Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

3/17/2020
08:30 AM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
100%
0%

Many Ransomware Attacks Can be Stopped Before They Begin

The tendency by many attackers to wait for the right time to strike gives defenders an opening, FireEye says.

Many threat actors tend to lurk around compromised networks for days before deploying ransomware, giving victim organizations a chance to prevent the attacks if they can spot the initial activity quickly enough.

Researchers from FireEye Mandiant recently reviewed more than two years' worth of ransomware attack data to see what trends they could spot. The researchers wanted to identify common characteristics around initial intrusion vectors, average attacker dwell time on a compromised network, and the time of day when attackers typically tended to deploy ransomware.

Their study showed that in a majority of incidents, attackers waited at least three days after breaking into a network to identity key systems to target with their ransomware. Such post-compromise ransomware deployment is growing in popularity because it is often more damaging for victims and more profitable for attackers than other models, says Kelli Vanderlee, manager, intelligence analysis at FireEye.

By spending time in a victim environment, malicious actors are often able to identify important assets, like backups and network segments storing valuable data and key systems that can be used to disseminate their ransomware widely. "This more effective targeting and deployment gives the threat actors more leverage against a victim, allowing them to demand higher ransoms and net higher profits," Vanderlee says. Post-compromise reconnaissance also provides attackers with additional opportunities for follow-on activity, like data theft for sale or extortion.

At the same time, though, the dwell time between initial compromise and ransomware deployment gives organizations a chance to neutralize the attack before it even has a chance to unfold, Vanderlee says. "In most cases ransomware is not executed until days after the initial intrusion, which means it is possible for defenders to prevent ransomware encryption before it starts if they can catch the first signs of activity quickly enough," she says.

According to Vanderlee, the Ryuk ransomware family is most frequently deployed post-compromise. Other families deployed in a similar manner include Clop, Bitpaymer, Doppelpaymer, Lockergoga, Maze, and Sodinokibi.

Tactical Deployment Strategy
FireEye's research also showed that in more than three-quarters (76%) of the incidents, attackers deployed the ransomware on a victim network outside normal office hours. Twenty-seven percent of the attacks the security vendor studied happened on weekends. About half (49%) occurred before 8 a.m. or after 6 p.m. on weekdays. Less than a quarter (24%) took place during office hours.

Attackers appear to be favoring off-hours on the assumption that response and remediation would be slower. "When ransomware is executed during business hours, it is more likely that network defenders will be able to respond quickly, potentially stopping the spread of ransomware in a network or preventing additional executions," Vanderlee says. 

The trend highlights the need for emergency planning, Vanderlee says. Organizations need to have security technology and staff in place 24/7 in order to catch the first signs of malicious activity. They also need to have clear and redundant escalation plans so that when an incident happens, the correct stakeholders are notified as quickly as possible.

Drive-by-downloads, weak and unprotected Remote Desktop Protocol (RDP) services, and phishing with a malicious link or attachment were the most common initial infection vectors in the ransomware attacks in FireEye's study. RDP attacks, where threat actors log in remotely to a system on a target environment via the RDP protocol, were especially common in 2017,  but they appear to have declined somewhat in popularity since then.

Over the same period, phishing, in particular, and drive-by-downloads have gained in popularity as a way for attackers to try and get an initial foothold on a target network, FireEye said.

Last year ransomware attacks costs businesses and other organizations a staggering $11.5 billion in losses, as noted in a recent Deep Instinct report that cited that figure from Cybersecurity Ventures.  Among the most targeted were state and local government entities, critical infrastructure organizations, and entities in the healthcare sector.

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's featured story: "Beyond Burnout: What Is Cybersecurity Doing to Us?"

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
EUNQUE12
50%
50%
EUNQUE12,
User Rank: Apprentice
3/18/2020 | 8:22:44 AM
Ransomware ransom attacks
I think Ransomware ransom attacks double during Q2 2019.
keywordbookmarks@gmail.com
50%
50%
[email protected],
User Rank: Apprentice
3/18/2020 | 5:36:09 AM
Thanks for the informative post.
These are really amazing and valuable websites you have shared with us. Thanks for the informative post.
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5615
PUBLISHED: 2020-08-04
Cross-site request forgery (CSRF) vulnerability in [Calendar01] free edition ver1.0.0 and [Calendar02] free edition ver1.0.0 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2020-5616
PUBLISHED: 2020-08-04
[Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News01] free edition ver1.0.3 and earlier, [PKOBO-vote01] free edition ver1.0.1 and earlier, [Telop01] fre...
CVE-2020-5617
PUBLISHED: 2020-08-04
Privilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unauthorized privileges and modify/obtain sensitive information or perform unintended operations via unspecified vectors.
CVE-2020-11583
PUBLISHED: 2020-08-03
A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.
CVE-2020-11584
PUBLISHED: 2020-08-03
A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.