coherence with other ransomware variants, according to researchers. The findings suggest that all three groups, Hive, Royal and Black Basta, either work with the same collaborators or share specific technical knowledge about their operations. Sophos described these coordinated efforts as “cumulative threat activity,” a concept that empowers security teams to create detection and response strategies.
Discovering the common thread in ransomware
How can security teams gather this kind of threat intelligence for their internal ransomware defense strategy? To identify and understand these ransomware threat groups, Sophos researchers recommend that teams use the following data-driven steps to detect patterns:
- Data collection: Gather and analyze threat intelligence data, including indicators of compromise (IoC), malware signatures, attack vectors, and behavioral patterns.
- Pattern Recognition: Use advanced analytics and machine learning to uncover patterns of recurring TTPs, such as initial access methods, lateral movement techniques, and data exfiltration strategies.
- Attribution and clustering: Linking ransomware attacks that exhibit common characteristics. This can include attributing attacks to specific hacking groups or identifying common infrastructure, tools, or malware variants.
- Temporal analysis: Examine the timing of ransomware attacks to discern patterns in their execution. This could reveal coordinated campaigns or seasonal variations in attack activity.
Using details for defense
Understanding hacking groups can reshape the way organizations and security professionals approach defensive posture against ransomware attacks. Armed with a deeper understanding of the common elements that connect ransomware attacks within groups, security professionals can formulate more proactive strategies to prepare for the possibility of ransomware. Understanding highly specific attacker behaviors can help rapid response by detection and response (MDR) teams when faced with an attack and can also help security providers better protect their customers.
With the development of behavioral-based defenses, the identity of the attacker becomes irrelevant – whether it’s Royal, Black Basta or any other hacking group. What really matters is that potential victims have the necessary security measures in place to prevent future attacks that exhibit these common characteristics. Read more about the research and findings in the article “Clustering Attacker Behavior Reveals Hidden Patterns” by Sophos.
Information source: csoonline.com
