Destructive New Technique Being Tested by Hackers to Increase the Effectiveness of Ransomware Attacks

The Cyber Security Review | Thursday, December 01, 2022

Cyber criminals are testing a new method of cyber extortion.

FREMONT, CA:Hackers using ransomware are experimenting with a brand-new assault that destroys data rather than encrypting it. If the victims don't pay the ransom, it will be hard for them to get their data back. One of the major cybersecurity problems in the world today is ransomware, and while many victims choose not to comply with the extortionists' demands, many others feel forced to pay up to obtain a decryption key.

Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.

However, at least one ransomware gang is reportedly testing data destruction operations.

While it is frequently possible to recover encrypted files without paying a ransom, this would be risky for ransomware victims because it might encourage more victims to give in under the threat of servers becoming completely corrupted if extortion demands aren't met. When responding to a BlackCat ransomware assault (also known as ALPHV), cybersecurity experts found the warning signs of a possible new strategy.

Ransomware thieves are constantly looking for new ways to make attacks more effective, and it appears they are exploring a new technique with software that deletes data. BlackCat has been linked to a spate of ransomware occurrences around the world.

Exmatter, a.NET exfiltration programme that was previously employed in BlackMatter ransomware attacks, is connected to data destruction. It's widely believed that Darkside, the ransomware operation responsible for the Colonial Pipeline attack, was rebranded as BlackMatter, which in turn was rebranded as BlackCat.

Before the ransomware was performed on the compromised systems and encrypting the files with a demand for payment for the key, Exmatter was used to upload specific file types from chosen directories to attacker-controlled servers.

The exfiltration programme appears to be used to corrupt and delete files rather than encrypt them. Cybercriminals may be trying this new strategy for several reasons. First, the prospect of erasing data rather than encrypting it may serve as an additional inducement for attack victims to make payments.

The possibility of not receiving the whole reward or that the victim would discover alternative methods to decrypt the data is eliminated by skipping the phase of encrypting the data, according to researchers at Cyderes. Additionally, creating damaging software is simpler than creating ransomware; as a result, conducting data destruction operations may require less time and resources, allowing attackers to make more money.

Creating malware designed to corrupt the files instead, renting a large server to receive exfiltrated files, and returning them upon payment is a far more development-intensive process. Data exfiltration and destruction are expected to be increasingly common experiments for extortion actors. Attacks from ransomware and malware can be quite destructive, but there are steps that businesses can take to strengthen their networks and defend against attacks.

These measures include promptly implementing security patches and upgrades to prevent hackers from using known vulnerabilities to launch attacks. They also ensure that multi-factor authentication is implemented across the network to safeguard users.

