There are few guarantees in the IT industry, but one certainty is that as the world steps into 2022, ransomware will continue to be a primary cyberthreat.
The dangers from ransomware have risen sharply since WannaCry and NotPetya hit the scene in 2017, and this year has been no different. A pair of recent reports underscores just how big that threat is.
The Global Threat Landscape Report released in August by FortiGuard, the threat intelligence unit of Fortinet, found that the weekly average of ransomware incidents over the previous 12 months had jumped 10.7 times. In Fortinets Global State of Ransomware Report in September, two-thirds of companies surveyed had been victims of ransomware attacks and 85 percent said they were more concerned about ransomware than any other cyberthreat.
The sharp increase in ransomware attacks can be attributed to many reasons, from the low level of cyber hygiene of some enterprises to insufficient training and education of employees and patch management issues, according to Derek Manky, chief of security insights and global threat alliances for Fortinets FortiGuard Labs. Cybercriminals dont have to work too hard to get into these systems. When they do, the payoff can be huge, particularly as attackers are setting their sights on larger companies.
One constant in all this will be cryptocurrency, the coin of the realm when it comes to ransomware. The big payoffs, the tendency of most victims to pay the ransom demand, and the money to be made by selling or leasing their malware in the growing ransomware-as-a-service (RaaS) market are all enticements when it comes to ransomware.
The engine that is driving much of this is cryptocurrencies, which have become the way ransoms are paid and are creating the financial foundation for the rapid evolution of the ransomware market, the skyrocketing increases in incidents and the growing numbers of bad actors getting into it, Manky told eSecurity Planet.
There is no doubt a parallel rise here that were seeing, he said. It is because of the cash cow. Cryptocurrency really is fueling this in a sense. If you were to take cryptocurrency away from that, they dont have a convenient digital platform. Theyre going to have to go back to the drawing board. It actually makes their operations more expensive because they need to try to be innovative and get more boots on the ground themselves, just like any business would if they dont have a platform.
Fortinet ransomware detections
Also read: The State of Blockchain Applications in Cybersecurity
Compounding all this is that ransomware is a vicious circle, Manky said.
Once you have that lower state of security and attackers are getting into systems, theyre forcing the hands as a means of enterprises to pay the ransom, he said. When theyre paying the ransom using cryptocurrency, its encouraging cybercriminals. Its making their pockets deeper. They dont have to do a heavy lift to reap profits like theyre doing today.
The use of cryptocurrencies like Bitcoin, Ethereum and myriad others harkens back to the days of e-gold, another digital currency launched in the 1990s that included the use of online accounts. E-gold use peaked in the mid-2000s before it was suspended in 2009 for legal reasons. As cybercrime became more about monetization, cybercriminals began leveraging the currency for money laundering, fraud and other schemes, he said.
Between the demise of e-gold and the rise of cryptocurrency, bad actors used a number of different ways to move money, including gift cards. They would steal credit cards to buy gift cards and then use those to be cashed out and sold to other people, Manky said.
Also read: Best Ransomware Removal Tools
The rise of cryptocurrency has had a ripple effect throughout the cybercriminal world, Mansky said. When it first hit the scene, the primary targets of threat actors were the cryptocurrency exchanges themselves. The payouts for hackers were significant; when they hit an exchange, they had access to hundreds of cryptocurrency wallets. However, exchanges began strengthening their security, which made attacking them more expensive, so cybercriminals shifted tactics and began increasingly to target users.
Instead of robbing a bank, theyre going to the victims themselves, Manky said.
For the past five years, there has been cryptomining, where bad actors infect systems with malware that leverages the CPUs to mine for coins, essentially crowdsourcing stolen CPU power. More recently has been crypto-jacking, where hackers go directly into a users wallet and steal their coins.
This also has shifted the attack vector and opened up end users to greater threats. Attackers no longer are going after one target, he said. They may get into a system to steal digital wallets, but once a system is compromised, its open to other attacks.
Its a new form of crypto-jacking, essentially, but these are always multi-purpose in a sense, because in order to install that malware, they need what we call a loader, he said. They need a channel into that system. They do this through taking advantage of cyber-hygiene practices, social engineering, all those things we talk about. But once theyve infected these systems, theyre compromised, and oftentimes we see a lot of secondary attacks happening. Its just more and more volume and attack angles.
