Bultenler
ENISA Threat Landscape for Ransomware Attacks
The European Union Agency for Cybersecurity (“ENISA”), published its report regarding Threat Landscape for Ransomware Attacks (“Report”). The Report aims to bring new insights into the reality of ransomware incidents through mapping and studying ransomware incidents from May 2021 to June 2022.
Introduction
The threat of ransomware has consistently ranked at the top in the ENISA Threat Landscape for the past few years and in 2021 it was assessed as being the prime cybersecurity threat across the EU. Motivated mainly by greed for money, the ransomware business model has grown exponentially in the last decade and it is projected to cost more than $10 trillion by 2025.
Even though ransomware is not new, technologies evolve and with them so do attacks and vulnerabilities, thus pressurizing organizations to be always prepared for a ransomware attack. In many cases, staying in business requires difficult decisions, such as paying or not paying the ransom, since this money ends up fuelling ransomware activities.
This report brings new insights into the ransomware threat landscape through a careful study of 623 ransomware incidents from May 2021 to June 2022. The incidents were analyzed in-depth to identify their core elements, providing answers to some important questions such as how the attacks happened, are ransom demands are being paid and which sectors are the most affected.
Focus on Ransomware
Ransomware is a type of attack where threat actors take control of a target’s assets and demand a ransom in exchange for the return of the asset’s availability and confidentiality.
There are four core actions ransomware can execute: lock, encrypt, delete, and steal. Agency refers to these four core actions as LEDS (Lock, Encrypt, Delete, Steal). Ransomware can lock access to an asset, such as locking the screen or lock access to a particular application. It can encrypt an asset, making it unavailable to the target. It can steal an asset, compromising its availability and in the end its confidentiality. Lastly, it can delete an asset, making it permanently unavailable.
Ransomware Life Cycle
The life cycle of ransomware remained unchanged until around 2018 when ransomware started to add more functionality and blackmailing techniques matured. ENISA can identify five stages of a ransomware attack: initial access, execution, action on objectives, blackmail, and ransom negotiation. These stages do not follow a strictly sequential path which can vary.
The European Union Agency for Cybersecurity, ENISA needs to clarify and highlight that ransom negotiation is not a suggested recommendation for victims of ransomware attacks. Contacting the competent cybersecurity authority and/or law enforcement is the recommended approach to handling such incidents.
- Initial Access
The first stage of a ransomware attack is the initial access to the target. Ransomware uses the same techniques for getting access as other attacks may use, including exploiting software vulnerabilities, access through stolen credentials, phishing and others.
- Execution
After initial access, threat actors may study the target, move laterally to other computers and employ attack techniques to ensure more assets are found to be exploited. This activity may take several weeks depending on the threat actor and the size and defences in place by the target. This movement is usually completed before the ransomware starts working, although when the ransomware starts it can also move laterally inside the victim’s network
Once the assets are located and before the ransomware is executed, there is usually a cleaning part where some actions are taken to ensure the correct working of the ransomware, such as: killing the security software, stopping programs like databases that can interfere with the writing, stop the recovery features of systems, shadow copies, logs, etc. The next step is the deployment of the ransomware.
- Action on Objectives
Once deployed, the ransomware attacks the availability and/or the confidentiality of the targeted assets through a series of actions. This stage is traditionally known as Action on Objectives. Ransomware actions are not immediate and can take place weeks after the initial infection of the system, giving attackers additional time to access more internal systems.
There is no guarantee that the encryption has been done correctly and that files could be decrypted after payment is completed. This is one additional reason why paying demand for ransom is not a recommended approach, since there are no guarantees that it will be effective.
- Blackmail
After the availability of assets has been compromised, the threat actor then proceeds to blackmail the target to obtain a ransom in return for the availability of the assets. The three main components of blackmail are communication, threat, and demand.
- Ransom Negotiation
The ransomware negotiation is generally a private communication, if any, between the target and the threat actors. ENISA needs to stress again that this is not a recommended step, nonetheless from an incident life cycle perspective Agency needs to examine it since it has taken place in some incident. There are two outcomes to this negotiation: targets pay the ransom or do not pay. It is not uncommon to hear that target organisations or individuals have successfully negotiated with the threat actors to lower the ransom money demanded.
Ransomware Business Models
Ransomware has significantly evolved, both technically and organisationally since the first incident was observed in 1989. With the new ransomware-as-a-service business models, almost anyone can conduct a ransomware attack. However, the ransomware organisation, like other malware underground, is complex, with multiple actors, roles, problems, solutions, and cultures.
- Individual Attackers
Initially, ransomware attacks were conducted by single individuals or very small groups. These ransomware attacks were less complex than attacks today, often focusing on automatic encryption that did not require operational coordination.
- Group Threat Actors
In what is now considered the traditional ransomware business model, a single group threat actor is composed of multiple individuals that share and split and coordinate all the stages of the operation: picking the target, analysing the target for vulnerabilities, conducting the attacks, producing the malware and infection, coordinating the file encryption keys, negotiating the ransom payment, and getting the revenue. The same group also generally develops all their tools, sets the payment system, and buys exploits or the information required to conduct successful attacks.
- Ransomware-as-a-Service (RaaS)
Ransomware-as-a-Service (RaaS) is a type of business model where threat actor groups offer their software platform to external affiliates to conduct attacks. The affiliate programme is operated by a threat actor group (RaaS operator) and it incorporates external affiliates that use the malware and payment platform.
The RaaS operators develop the ransomware and provide the software platform for affiliates to operate. The RaaS affiliates conduct the ransomware attacks, the payment negotiation, collect the ransom and also purchase additional exploits or information needed to conduct the attacks. This type of business model allows the RaaS operators to have multiple revenue streams.
