Intro
No matter where I go or whom I talk to, Ransomware always comes up. The part that gets me is that people are still spitting out myths, are simply getting facts wrong, or are still thinking & acting as if it is 6-8 years ago. The Ransomware landscape has changed and some people are not taking it seriously.
Ransomware payouts in the US are estimated at almost $600 million for the first 6 months of 2021 alone.
The darknet has RaaS or Ransomware-As-A-Service, making it extremely easy for someone to create their own Ransomware campaign.
I spoke to someone last week that said “Backups are the best defense against Ransomware’ I didn’t want to burst his bubble but I had to lay down a few facts for him. Let me break them down here too.
So what is the problem?
Most people, CEOs, CSOs, or even IT Managers and even outsourced MSPs see a ransomware event as:
- Attackers send you a phishing link or “hacks” you through RDP
- A payload is downloaded
- Your files are encrypted
- You pay to get your files back or you restore your data from backup.
If you are lucky enough, that is all that will happen.
Modern-day Ransomware.
This is where things start to get scary. What actually happens is:
- Threat actor gains access to your network using an exploit, phishing campaign, or unpatched public-facing service.
- Threat actor spends up to 3 months on your network looking for & exfiltrating data. This can be files, emails, databases, etc.
- A ransomware payload is then detonated with the highest privileges possible to maximize impact and grab the attention of exco/management.
- Negotiations begin, not for you to get your data back, but to prevent your data from being made publicly available on darknet sites.
The issue is, most of the management & IT folk tend to think that File Encryption was the only thing that happened on the network. They don’t think about the data exfiltration, the collecting of passwords, targeting of staff members, or even, suppliers & customers. Ransomware has become an extortion platform, and you now need to prevent your data from getting out into the wild or being used in other fraud campaigns. Imagine the GDPR/POPI implications of this.
So how do you really get infected with Ransomware?
This might be a little long for this post, but let’s just say, it is not only Phishing that is going to get you Some avenues that get these nasty payloads onto your endpoints:
- Software Pirating sites.
- Drive-by exploits making use of Exploit Kits
- Password reuse and password leaks.
- Publishing services that you shouldn’t (RDP)
- Not patching your public-facing services
This is just to name a few.
The initial payload you get will set up a C2 framework for the attacker to remotely connect to your network and start browsing around. Other portions of the payload will grab stored credentials, cookies, and other misc data and send that off for later use.
The attacker can then send multiple payloads to the network to further dig in, persist, and elevate privilege. Most Ransomware groups actually have specific playbooks around how to do this.
If you were clever enough to have a Security Operations center or some decent EDR you would be able to detect these actions and at least have a fighting chance.
Final words
I have spent countless hours in the trenches sifting through logs, analyzing payloads, helping some random employee get her life back, investigating fraud and so much more because of a ransomware attack that someone thought just about file encryption.
If you want to know more, please feel to reach out for a training session or speaking engagement. The more you know the better equipped you will be to handle your own events.