Fortinet: Top ransomware concerns
Cryptocurrency is enabling cybercriminals to enrich themselves beyond what had been possible. They not only can get paid more money for their actions, but the nature of the payments allows them to add more layers to their operations, making it more difficult to trace payments. It operates like cash in many ways. It makes hiding and laundering the payment easier.
They can actually print their own money, he said. They can print cryptocurrency on a piece of paper. All it is is a big hash address, a cryptographic algorithm, and they can transfer it that way. They can transfer it on a USB stick. They can transfer it physically on a piece of paper and put it into a briefcase and give it to somebody else. Once they have that and the actual keys for it, the moneys theirs. Its literally physically transferring a wallet to a wallet.
And they have multiple coins to choose from. They can be paid in Bitcoin and wash the payment by shifting to Ethereum or other exchanges. It makes it difficult for investigators, who dont have only one coin to follow, Manky said, adding that the bad actors can fork that to 100 different alternate coins.
Also read: Best Ransomware Removal and Recovery Services
The profits threat actors are reaping are helping to fuel the rise of a more sophisticated and well-armed hacker that is able to build greater expertise on the backend, so they have the capability to launch larger and more complex attacks.
We see cybercriminals now that lie between whats typically been nation-state attacks and nation-state capability in terms of sophistication like zero-days and these sorts of things thats now in the realm of cybercriminals, too, he said.
More money begets more sophisticated operations and methods think ransomware-as-a-service (RaaS) and that leads to not only more sophisticated campaigns but also more attackers. With RaaS offered by highly sophisticated groups, less skilled people can leverage such services to launch attacks.
All these cryptocurrency-fueled trends including the greater sophistication of cybercriminals driven by massive profits, the promise of payoffs and the expanding numbers of threat actors who can launch attacks has helped fuel the growing global problem of ransomware.
U.S. lawmakers, who this year have become more involved in the problem of ransomware as critical infrastructure including energy systems as seen in the attack on Colonial Pipeline and food supplies via the campaign as global meat processor JBS also are seeing the link between ransomware and cryptocurrency.
In October, several senators and representatives sent a letter to the departments of Justice, State and Homeland Security urging them to address among other things the role of cryptocurrencies in the rise of ransomware attacks, noting the anonymity the digital currencies give attackers.
Its important for enterprises to understand that link as well, Manky said. A key is prevention and protections like backing up data because once ransomware is in a system, they are forcing many companies that have few other options to pay in cryptocurrency. The exchanges put in protective measures, which drove up the cost to cybercriminals of attacking the exchanges. Given the increasingly distributed nature of IT, its important for enterprises to think about prevention and resiliency in a similar way.
If we dont do that its going to be very bleak, Manky said. Its going to continue to fund these cybercriminals. Their pockets are going to get deeper. Their capabilities are going to become more sophisticated. They have businesses of their own and like any business, as it grows, they add more and more people, more partners. In the 90s, it used to be one person. Then it was a handful of people. Now were seeing 50, 100 people with partners, even thousands in some of these organizations. Thats a big problem.
Further reading: Best Backup Solutions for Ransomware Protection
See the original post here:
The Link Between Ransomware and Cryptocurrency | eSecurityPlanet - eSecurity Planet
- Cryptocurrency News Round-Up: Bitcoin in Space & MtGox 2.0 [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- This week in bitcoin: Visualizing cryptocurrency [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- PotCoin cryptocurrency aiming to aid Colorados cash-only pot shops [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Crypto()Currency - CryptoCurrency.org [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- As Bitcoin Soars in Value, Alternative Cryptocurrencies ... [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Cryptocurrency - Wikipedia, the free encyclopedia [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Bitcoin vs. Political Power: The Cryptocurrency Revolution - Stefan Molyneux at TNW Conference - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- TNW - Stefan Molyneux - Money, Power and Politics The Cryptocurrency Revolution - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Bit coin and Cryptocurrency - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Atencoin is the First AML Compliant CryptoCurrency - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- How to Set Up a Ripple (CryptoCurrency) Generating System! - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Bitcoin / Cryptocurrency - An Extensive FAQ - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- --- The Great Debate --- Bitcoin vs Altcoin @ The CryptoCurrency Convention 4/9/14 - - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Bryce Weiner @ CryptoCurrency Convention 4/9/14 - - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Popularcoin @ CryptoCurrency Convention 4/9/14 - Joshua Nold - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- TimeKoin @ CryptoCurrency Convention 4/9/14 - Michael Brown - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Infinitecoin @ CryptoCurrency Convention 4/9/14 - Loring Small - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Bitcoin Exchange CryptoRush Loses Millions of BlackCoin Cryptocurrency - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Brock Pierce, Entrepreneur "FireSide Chat" @ CryptoCurrency Convention NYC - 4/9/14 - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Dogecoin Founder Speaks on the Future of Cryptocurrency [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- Flash Gordon Conquers the Universe 3 Captured by Shark Men (1940) - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- [OFFICIAL SPONSOR] Nick Spanos, Bitcoin Center NYC @ CryptoCurrency Convention 4/9/14 - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- AuroraCoin @ CryptoCurrency Convention NYC 4/9/14 - David Lio - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- Florincoin @ CryptoCurrency Convention NYC 4/9/14 - Joe Fiscella - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- DigiByte @ CryptoCurrency Convention NYC 4/9/14 - Jared Tate - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- Digitalcoin @ CryptoCurrency Convention NYC 4/9/14 - Andrew Davidson - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- PotCoin @ CryptoCurrency Convention NYC 4/9/14 - Nick Iversen - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- ZenithCoin @ CryptoCurrency Convention NYC 4/9/14 - Eddie Corral - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- BitAngels Co-Founder, David Johnson @ CryptoCurrency Convention NYC 4/9/14 - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- New York to Regulate Bitcoin: Is the Cryptocurrency Biz Like the Wild West? - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- Australian dogecoin founder speaks on the future of cryptocurrency [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- Cryptocurrency [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- How to Buy Bitcoins BTC Litecoins LTC Quarks QRK Cryptocurrency Altcoins - Video [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- Coinnext Cryptocurrency Exchange Coming Soon - Video [Last Updated On: April 30th, 2014] [Originally Added On: April 30th, 2014]
- Cryptocurrency News Round-Up: MtGox Hearing Begins as Bitcoin gets Bloomberg Endorsement [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- mTrader.org - Cryptocurrency Mining System - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Ripple XRP Decentralized CryptoCurrency Bitcoin Exchange Open-Sourced BlockChain - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Cryptocurrency News Round-Up: Transparent Exchange & Bitcoin Banks [Last Updated On: May 2nd, 2014] [Originally Added On: May 2nd, 2014]
- Bitcoin Cryptocurrency Crash Course with Andreas Antonopoulos - Jefferson Club Dinner Meet - Video [Last Updated On: May 2nd, 2014] [Originally Added On: May 2nd, 2014]
- MAX KEISER & ALEX JONES talks about BITCOIN - Is Cryptocurrency the FUTURE? - Video [Last Updated On: May 2nd, 2014] [Originally Added On: May 2nd, 2014]
- CryptoCurrency - cryptobars commodity Launch! - Video [Last Updated On: May 2nd, 2014] [Originally Added On: May 2nd, 2014]
