Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Partner Perspectives  Connecting marketers to our tech communities.
7/1/2015
11:05 AM
Vincent Weafer
Vincent Weafer
Partner Perspectives
50%
50%

Franchising Ransomware

Ransomware-as-a-service is fueling cyberattacks. Is your organization prepared?

Got a great business idea? Want to expand with less risk? Build a good product, develop some training, put them together into a repeatable formula, and collect the royalties from your franchisees. This model, used successfully for everything from fast food to hair salons to tax preparation, is now available for criminal ransomware.

Cybercriminals have long been making their tools available to others, whether due to pride of authorship or as a means of raking in some extra cash. However, the ransomware-as-a-service model is relatively new and has resulted in a massive increase in ransomware attacks (as reported in the latest quarterly Threats Report). CTB-Locker and Tox are two examples of how malware uses different business models to flood the Internet with attacks, trying to catch more victims before threat notices, signature updates, and other defensive measures catch up.

Since the servers for CryptoLocker were taken down last year, CTB-Locker has become one of the most common sources of ransomware attacks. CTB-Locker uses an affiliate program to drive growth and revenue. Criminals who sign up as an affiliate get the tools to distribute this ransomware to their own selection of targets and collect 70% of the resulting revenue. Distribution vectors are typically phishing emails such as delivery notifications and fake software updates. Once your files are encrypted, you are left with .bmp, .txt, and .html files that contain information on how to pay the ransom to get your files back. Removing the malware is relatively easy. However, decrypting the files, which are encrypted with RSA 2,048-bit private-key encryption, is close to impossible. Payment is expected in Bitcoin, which preserves the criminal’s anonymity.

Malware For Hire

Tox is another ransomware that is growing in popularity. The authors of Tox offer a ransomware kit that requires very little in the way of technical skills. Simply provide the ransom amount and “cause” for which you are fundraising, and you get your own executable file. Install or distribute as you see fit for a mere 20% of your gross ransoms, also payable in Bitcoin. Both Tox and CTB-Locker use the TOR network to get their encryption keys and hide the IP addresses of their servers to avoid the fate of CryptoLocker and evade endpoint security systems.

Bitcoin and other virtual currencies are an important part of ransomware. By protecting anonymity, data kidnappers can go after more lucrative targets, which might otherwise have the ability to track down the perpetrators. As a result, these attacks are shifting from consumer systems to business systems, in the hopes of getting more and bigger ransoms. Many organizations appear to be paying ransoms to get their data back, validating the model and fueling further attacks.

Ransomware has evolved and is spreading quickly, but it can be stopped. Frequent backups and user awareness remain the best protection against ransomware, followed by multipoint defenses. Anti-spam systems will catch many of the phishing emails, especially if they are configured to detect and block compressed files and executables. Consider blocking TOR network connections to prevent the ransomware from getting the encryption keys. Finally, keep system patches up to date and advanced security features configured and enabled on the endpoints. 

Vincent Weafer is Senior Vice President of Intel Security, managing more than 350 researchers across 30 countries. He's also responsible for managing millions of sensors across the globe, all dedicated to protecting our customers from the latest cyber threats. Vincent's team ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
gsatpathy
50%
50%
gsatpathy,
User Rank: Apprentice
1/22/2016 | 10:43:58 AM
prevent the ransomware
I think there should be a way to prevent the ransomware without blocking TOR network connections.
Joe Stanganelli
0%
100%
Joe Stanganelli,
User Rank: Ninja
7/2/2015 | 6:03:09 AM
Re: I agree
Stuff like this always reminds me of that classic New Yorker cartoon...

upload.wikimedia.org/wikipedia/en/f/f8/Internet_dog.jpg
Blog Voyage
100%
0%
Blog Voyage,
User Rank: Strategist
7/2/2015 | 2:51:00 AM
I agree
"Bitcoin and other virtual currencies are an important part of ransomware". Oh damn right !
Data Privacy Protections for the Most Vulnerable -- Children
Dimitri Sirota, Founder & CEO of BigID,  10/17/2019
Sodinokibi Ransomware: Where Attackers' Money Goes
Kelly Sheridan, Staff Editor, Dark Reading,  10/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18214
PUBLISHED: 2019-10-19
The Video_Converter app 0.1.0 for Nextcloud allows denial of service (CPU and memory consumption) via multiple concurrent conversions because many FFmpeg processes may be running at once. (The workload is not queued for serial execution.)
CVE-2019-18202
PUBLISHED: 2019-10-19
Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. A remote attacker can check for the existence of paths and file names via crafted HTTP requests.
CVE-2019-18209
PUBLISHED: 2019-10-19
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.
CVE-2019-18198
PUBLISHED: 2019-10-18
In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by a local attacker to corrupt memory, aka CID-ca7a03c41753.
CVE-2019-18197
PUBLISHED: 2019-10-18
In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclo...