RaaS: Threat to Security World
The world today is facing the biggest cybersecurity threat that is Ransomware, with the potential to significantly affect whole societies and economies – and the attacks are unrelenting.
The impetus to the sudden recent spike in ransomware attacks, was the dramatic shift from a linear attack model, to an insidious multi-dimensional Ransomware-as-a-Service model. Overall, there is a 51% increase in ransomware incidents reported in 2022-H1 compared to previous year 2021.
Ransomware-as-a-Service ecosystem is evolving with sophisticated double and triple extortion tactics [Data exfiltration, DDoS] and a wide range of ransomware campaigns through affiliates. This is leading to higher probability of monetization and further rise in attack campaigns. Ransomware as a Service is an adoption of the Software as a Service business model.
Like all Software-as-a-Service solutions, Ransomware-as-a-Service users don't need to be skilled or even experienced, to proficiently use the tool. Ransomware-as-a-Service solutions, therefore, empower even the most novel hackers to execute highly sophisticated cyberattacks. Ransomware-as-a-Service solutions pay their affiliates very high dividends.
Threat actors are continuing to exploit known vulnerabilities, compromised credentials of remote access services and phishing campaigns for initial access into the infrastructure of organizations as well as citizens.
Reputable Ransomware-as-a-Service developers create software with a high chance of penetration success and a low chance of discovery. Once the ransomware is developed, it is modified to a multi-end user infrastructure. The software is then ready to be licensed to multiple affiliates. The revenue model for Ransomware-as-a-Service solutions mirrors Software-as-a-Service products, affiliates can either sign up with a one-time fee or a monthly subscription. Some Ransomware-as-a-Service solutions don't have monetary entry requirements and affiliates can sign up on a commission basis.
Major sectors affected in H1 2022
Majority of the attacks are observed in the Data Centres/IT/ITeS sector followed by Manufacturing and Finance sectors. Ransomware groups have also targeted critical infrastructure in H1 2022 including Oil & Gas, Transport, Power
Ransomware attacks are evolving with increased use of legitimate tools like “AnyDesk” for remote administration, which ensure continued command and control by the attacker. For cloud-based systems, ransomware groups are wiping the data instead of encrypting, after data exfiltration. Secondly, for cloud -based systems, ransomware groups are wiping the data instead of encrypting, after data exfiltration.
Ransomware-as-a-service has become a popular business model in the cybercrime ecosystem. Ransomware-as-a-service allows cybercriminals to easily deploy ransomware attacks without any knowledge of coding or hacking needed.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.