The Cyber Security Review | Thursday, December 01, 2022
Cyber criminals are testing a new method of cyber extortion.
FREMONT, CA:Hackers using ransomware are experimenting with a brand-new assault that destroys data rather than encrypting it. If the victims don't pay the ransom, it will be hard for them to get their data back. One of the major cybersecurity problems in the world today is ransomware, and while many victims choose not to comply with the extortionists' demands, many others feel forced to pay up to obtain a decryption key.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
However, at least one ransomware gang is reportedly testing data destruction operations.
While it is frequently possible to recover encrypted files without paying a ransom, this would be risky for ransomware victims because it might encourage more victims to give in under the threat of servers becoming completely corrupted if extortion demands aren't met. When responding to a BlackCat ransomware assault (also known as ALPHV), cybersecurity experts found the warning signs of a possible new strategy.
Ransomware thieves are constantly looking for new ways to make attacks more effective, and it appears they are exploring a new technique with software that deletes data. BlackCat has been linked to a spate of ransomware occurrences around the world.
Exmatter, a.NET exfiltration programme that was previously employed in BlackMatter ransomware attacks, is connected to data destruction. It's widely believed that Darkside, the ransomware operation responsible for the Colonial Pipeline attack, was rebranded as BlackMatter, which in turn was rebranded as BlackCat.
Before the ransomware was performed on the compromised systems and encrypting the files with a demand for payment for the key, Exmatter was used to upload specific file types from chosen directories to attacker-controlled servers.
The exfiltration programme appears to be used to corrupt and delete files rather than encrypt them. Cybercriminals may be trying this new strategy for several reasons. First, the prospect of erasing data rather than encrypting it may serve as an additional inducement for attack victims to make payments.
The possibility of not receiving the whole reward or that the victim would discover alternative methods to decrypt the data is eliminated by skipping the phase of encrypting the data, according to researchers at Cyderes. Additionally, creating damaging software is simpler than creating ransomware; as a result, conducting data destruction operations may require less time and resources, allowing attackers to make more money.
Creating malware designed to corrupt the files instead, renting a large server to receive exfiltrated files, and returning them upon payment is a far more development-intensive process. Data exfiltration and destruction are expected to be increasingly common experiments for extortion actors. Attacks from ransomware and malware can be quite destructive, but there are steps that businesses can take to strengthen their networks and defend against attacks.
These measures include promptly implementing security patches and upgrades to prevent hackers from using known vulnerabilities to launch attacks. They also ensure that multi-factor authentication is implemented across the network to safeguard users.
More in News