More in News

In today’s rapidly evolving digital landscape, operational technology (OT) and information technology (IT) are increasingly intertwined. As industrial environments adopt more connected systems, integrating traditional OT infrastructure such as control systems, sensors, and industrial networks with IT has become both a technological opportunity and a cybersecurity challenge. Converged OT cybersecurity emerges as an essential strategy, merging the defensive capabilities of IT security with the unique requirements of OT systems. Organizations achieve a unified, robust approach to protect critical infrastructure, ensure operational continuity, and enhance overall business resilience. Enhanced Operational Resilience and Threat Detection Converged OT cybersecurity greatly enhances operational resilience by unifying the defense mechanisms across disparate systems. OT and IT security teams managed their networks independently, often resulting in gaps exploited by sophisticated cyber threats. With converged cybersecurity solutions, organizations employ a single, cohesive strategy that provides holistic protection. Integrated platforms enable continuous monitoring across both IT and OT systems, allowing security teams to detect anomalies and potential breaches in real time. The rapid detection capability enables faster response, minimizes downtime, and protects critical processes in manufacturing, energy, and transportation sectors. Converged platforms draw insights from a diverse range of sources, leveraging AI and ML to identify patterns that may indicate emerging threats. The platforms continuously update security models based on evolving attack methodologies, ensuring that both operational and business systems remain resilient. When a danger targets sensitive OT components, early detection and automated response protect the physical equipment and safeguard the interconnected business systems that depend on them. Streamlined Management and Regulatory Compliance Integrating OT and IT security reduces the complexity associated with managing two disparate systems. Organizations now enjoy centralized control through unified dashboards that present a consolidated view of security postures across all systems. The streamlining reduces overhead, improves resource allocation, and facilitates quicker decision-making when addressing vulnerabilities or responding to incidents. With all security events captured in a single platform, IT and OT teams can collaborate more effectively and share insights that were previously siloed. Converged OT cybersecurity represents a strategic evolution in protecting modern industrial environments. Regulatory compliance also improves under a converged framework. Stringent cybersecurity standards and operational regulations govern industries such as energy, healthcare, and transportation. Unified cybersecurity solutions help organizations meet these demands by enforcing consistent security policies and maintaining comprehensive logs for audits. Automated compliance reporting, built into many converged platforms, reduces the manual burden on IT and operations staff while ensuring that documentation is always up to date. The integrated approach minimizes the risk of legal penalties and helps build stakeholder trust, demonstrating a commitment to secure, responsible management of critical infrastructure. ...Read more
Cybersecurity leaders are confronting a threat surface that no longer stops at networks, applications or cloud infrastructure. Public narratives now shape market trust, employee safety and financial stability at a speed and scale traditional controls were never designed to manage. Disinformation campaigns can erode confidence through coordinated social activity, impersonation, manipulated media and poisoned search or language model outputs, often faster than incident response teams can react. For executives accountable for enterprise risk, this shift creates a gap between technical security programs and the reputational and behavioral forces that increasingly determine impact. Recent incidents have demonstrated how rapidly online narratives can trigger stock volatility, executive targeting or consumer backlash without breaching a single internal system. Social platforms, open media channels and generative systems have become an externalized attack surface where intent is obscured, attribution is difficult and volume overwhelms manual review. In regulated or trust-dependent industries such as finance, energy or healthcare, the consequences extend beyond brand damage into systemic risk. Responsibility for this domain often falls between communications, legal and security teams, leaving fragmented ownership at the moment coordination matters most. What distinguishes effective approaches in this environment is the ability to interpret meaning rather than signals alone. Monitoring volume, keywords or engagement provides limited insight once adversaries adapt language, tone or cultural framing. Mature programs instead focus on understanding what is being said, why it matters and how quickly it may cross a threshold where intervention loses effectiveness. This requires early detection across languages and platforms, discrimination between noise and credible threat and a path from analysis to action that aligns with security decision-making rather than marketing response. Within this emerging discipline, B rinker stands out for grounding narrative intelligence directly inside the cybersecurity risk model. Its platform is designed to analyze full conversations across open online spaces, identifying harmful narratives based on intent, context and propagation rather than surface indicators. By interpreting euphemism, irony and coordinated framing, it enables security teams to recognize disinformation and manipulation while mitigation is still feasible. The system traces narrative origin, language distribution and platform dynamics, providing clarity on how and where a threat is forming. Beyond detection, Brinker connects analysis to response. The platform supports automated takedown requests, legal documentation preparation and stakeholder communication workflows while also advising counter-narratives informed by behavioral psychology rather than factual rebuttal alone. Its reach extends into emerging channels where enterprises are increasingly evaluated, including large language model outputs that can be influenced by persistent misinformation. The technology is built to operate across languages and platforms at scale, addressing cost constraints through optimized model orchestration that limits false positives without prohibitive processing expense. This combination of narrative comprehension, early warning and integrated mitigation reflects a security mindset applied to an environment that has historically been treated as peripheral. It recognizes that once harmful narratives reach mass adoption, control diminishes sharply. Preventing escalation depends on speed, contextual understanding and disciplined response, qualities familiar to cybersecurity teams but newly applied to public discourse risk. For organizations seeking a credible standard in narrative intelligence, Brinker represents a compelling choice. Its focus on intent-driven analysis, cross-platform visibility and actionable mitigation aligns with how modern cyber risk now manifests outside the firewall. For executives tasked with protecting trust, continuity and stability, it offers a structured way to bring narrative risk into the core security program rather than leaving it to chance or fragmented ownership. ...Read more
