Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Partner Perspectives  Connecting marketers to our tech communities.
7/1/2015
11:05 AM
Vincent Weafer
Vincent Weafer
Partner Perspectives
50%
50%

Franchising Ransomware

Ransomware-as-a-service is fueling cyberattacks. Is your organization prepared?

Got a great business idea? Want to expand with less risk? Build a good product, develop some training, put them together into a repeatable formula, and collect the royalties from your franchisees. This model, used successfully for everything from fast food to hair salons to tax preparation, is now available for criminal ransomware.

Cybercriminals have long been making their tools available to others, whether due to pride of authorship or as a means of raking in some extra cash. However, the ransomware-as-a-service model is relatively new and has resulted in a massive increase in ransomware attacks (as reported in the latest quarterly Threats Report). CTB-Locker and Tox are two examples of how malware uses different business models to flood the Internet with attacks, trying to catch more victims before threat notices, signature updates, and other defensive measures catch up.

Since the servers for CryptoLocker were taken down last year, CTB-Locker has become one of the most common sources of ransomware attacks. CTB-Locker uses an affiliate program to drive growth and revenue. Criminals who sign up as an affiliate get the tools to distribute this ransomware to their own selection of targets and collect 70% of the resulting revenue. Distribution vectors are typically phishing emails such as delivery notifications and fake software updates. Once your files are encrypted, you are left with .bmp, .txt, and .html files that contain information on how to pay the ransom to get your files back. Removing the malware is relatively easy. However, decrypting the files, which are encrypted with RSA 2,048-bit private-key encryption, is close to impossible. Payment is expected in Bitcoin, which preserves the criminal’s anonymity.

Malware For Hire

Tox is another ransomware that is growing in popularity. The authors of Tox offer a ransomware kit that requires very little in the way of technical skills. Simply provide the ransom amount and “cause” for which you are fundraising, and you get your own executable file. Install or distribute as you see fit for a mere 20% of your gross ransoms, also payable in Bitcoin. Both Tox and CTB-Locker use the TOR network to get their encryption keys and hide the IP addresses of their servers to avoid the fate of CryptoLocker and evade endpoint security systems.

Bitcoin and other virtual currencies are an important part of ransomware. By protecting anonymity, data kidnappers can go after more lucrative targets, which might otherwise have the ability to track down the perpetrators. As a result, these attacks are shifting from consumer systems to business systems, in the hopes of getting more and bigger ransoms. Many organizations appear to be paying ransoms to get their data back, validating the model and fueling further attacks.

Ransomware has evolved and is spreading quickly, but it can be stopped. Frequent backups and user awareness remain the best protection against ransomware, followed by multipoint defenses. Anti-spam systems will catch many of the phishing emails, especially if they are configured to detect and block compressed files and executables. Consider blocking TOR network connections to prevent the ransomware from getting the encryption keys. Finally, keep system patches up to date and advanced security features configured and enabled on the endpoints. 

Vincent Weafer is Senior Vice President of Intel Security, managing more than 350 researchers across 30 countries. He's also responsible for managing millions of sensors across the globe, all dedicated to protecting our customers from the latest cyber threats. Vincent's team ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
gsatpathy
50%
50%
gsatpathy,
User Rank: Apprentice
1/22/2016 | 10:43:58 AM
prevent the ransomware
I think there should be a way to prevent the ransomware without blocking TOR network connections.
Joe Stanganelli
0%
100%
Joe Stanganelli,
User Rank: Ninja
7/2/2015 | 6:03:09 AM
Re: I agree
Stuff like this always reminds me of that classic New Yorker cartoon...

upload.wikimedia.org/wikipedia/en/f/f8/Internet_dog.jpg
Blog Voyage
100%
0%
Blog Voyage,
User Rank: Strategist
7/2/2015 | 2:51:00 AM
I agree
"Bitcoin and other virtual currencies are an important part of ransomware". Oh damn right !
News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-3493
PUBLISHED: 2021-04-17
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivile...
CVE-2021-3492
PUBLISHED: 2021-04-17
Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (ker...
CVE-2020-2509
PUBLISHED: 2021-04-17
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later Q...
CVE-2020-36195
PUBLISHED: 2021-04-17
An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia C...
CVE-2021-29445
PUBLISHED: 2021-04-16
jose-node-esm-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed `JWEDe...