Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

3/17/2020
08:30 AM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
100%
0%

Many Ransomware Attacks Can be Stopped Before They Begin

The tendency by many attackers to wait for the right time to strike gives defenders an opening, FireEye says.

Many threat actors tend to lurk around compromised networks for days before deploying ransomware, giving victim organizations a chance to prevent the attacks if they can spot the initial activity quickly enough.

Researchers from FireEye Mandiant recently reviewed more than two years' worth of ransomware attack data to see what trends they could spot. The researchers wanted to identify common characteristics around initial intrusion vectors, average attacker dwell time on a compromised network, and the time of day when attackers typically tended to deploy ransomware.

Their study showed that in a majority of incidents, attackers waited at least three days after breaking into a network to identity key systems to target with their ransomware. Such post-compromise ransomware deployment is growing in popularity because it is often more damaging for victims and more profitable for attackers than other models, says Kelli Vanderlee, manager, intelligence analysis at FireEye.

By spending time in a victim environment, malicious actors are often able to identify important assets, like backups and network segments storing valuable data and key systems that can be used to disseminate their ransomware widely. "This more effective targeting and deployment gives the threat actors more leverage against a victim, allowing them to demand higher ransoms and net higher profits," Vanderlee says. Post-compromise reconnaissance also provides attackers with additional opportunities for follow-on activity, like data theft for sale or extortion.

At the same time, though, the dwell time between initial compromise and ransomware deployment gives organizations a chance to neutralize the attack before it even has a chance to unfold, Vanderlee says. "In most cases ransomware is not executed until days after the initial intrusion, which means it is possible for defenders to prevent ransomware encryption before it starts if they can catch the first signs of activity quickly enough," she says.

According to Vanderlee, the Ryuk ransomware family is most frequently deployed post-compromise. Other families deployed in a similar manner include Clop, Bitpaymer, Doppelpaymer, Lockergoga, Maze, and Sodinokibi.

Tactical Deployment Strategy
FireEye's research also showed that in more than three-quarters (76%) of the incidents, attackers deployed the ransomware on a victim network outside normal office hours. Twenty-seven percent of the attacks the security vendor studied happened on weekends. About half (49%) occurred before 8 a.m. or after 6 p.m. on weekdays. Less than a quarter (24%) took place during office hours.

Attackers appear to be favoring off-hours on the assumption that response and remediation would be slower. "When ransomware is executed during business hours, it is more likely that network defenders will be able to respond quickly, potentially stopping the spread of ransomware in a network or preventing additional executions," Vanderlee says. 

The trend highlights the need for emergency planning, Vanderlee says. Organizations need to have security technology and staff in place 24/7 in order to catch the first signs of malicious activity. They also need to have clear and redundant escalation plans so that when an incident happens, the correct stakeholders are notified as quickly as possible.

Drive-by-downloads, weak and unprotected Remote Desktop Protocol (RDP) services, and phishing with a malicious link or attachment were the most common initial infection vectors in the ransomware attacks in FireEye's study. RDP attacks, where threat actors log in remotely to a system on a target environment via the RDP protocol, were especially common in 2017,  but they appear to have declined somewhat in popularity since then.

Over the same period, phishing, in particular, and drive-by-downloads have gained in popularity as a way for attackers to try and get an initial foothold on a target network, FireEye said.

Last year ransomware attacks costs businesses and other organizations a staggering $11.5 billion in losses, as noted in a recent Deep Instinct report that cited that figure from Cybersecurity Ventures.  Among the most targeted were state and local government entities, critical infrastructure organizations, and entities in the healthcare sector.

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's featured story: "Beyond Burnout: What Is Cybersecurity Doing to Us?"

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
keywordbookmarks@gmail.com
50%
50%
[email protected],
User Rank: Apprentice
3/18/2020 | 5:36:09 AM
Thanks for the informative post.
These are really amazing and valuable websites you have shared with us. Thanks for the informative post.
EUNQUE12
50%
50%
EUNQUE12,
User Rank: Apprentice
3/18/2020 | 8:22:44 AM
Ransomware ransom attacks
I think Ransomware ransom attacks double during Q2 2019.
Commentary
How SolarWinds Busted Up Our Assumptions About Code Signing
Dr. Jethro Beekman, Technical Director,  3/3/2021
News
'ObliqueRAT' Now Hides Behind Images on Compromised Websites
Jai Vijayan, Contributing Writer,  3/2/2021
News
Attackers Turn Struggling Software Projects Into Trojan Horses
Robert Lemos, Contributing Writer,  2/26/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-28042
PUBLISHED: 2021-03-05
Deutsche Post Mailoptimizer 4.3 before 2020-11-09 allows Directory Traversal via a crafted ZIP archive to the Upload feature or the MO Connect component. This can lead to remote code execution.
CVE-2021-28041
PUBLISHED: 2021-03-05
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
CVE-2021-3377
PUBLISHED: 2021-03-05
The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.
CVE-2021-3420
PUBLISHED: 2021-03-05
A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory allocation functions mEMALIGn, pvALLOc, nano_memalign, nano_valloc, nano_pvalloc could case an integer overflow, leading to an allocation of a small buffer and then to a heap-based buffer overflow.
CVE-2020-29020
PUBLISHED: 2021-03-05
Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured credentials. This issue affects: Secomea SiteManager All versions prior to 9.4.620527004 on Hardware.