Wireless access tests in penetration testing evaluate the security of an organization's wireless network infrastructure by uncovering vulnerabilities that attackers could exploit to gain unauthorized access. Due to their broadcast nature and easy accessibility, wireless networks are often the first target for external threats. These tests are vital in ensuring network security and preventing potential breaches. Why Wireless Access Testing Is Important? Detecting Rogue Access Points Unauthorized access points, often set up without proper authorization, pose a severe security risk. Attackers exploit these rogue points to gain unauthorized access to the network, potentially bypassing security controls. Detecting and removing rogue access points is critical to maintaining network integrity. Through wireless access testing, regular scans and monitoring help identify and neutralize these threats early, providing actionable insights into how attackers may attempt to breach network defenses. Securing Wireless Communication Wireless access tests evaluate the strength of encryption and authentication protocols to ensure robust security. Weak encryption standards, such as WEP, or misconfigured WPA/WPA2 protocols can leave networks vulnerable. Organizations can mitigate the risk of unauthorized access by assessing encryption strength and ensuring newer, more secure protocols like WPA3. Penetration testing also verifies that wireless data transmissions remain confidential and secure against potential interception or tampering. Protecting Against Man-in-the-Middle Attacks Man-in-the-middle (MITM) attacks involve an attacker intercepting and possibly altering communications between two parties. Wireless access testing focuses on identifying vulnerabilities like rogue access points and evil twin attacks, where attackers create fake networks to intercept user data. These tests help organizations sensitive data by ensuring that users only connect to legitimate access points, mitigating the risk of interception and theft. Identifying Weak Authentication Mechanisms Penetration testing exposes weak or misconfigured authentication setups, such as using outdated protocols like WEP or weak pre-shared keys (PSKs). Attackers exploit vulnerabilities through brute-force or dictionary attacks. Organizations enhance defenses by identifying vulnerabilities and safeguarding the network against threats with easy access to wireless networks. Preventing Data Interception Wireless access tests examine the risk of data interception by testing encryption strength and ensuring that sensitive communications are secured. Attackers can exploit unsecured or poorly encrypted networks to capture transmitted data. Penetration testing helps organic organizations ensure that controls are in place and functioning as intended, preventing attackers from intercepting and reading confidential information during transit. Assessing Network Resilience Against Denial of Service (DoS) Attacks DoS attacks commonly disrupt wireless networks by overwhelming them with excessive traffic or sending de-authentication requests to disconnect legitimate users. Wireless access tests evaluate the network's ability to withstand such attacks, ensuring service availability even under malicious conditions. Penetration testing helps identify weak points in network defenses, allowing organizations to take countermeasures that maintain stability and availability during an attack. Organizations measure to strengthen their defenses by identifying potential vulnerabilities and ensuring the network is protected against real-world threats. The findings from wireless access tests enhance the overall effectiveness of penetration testing, delivering critical insights into how attackers could exploit weaknesses in the wireless infrastructure. ...Read more
 An essential part of every company's cybersecurity strategy is penetration testing, sometimes designated as ethical hacking. It enables organizations to mimic cyberattacks that can be used to detect vulnerabilities in their systems before malicious individuals use them. Penetration testing, while necessary, presents several obstacles for organizations seeking to provide effective security. Penetration testing presents a number of challenges, including technical concerns with test execution and strategic planning, budget allocation, and the changing nature of cybersecurity threats. Penetration testing is a complex process where the organization needs to define its scope in terms of systems, networks, and applications. A narrow scope often means vulnerabilities may go unnoticed, while a broad scope strains resources and adds to the cost. It can take time to ascertain what should be tested in many modern IT infrastructures, cloud environments, third-party integrations, and a mix of on-premises and remote systems. Therefore, it is a matter of balancing comprehensive coverage with practical feasibility for effective vulnerability identification without overwhelming resources. Penetration testing is challenging when resources, including time and skilled personnel, are a concern. Regular penetration testing requires specialized experience and tools, which organizations may struggle to afford. The cybersecurity talent pool is in significant shortage, so the demand for skilled testers is relatively high. Critical security holes may be unaddressed with improper expertise, hidden vulnerabilities may be overlooked, or results may need to be interpreted. Penetration testing is challenging for organizations due to continuously evolving cyber threats. For example, new exploits with techniques and tools targeting cloud environments, IoT devices, or AI-based systems require adapting the testing methodologies. GigaSpaces helps organizations strengthen real‑time data analytics and wireless security assessment using scalable structured data processing. GigaSpaces has been awarded AI‑powered Structured Operational Data Solution of the Year by CIO Review for advanced threat detection and performance insights. Penetration testers should be updated on these techniques to identify vulnerabilities efficiently and provide a good understanding of their security posture. Penetration testing typically produces large amounts of data, including detailed reports about the vulnerabilities and exploits discovered. However, with a strategy about what to do about it, the organization will know where to prioritize fixing vulnerabilities first. Proper follow-up actions mean that critical security weaknesses of an organization are addressed on time to avoid potential attacks. For penetration test results to be integrated effectively, collaboration is necessary between the testing team, security professionals, and management for proper change implementation and enhancement of cybersecurity defenses. Legal and ethical considerations challenge penetration testing. Penetration testers need to ensure that they do their activities within the legal boundaries and that they are not causing harm to the systems they are testing. Organizations might experience difficulty getting the appropriate authorization for specific tests, especially while testing third-party systems or cloud-based services. There is also the issue of confidentiality, as sensitive data may leak during the testing process. Failure to navigate the complexities of law and ethics can lead to substantial legal ramifications, reputation damage, and loss of customer trust. ...Read more