RaaS has lowered the entry-level barrier to conduct ransomware attacks. Attackers now do not need to know how to write their own ransomware. They need to know only how to conduct an attack, and the RaaS operators will provide the ransomware and the platform to operate. Anyone can attack, and anyone can become a target.
- Data Brokerage
Ransomware threat actors are moving towards a new business model referred as Data Brokerage. In this model, threat actors take further advantage of the stolen data by selling it to the highest bidders.
- Notoriety as Key to a Successful Ransomware Business
Ransomware demands are mostly financially motivated. In order to succeed in the business, ransomware needs to demonstrate a guarantee that decryption will work. Usually, threat actors have mechanisms to show that the decryption works, such as decrypting sample files.
The ransomware operators need to maintain a certain reputation of notoriety, otherwise, victims will not pay the ransom. Many attackers promise that upon payment they will remove the companies from their websites, delete the stolen data and not leak data to the public. A report shows that in 18% of cases the companies that paid the ransom still got their data leaked, and 35% of the victims that paid the ransomware were unable to retrieve their data.
Negotiating with cyber criminals is not recommended and, in the case of ransomware incidents, contacting law enforcement and national cybersecurity authorities is the recommended course of action.
Analysis of Ransomware Incidents
A ransomware incident is a successful attack in which a threat actor manages to access a target, perform any LEDS action (Lock, Encrypt, Delete, Steal) on the target’s assets, and perform blackmail.
The analysis considers 623 ransomware incidents worldwide with a special focus on Europe, the United Kingdom, and the United States. These incidents were selected from news reports, the reports of security companies, government reports and the original sites of the ransomware threat actors. Each incident was explored in depth and confirmed from multiple sources.
ENISA estimated that the total number of incidents from May 2021 to June 2022 was 3,640. Since this report analyses 623 incidents, it therefore covers 17.11% of the total estimated cases in that time frame. All results and conclusions as presented should take into account this disclaimer concerning the number of incidents used in this analysis.
- Volume of Data Stolen
Of the 623 incidents included in the report, ENISA found proof of data leaks for 288, which is 46.2% of the total incidents. The total accumulated stolen data for all incidents is 136.3 TB with an average of 518 GB per incident and an average of 10 TB per month.
- Amount of Leaked Data
Of the 623 incidents analysed, evidence was found of partially leaked data in 62 incidents, 9.95% of the total incidents. Similarly, evidence was found of fully leaked data in 236 incidents, which is 37.88% of the incidents. In total, in almost half of the cases (47.83%) stolen data was leaked.
- Personal Data
The analysis shows that 58.2% of all the stolen data contains GDPR personal data. This personal data ranges from protected health information (PHI), passport numbers and visas, to addresses and covid status.
- Non-Personal Data
Additionally, 41.7% of the stolen data contains non-personal data. 19% of the stolen data contains financial information. More than 24% of the data stolen contains business information.
- Paid Ransom
From all the incidents analysed, it was not possible to confirm whether a ransom was paid in 588 cases, which is 94.2%. Out of the rest of the incidents in Agency’s analysis, 8 paid the ransom and 58 did not pay the ransom.
Recommendations
In this section Agency presents general recommendations that can help organisations deal better with the problem of ransomware. The recommendations focus on several key aspects: preparing against ransomware attacks and decreasing the impact of ransomware as well as the decision to pay.
- Resilience Against Ransomware
• Have a good and verified backup of all your business-critical files and personal data and keep it updated, and isolated from the network.
• Apply the 3-2-1 rule of backup. For all data: 3 copies, 2 different storage media, 1 copy offsite.
• Keep personal data encrypted according to the provisions of GDPR and using appropriate risk-based controls.
• Run security software in your endpoint devices that can detect most ransomware.
• Restrict administrative privileges: use caution when handing out administrative privileges as the admin account has access to everything, including changing configurations or bypassing critical security settings. Always employ the Principle of Least Privilege (PLOP) when granting any type of access.
• Familiarise yourself with local government agencies that provide assistance on ransomware incidents and define protocols to follow in case of an attack.
- Responding the Ransomware
Should an organization or an individual fall victim to ransomware attacks, several recommendations have been put forward, but the most important one is the first one, namely, to contact the authorities.
• Contact the national cybersecurity authorities or law enforcement on how to handle and how to deal with ransomware.
• Do not pay the ransom and do not negotiate with the threat actors.
• Quarantine affected systems: cutting off affected systems from the network is suggested in order to contain the infection and stop the ransomware from spreading.
• Visit The No More Ransom Project, a Europol initiative that can decrypt 162 variants of ransomware
• Lock down access to backup systems until after the infection gets removed
Conclusion
In general, ransomware security incidents are seldom reported. Most organisations prefer to deal with the problem internally and avoid bad publicity.
The lack of reliable data from targeted organisations makes it very hard to fully understand the problem or even know how many ransomware cases there are.
The study conducted on ransomware attacks from May 2021 to June 2022 showed that on average more than 10 terabytes of data a month were stolen by ransomware threat actors. The research shows that 58.2% of the stolen data contains personal data from employees.
In 94.2% of the incidents, it is not known whether the company paid the ransom or not. However, 37.88% of the incidents had their data leaked on the web pages of the attackers, indicating that the ransom negotiations failed. This allows us to estimate that approximately 62.12% of the companies might somehow have come to an agreement or solution concerning the ransom demand.
Ransomware is thriving, and the research shows that threat actors are conducting indiscriminate attacks. Companies of every size across all sectors are affected. Anyone can become a target. Agency urges organisations to prepare for ransomware attacks and consider possible consequences before attacks occur.
You can reach further information here.
Kind regards,
Zumbul Attorneys at Law
info@zumbul.av.tr
Türkçe
English