HomeTechnologyRansomware as a Service,...

Ransomware as a Service, a “Modern and Efficient” Business Model for Criminals

Experienced criminals post their services online for interested attackers. | Font: Photo by Mika Baumeister on Unsplash

adUnits.push({
code: ‘Rpp_tecnologia_mas_tecnologia_Nota_Interna1’,
mediaTypes: {
banner: {
sizes: (navigator.userAgent.match(/iPhone|android|iPod/i)) ? [[300, 250], [320, 460], [320, 480], [320, 50], [300, 100], [320, 100]] : [[300, 250], [320, 460], [320, 480], [320, 50], [300, 100], [320, 100], [635, 90]]
}
},
bids: [{
bidder: ‘appnexus’,
params: {
placementId: ‘14149971’
}
},{
bidder: ‘rubicon’,
params: {
accountId: ‘19264’,
siteId: ‘314342’,
zoneId: ‘1604128’
}
},{
bidder: ‘amx’,
params: {
tagId: ‘MTUybWVkaWEuY29t’
}
},{
bidder: ‘oftmedia’,
params: {
placementId: navigator.userAgent.match(/iPhone|android|iPod/i) ? ‘22617692’: ‘22617693’
}
}]
});

Destruction on Thursday of the attacking network ransomware hivewhich extorted close to $100 million from more than 1,500 victims around the world, shows how hacking has become a super-efficient niche industry that can enable anyone to become a cyber artist.

The operation was carried out in coordination with the police forces of the United States, Germany and the Netherlands, as well as with Europol, said the director of the US Federal Police (FBI), Christopher Wray.

modern business model

hive operates in a mode that cybersecurity experts call “ransomware as a service”, or RaaSwhen a company offers its software and methods to others for extortion purposes.

The model is fundamental to the ecosystem ransomware a broader one in which actors specialize in one skill or function, maximizing efficiency.

According to Ariel Ropek, director of cyberthreat intelligence at cybersecurity firm Avertium, this structure allows criminals with minimal computing skills to step into the game. ransomware pay others for their experience.

“There are quite a few of them,” Ropek said of the operations RaaS. “This is really a business model these days,” he added.

How it works

On the so-called “dark web”, a part of the Internet that regular browsers cannot access, ISPs ransomware and maintain an open display of their products.

At one extreme are initial access brokers who specialize in access to corporate or institutional computer systems and then sell that access to a hacker or system operator. ransomware.

But the operator depends on the developers RaaS What hivewho have programming skills to create the malware needed to perform the operation and bypass security countermeasures.

In general, their programs are once inserted by the operator ransomware in the target’s IT systems – manipulated to freeze the target’s files and data using encryption.

Developers RaaS What hive they offer a full range of services to operators in exchange for a large portion of the ransom paid, Ropek said.

“Their goal is to operate ransomware be as complete as possible,” he said.

polite but firm

when ransomware installed and activated, the target receives a message about what to do and how much to pay for decrypting their data.

This ransom can range from thousands to millions of dollars, depending on the financial strength of the target.

Inevitably, the target tries to negotiate with the portal, but often not very far.

Cybersecurity firm Menlo Security published last year a conversation between a target and a “sales team” hive took place on a special portal for victims.

It contains an operator hive politely and professionally offered to prove that the decryption would work on the test file.

But when the target offered a portion of the required $200,000, hive he was firm and insisted on paying the full amount.

Finally, the agent hive he relented and offered a substantial discount. “The price is $50,000. This is the final amount. What else can I say?” he wrote.

If the target organization refuses to pay, developers RaaS they have support: they threaten to post or sell hacked confidential files on the Internet.

hive maintains a separate website, hivesto publish the data.

Behind the business, Ropek says, are specialized fundraising operations that help members get their share of the ransom.

humble hit

action on thursday against hive it was only a modest blow to the industry RaaS.

There are many other specialists in ransomwareLooks like hivewhich are still working.

The biggest threat today is LockBeatwhich attacked Britain’s Royal Mail in early January and a Canadian children’s hospital in December.

In November, the US Department of Justice stated that LockBeat he received tens of millions of dollars in ransom from thousands of victims.

And it is not difficult for operators hive start again. “It’s a relatively simple process of setting up new servers, generating new encryption keys. There is usually some kind of rebranding going on,” Ropek said. (AFP)

We recommend you METADATA, an RPP technology podcast. News, analytics, reviews, recommendations and everything you need to know about the world of technology.

Source: RPP

- A word from our sponsors -

Most Popular

LEAVE A REPLY

Please enter your comment!
Please enter your name here

More from Author

- A word from our sponsors -

Read Now

Blackpink becomes the first K-pop group to reach 2.3 billion views with MV

Years later, Blackpink secured another record with "DDU-DDU-DU", a track that received a music video on June 15, 2018Another record for Blackpink! The K-Pop female group exceeded 2.3 billion views on “DDU-DDU-DDU” MV on May 10, becoming the first K-pop group to reach such a Views brand...

5 tourist points of the doramas you need to know

City of Hometown Cha Cha Cha? Goblin Port? Discover some sights in South Korea that appeared in doramasHave you ever dreamed of visiting the amazing places that appear in your favorite doramas? In South Korea, there are several sights that set a scenario for these exciting stories....

‘A Minecraft movie’ gets a date to reach digital platforms

See when 'a Minecraft Movie' can be watched from your home TV when released for rent and purchase on digital platforms'A Minecraft movie' has a date to reach digital platforms! The information was confirmed by Warner Bros. This Monday, 12, stating that Live-action can be watched in...

Council of International Circulation Organization

The Council of the International Civil Aviation Organization (ICAO) entrusted Russia with responsibility for the rhythm of the passenger aircraft MH17 in July 2014. .in_text_content_22 {width: 300px; Height: 600px; } @Media (min-width: 600px) {.in_text_content_22 {width: 580px; Height: 400px; }} .Adsbygoogle {Touch-Action: Manipulation; } ...

Romania candidate Simion did not capture the debate and attacker of journalists

George Simion did not come to the debate and attacked journalists. .in_text_content_22 {width: 300px; Height: 600px; } @Media (min-width: 600px) {.in_text_content_22 {width: 580px; Height: 400px; }} .Adsbygoogle {Touch-Action: Manipulation; } On Monday, 19:00, the Digi24 Romanian television channel organized the key...

Hollywood actor will appear on BTS’s Jin program on YouTube

Find out what is the Hollywood star that will make special participation in 'Run Jin', BTS's Jin Variety ProgramThe Variety Program of Jinfrom BTS, on Youtube, will be attended by a Hollywood star as special guest: the American actor Tom Cruise!The information was confirmed on Monday, 12,...

New Netflix romantic drama debuts today, 12

Learn more about 'Taste of Love', Netflix's new drama that features a story of romance between Kang Ha-Neul and GO Min-SI charactersOn Monday, 12, Netflix brought to its catalog the debut episode of "Taste of Love", the new South Korean dorama (as the K-Drama in Brazil) of...