- Coin Pursuit Launches SliceFeeds Interactive Cryptocurrency Network [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- CS 171 Final Project: Cryptocurrency Visualizations - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- The Mises View: "Taxing Cryptocurrency" | Jeff Deist - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Cryptocurrency Explained The Tech Guy 1046 - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Such Dogecoin. Much Validity. How one altcoin may have turned into cryptocurrencys best marketing tool [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- Cryptocurrency | Ground Zero with Clyde Lewis [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- Know How 74 Cryptocurrency - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- MIT undergrads will each receive $100 in bitcoin [Last Updated On: May 5th, 2014] [Originally Added On: May 5th, 2014]
- Bitcoin wins US election panel's approval for political donations [Last Updated On: May 9th, 2014] [Originally Added On: May 9th, 2014]
- CryptoCurrency of the World Unite! - Video [Last Updated On: May 10th, 2014] [Originally Added On: May 10th, 2014]
- The Bitcoin Stats Show - Ep 6: 16th April 2014 - Video [Last Updated On: May 10th, 2014] [Originally Added On: May 10th, 2014]
- Bitcoin vs. Political Power: The Cryptocurrency Revolution Stefan Molyneux at TNW Conferen - Video [Last Updated On: May 11th, 2014] [Originally Added On: May 11th, 2014]
- AMD cuts Radeon R9 280 price as inflation woes die down [Last Updated On: May 15th, 2014] [Originally Added On: May 15th, 2014]
- BBT Presents: Ode to Cryptocurrency - Video [Last Updated On: May 15th, 2014] [Originally Added On: May 15th, 2014]
- The Cryptocurrency Certification Consortium - Video [Last Updated On: May 15th, 2014] [Originally Added On: May 15th, 2014]
- Scryptify Cryptocurrency Video - Crypto Currency Exchanges - Video [Last Updated On: May 15th, 2014] [Originally Added On: May 15th, 2014]
- Bitpagar Cryptocurrency - Video [Last Updated On: May 16th, 2014] [Originally Added On: May 16th, 2014]
- How to Mine Cryptocurrency Safely - Video [Last Updated On: May 17th, 2014] [Originally Added On: May 17th, 2014]
- Bunnycoin - Innovative New Cryptocurrency - Video [Last Updated On: May 17th, 2014] [Originally Added On: May 17th, 2014]
- Cubieboard 1 2 Mining Peercoins SHA256 based Cryptocurrency - Video [Last Updated On: May 17th, 2014] [Originally Added On: May 17th, 2014]
- Megacoin Teaser Video New CryptoCurrency Bitcoin Best AltCoin 2014 Anonymous Zerocoin - Video [Last Updated On: May 17th, 2014] [Originally Added On: May 17th, 2014]
- Jan Irvin on Learning, Statism, Culture, Cryptocurrency and Voluntarism -- Potent News Podcast #1 - Video [Last Updated On: May 17th, 2014] [Originally Added On: May 17th, 2014]
- Nxt cryptocurrency platform: Proof of Stake mining system - Video [Last Updated On: May 19th, 2014] [Originally Added On: May 19th, 2014]
- Givecoin.info Announces Partnership with Do A Bit of Good: World's First Charitable Mining Screensaver [Last Updated On: May 21st, 2014] [Originally Added On: May 21st, 2014]
- Cryptocurrency: Get Mining! - Video [Last Updated On: May 22nd, 2014] [Originally Added On: May 22nd, 2014]
- Violincoin - The first cryptocurrency for musician - - Video [Last Updated On: May 22nd, 2014] [Originally Added On: May 22nd, 2014]
- Trollcoin - The Fun Cryptocurrency! - Video [Last Updated On: May 22nd, 2014] [Originally Added On: May 22nd, 2014]
- The Cryptocurrency Store (Spanish/Espagnol) - Video [Last Updated On: May 23rd, 2014] [Originally Added On: May 23rd, 2014]
- How To Trade CryptoCurrency: Sign up to a safe and reliable exchange for trading CryptoCurrency - Video [Last Updated On: May 23rd, 2014] [Originally Added On: May 23rd, 2014]
- UT students to launch cryptocurrency exchange [Last Updated On: May 24th, 2014] [Originally Added On: May 24th, 2014]
- Cryptocurrency and Nonprofits with Eric Nakagawa - Video [Last Updated On: May 24th, 2014] [Originally Added On: May 24th, 2014]
- The Cryptocurrency Store - Video [Last Updated On: May 24th, 2014] [Originally Added On: May 24th, 2014]
- Videoconferencia Cryptocurrency 201243946 - Video [Last Updated On: May 27th, 2014] [Originally Added On: May 27th, 2014]
- VideoCharla Jesus Ramos Cryptocurrency - Video [Last Updated On: May 27th, 2014] [Originally Added On: May 27th, 2014]
- Cryptocurrency Round-Up: Bitcoin Pioneer Dies and Digital Currency's Status in Australia [Last Updated On: September 1st, 2014] [Originally Added On: September 1st, 2014]
- Bleutrade Cryptocurrency Exchange Review - Video [Last Updated On: September 1st, 2014] [Originally Added On: September 1st, 2014]
- Bitcoin enthusiasts discuss the cryptocurrency - Video [Last Updated On: September 1st, 2014] [Originally Added On: September 1st, 2014]
- Make Fast 1.0 up to 10.00 BTC or Any Cryptocurrency REAL CASH - Video [Last Updated On: September 1st, 2014] [Originally Added On: September 1st, 2014]
- Halcyon cryptocurrency - Video [Last Updated On: September 1st, 2014] [Originally Added On: September 1st, 2014]