HomeSecurityLaw enforcement agencies are taking a toll on ransomware groups

Law enforcement agencies are taking action against ransomware groups

Although the results of law enforcement actions against the ransomware-as-a-service Alphv/BlackCat and LockBit have not yet fully taken shape, the suspension of the Qakbot botnet in August 2023 had one obvious result: ransomware partners have switched to exploiting vulnerabilities as the primary method of malware delivery.

See also: Microsoft Teams: Ransomware access broker steals accounts through phishing

ransomware groups

The change is obvious to the Symantec Teams, but unfortunately it was not accompanied by a decrease in the number of ransomware victims.

Analysis of data from ransomware leak sites reveals that attackers managed to hit significantly more victims last year (4,700) compared to 2022 (2,800), they pointed out.

Constantly changing techniques

One of the hallmarks of successful ransomware groups is their ability to adapt their techniques to changing circumstances. When one door closes, they look for – and find – another.

For example, malicious macro-enabled documents long served as the primary means of ransomware delivery, until Microsoft implemented default protections that made this approach significantly less successful and forced them to change it.

The researchers pointed out other current trends related to ransomware attacks: the use of vulnerable drivers by attackers (e.g., to disable security software), legitimate remote desktop tools (AnyDesk, Atera, etc.), customized data theft tools (e.g., Lockbit's StealBit), and abuse of built-in Windows (e.g., Esentutl, DPAPI) to steal credentials.

See also: BianLian ransomware group stole data from Save The Children

Symantec threat detectors also noticed a strange phenomenon that suggests a skill imbalance between Lockbit and Alphv/Blackcat collaborators.

Alphv/BlackCat appears to be implementing an exit scam and defrauding some of its associates, while the main operator of the LockBit ransomware group is trying to reassure associates who were intimidated by law enforcement action to stay and continue collaboration .

law enforcement authorities

Meanwhile, the (relative) gap in the ransomware landscape created by the problems of the two groups above, according to cybersecurity firm RedSense, has been partially filled by Akira ransomware and related groups such as Zeon.

“In December, we obtained reliable primary information from sources (…), suggesting that Zeon operates as an elite team of pentesters for both Akira and LockBit, with the latter being their primary target,” said RedSense co-founder Yelisey Bohuslavskiy.

See also: Epic Games: Mogilevich hackers say they stole data

What are the key functions of Ransomware-as-a-Service?

Ransomware-as-a-Service (RaaS) is a model used in cyberspace, where hacking groups provide ransomware services to third parties. The core functions of RaaS include the creation, distribution, and management of ransomware attacks. Creation refers to the development of the ransomware software. RaaS providers create and deliver customized ransomware software that can be used for attacks. This software is often easy to use and does not require specialized knowledge. RaaS providers can use various techniques, such as phishing emails, malicious downloads, and drive-by downloads, to distribute the software to victims. RaaS providers also provide tools and services for monitoring the performance of attacks, managing ransom payments, and communicating with victims.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: helpnetsecurity

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS