{"id":46367,"date":"2021-12-20T04:14:00","date_gmt":"2021-12-20T09:14:00","guid":{"rendered":"http:\/\/blog.cybercon1.com\/?p=46367"},"modified":"2021-12-20T04:14:00","modified_gmt":"2021-12-20T09:14:00","slug":"ransomware-in-2022-were-all-screwed","status":"publish","type":"post","link":"https:\/\/blog.cyberconservices.com\/index.php\/2021\/12\/20\/ransomware-in-2022-were-all-screwed\/","title":{"rendered":"Ransomware in 2022: We&#8217;re all screwed"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Written by\u00a0<a href=\"https:\/\/www.zdnet.com\/meet-the-team\/us\/charlie-osborne\/\">Charlie Osborne<\/a> &#8211; <strong>Ransomware<\/strong> is now a primary threat for businesses, and with the past year or so considered the &#8220;golden era&#8221; for operators, cybersecurity experts believe this criminal enterprise will reach new heights in the future.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zdnet.com\/article\/hr-platform-kronos-brought-down-by-ransomware-attack-ukg-warns-of-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">Kronos<\/a>.&nbsp;<a href=\"https:\/\/www.zdnet.com\/article\/colonial-pipeline-ransomware-attack-everything-you-need-to-know\/\" target=\"_blank\" rel=\"noreferrer noopener\">Colonial Pipeline<\/a>.&nbsp;<a href=\"https:\/\/www.zdnet.com\/article\/ransomware-meat-firm-jbs-says-it-paid-out-11m-after-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">JBS<\/a>.&nbsp;<a href=\"https:\/\/www.zdnet.com\/article\/updated-kaseya-ransomware-attack-faq-what-we-know-now\/\" target=\"_blank\" rel=\"noreferrer noopener\">Kaseya<\/a>. These are only a handful of 2021&#8217;s high-profile victims of threat groups including&nbsp;<a href=\"https:\/\/www.zdnet.com\/article\/darkside-the-ransomware-group-responsible-for-colonial-pipeline-cyberattack-explained\/\" target=\"_blank\" rel=\"noreferrer noopener\">DarkSide<\/a>,&nbsp;<a href=\"https:\/\/www.zdnet.com\/article\/revil-ransomware-group-resurfaces-after-brief-hiatus\/\" target=\"_blank\" rel=\"noreferrer noopener\">REvil<\/a>, and&nbsp;<a href=\"https:\/\/www.zdnet.com\/article\/blackmatter-ransomware-to-shut-down-affiliates-transferring-victims-to-lockbit\/\" target=\"_blank\" rel=\"noreferrer noopener\">BlackMatter<\/a>.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to Kela&#8217;s analysis of dark web forum activity, the &#8220;perfect&#8221; prospective\u00a0<a rel=\"noreferrer noopener\" href=\"https:\/\/www.zdnet.com\/article\/this-is-the-perfect-ransomware-victim-according-to-cybercriminals\/\" target=\"_blank\"><strong>ransomware<\/strong> victim in the US<\/a>\u00a0will have a minimum annual revenue of $100 million and preferred access purchases include domain admin rights, as well as entry into Remote Desktop Protocol (RDP) and Virtual Private Network (VPN) services.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Over the past few years, we&#8217;ve seen<strong> ransomwar<\/strong>e operators evolve from disorganized splinter groups and individuals to highly sophisticated operations, with separate teams collaborating to target everything from SMBs to software supply chains.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Ransomware<\/strong> infection is no longer an end goal of a cyberattack. Instead, malware families in this arena &#8212; including WannaCry, NotPetya, Ryuk, Cerber, and Cryptolocker &#8212; can be one component of attacks designed to elicit a blackmail payment from a victim organization.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cisco Secure calls current <strong>ransomware tactics <\/strong>&#8220;<a rel=\"noreferrer noopener\" href=\"https:\/\/www.zdnet.com\/article\/black-hat-enterprise-players-face-one-two-punch-extortion-tactics-in-ransomware-attacks\/\" target=\"_blank\">double-extortion<\/a>.&#8221; Victims will have their systems encrypted in one facet of an attack, and a ransom note will demand payment, normally in Bitcoin (BTC). However, to pile on the pressure, ransomware groups may also steal corporate data before decryption and will threaten to publish or sell on this information, too, unless a payment is agreed upon and made. \u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The European Union Agency for Cybersecurity (ENISA) said there was a 150% rise in <strong>ransomware<\/strong> attacks between April 2020 and July 2021. According to the agency, we are experiencing the &#8220;<a rel=\"noreferrer noopener\" href=\"https:\/\/www.zdnet.com\/article\/ransomware-its-a-golden-era-for-cyber-criminals-and-it-could-get-worse-before-it-gets-better\/\" target=\"_blank\">golden era of ransomware<\/a>,&#8221; in part due to multiple monetization options.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is particularly notable in &#8220;Big Game hunting&#8221; when<strong> ransomware<\/strong> operators will specialize in going after large and profitable companies.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With this in mind, what can we expect from <strong>ransomware<\/strong> operators in 2022?  <a href=\"https:\/\/www.google.com\/url?rct=j&amp;sa=t&amp;url=https:\/\/www.zdnet.com\/article\/ransomware-in-2022-were-all-screwed\/&amp;ct=ga&amp;cd=CAEYAioUMTA4NjU4OTA4MTI1MTMzMzE2MDQyGmY5NWQ3ZDU3NzU5MmRlMjE6Y29tOmVuOlVT&amp;usg=AFQjCNHFytwRb41He15an3sxEKE-LpeH4Q\">Read On:<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Written by\u00a0Charlie Osborne &#8211; Ransomware is now a primary threat for businesses, and with the past year or so considered the &#8220;golden era&#8221; for operators, cybersecurity experts believe this criminal enterprise will reach new heights in the future.\u00a0 Kronos.&nbsp;Colonial Pipeline.&nbsp;JBS.&nbsp;Kaseya. <span class=\"excerpt-dots\">&hellip;<\/span> <a class=\"more-link\" href=\"https:\/\/blog.cyberconservices.com\/index.php\/2021\/12\/20\/ransomware-in-2022-were-all-screwed\/\"><span class=\"more-msg\">Continue reading &rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":46368,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_seo_schema_type":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[636],"tags":[637],"class_list":["post-46367","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ransomware","tag-ransomware"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack-related-posts":[{"id":76717,"url":"https:\/\/blog.cyberconservices.com\/index.php\/2023\/04\/25\/ransomware-101-exploring-its-inner-workings\/","url_meta":{"origin":46367,"position":0},"title":"Ransomware 101: Exploring Its Inner Workings","author":"Rick Backus","date":"April 25, 2023","format":false,"excerpt":"Ransomware is a type of malicious software that encrypts files and demands payment for decryption. It is a growing threat to businesses and individuals, with increasingly sophisticated attack methods. Understanding how ransomware works is crucial to protecting yourself and your data.","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/blog.cyberconservices.com\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/blog.cyberconservices.com\/wp-content\/uploads\/2023\/04\/Kidnappers-1.png?fit=1024%2C1024&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/blog.cyberconservices.com\/wp-content\/uploads\/2023\/04\/Kidnappers-1.png?fit=1024%2C1024&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/blog.cyberconservices.com\/wp-content\/uploads\/2023\/04\/Kidnappers-1.png?fit=1024%2C1024&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/blog.cyberconservices.com\/wp-content\/uploads\/2023\/04\/Kidnappers-1.png?fit=1024%2C1024&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":44419,"url":"https:\/\/blog.cyberconservices.com\/index.php\/2020\/11\/30\/how-ransomware-defense-is-evolving-with-ransomware-attacks\/","url_meta":{"origin":46367,"position":1},"title":"How Ransomware Defense is Evolving With Ransomware Attacks","author":"Rick Backus","date":"November 30, 2020","format":false,"excerpt":"Ransomware became deadly in 2020. Healthcare facilities were attacked at an alarming rate, including one incident\u00a0in Germany\u00a0that lead to a patient death when an attack locked critical systems and a woman needing critical care was turned away. She died after she had to be taken to another city for treatment.\u00a0\u2026","rel":"","context":"In &quot;Ransomware&quot;","block_context":{"text":"Ransomware","link":"https:\/\/blog.cyberconservices.com\/index.php\/category\/ransomware\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/cdn.pixabay.com\/photo\/2017\/06\/19\/06\/56\/arrow-2418321__340.jpg?resize=350%2C200&ssl=1","width":350,"height":200},"classes":[]},{"id":46060,"url":"https:\/\/blog.cyberconservices.com\/index.php\/2021\/04\/01\/acer-reportedly-suffered-a-revil-ransomware-attack-attracting-the-highest-ransom-demand-in\/","url_meta":{"origin":46367,"position":2},"title":"Acer Reportedly Suffered a REvil Ransomware Attack Attracting the Highest Ransom Demand in &#8230;","author":"Rick Backus","date":"April 1, 2021","format":false,"excerpt":"Acer suffered a REvil\u00a0ransomware attack\u00a0that attracted the highest\u00a0ransomware demand\u00a0in history. The threat actor behind the attack shared some of the pilfered files as proof of responsibility. However, the Taiwanese electronic behemoth was reluctant to acknowledge a ransomware attack. Instead, the company cited \u201creported abnormal situations\u201d and claimed to be \u201cconstantly\u2026","rel":"","context":"In &quot;Ransomware&quot;","block_context":{"text":"Ransomware","link":"https:\/\/blog.cyberconservices.com\/index.php\/category\/ransomware\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/cdn.pixabay.com\/photo\/2014\/11\/01\/22\/33\/gold-513062__340.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/cdn.pixabay.com\/photo\/2014\/11\/01\/22\/33\/gold-513062__340.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/cdn.pixabay.com\/photo\/2014\/11\/01\/22\/33\/gold-513062__340.jpg?resize=525%2C300&ssl=1 1.5x"},"classes":[]},{"id":31457,"url":"https:\/\/blog.cyberconservices.com\/index.php\/2019\/03\/22\/avast-and-emsisoft-release-free-decrypters-for-bigbobross-ransomware\/","url_meta":{"origin":46367,"position":3},"title":"Avast and Emsisoft release free decrypters for BigBobRoss ransomware","author":"Rick Backus","date":"March 22, 2019","format":false,"excerpt":"By\u00a0Catalin Cimpanu\u00a0- Avast and Emsisoft, two cyber-security firms known for their antivirus products, released today free decrypters that can help victims of the BigBobRoss ransomware recover their files without paying the ransom demand. The two decrypters are available for download from the\u00a0Avast\u00a0and\u00a0Emsisoft\u00a0sites, respectively. The ransomware is one of the smaller\u2026","rel":"","context":"In &quot;Ransomware&quot;","block_context":{"text":"Ransomware","link":"https:\/\/blog.cyberconservices.com\/index.php\/category\/ransomware\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.cyberconservices.com\/wp-content\/uploads\/2019\/03\/bigbobross-ransom-note.png?resize=350%2C200","width":350,"height":200},"classes":[]},{"id":33252,"url":"https:\/\/blog.cyberconservices.com\/index.php\/2020\/03\/30\/ransomware-hits-healthcare-hardest-preys-on-smbs\/","url_meta":{"origin":46367,"position":4},"title":"Ransomware hits healthcare hardest","author":"Rick Backus","date":"March 30, 2020","format":false,"excerpt":"By Samantha Ann Schwartz - Ransomware\u00a0targeted healthcare more than any other industry, accounting for 29%\u00a0of total ransomware attacks in 2019, according to cyber insurer\u00a0Beazley's 2020 Breach Briefing report. Professional services (14%) and financial institutions (11%) rounded out the top three targets.\u00a0 Ransomware increased 131% from 2018 to 2019. About six\u2026","rel":"","context":"In &quot;Ransomware&quot;","block_context":{"text":"Ransomware","link":"https:\/\/blog.cyberconservices.com\/index.php\/category\/ransomware\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/cdn.pixabay.com\/photo\/2014\/12\/10\/20\/56\/medical-563427__340.jpg?resize=350%2C200&ssl=1","width":350,"height":200},"classes":[]},{"id":32953,"url":"https:\/\/blog.cyberconservices.com\/index.php\/2019\/10\/30\/ransomware-the-nightmare-before-cyber-monday\/","url_meta":{"origin":46367,"position":5},"title":"Ransomware: The Nightmare Before Cyber Monday","author":"Rick Backus","date":"October 30, 2019","format":false,"excerpt":"The number of ransomware attacks on enterprises is up 500% from this time last year. Threat actors are becoming increasingly sophisticated and targeted. Ransomware is a business, and these actors want to get paid.\u00a0 Researcher Madeline Cyr interviewed me to help retailers understand the threat of ransomware for the upcoming\u2026","rel":"","context":"In &quot;Ransomware&quot;","block_context":{"text":"Ransomware","link":"https:\/\/blog.cyberconservices.com\/index.php\/category\/ransomware\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.cyberconservices.com\/wp-content\/uploads\/2019\/10\/skull-307778__340-300x205.png?resize=350%2C200","width":350,"height":200},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/posts\/46367","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/comments?post=46367"}],"version-history":[{"count":0,"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/posts\/46367\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/media?parent=46367"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/categories?post=46367"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/tags?post=46367"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}