Earlier quoted context omitted.
Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.
https://en.wikipedia.org/wiki/History_of_firefighting#Rome Fire fighting in Rome had a similar premise.
80% of orgs that paid the ransom were hit again
131–140 of 386 posts
Re: 80% of orgs that paid the ransom were hit again
#132Looks like ransomware criminals are going for the subscription model.
Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.
Re: 80% of orgs that paid the ransom were hit again
#133“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…
This has nothing to do with that idea.
The reason the orgs paid the random once was because they had a severe lack of backup and other data safety protocols in combination with a vector to be infected (from all what we know, the latter is common and difficult to avoid): paying the ransom is likely their only choice to maintain the business.
It is not surprising at all that these orgs can and will be infected again, and will continue to show a lack in the security and data safety departments, and so they will continue to pay ransoms.
It's sort of an inverse survivorship bias: if you get infected once because you're susceptible, you're likely to get infected again unless you fix your susceptibility.
Re: 80% of orgs that paid the ransom were hit again
#134Earlier quoted context omitted.
Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.
Makes more sense if the group offered a subscription model for decrypting files encrypted by that group. Then you wouldn't have to keep paying the big lump sum.
Re: 80% of orgs that paid the ransom were hit again
#135Earlier quoted context omitted.
Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.
If only there were organizations who weren't criminals at all and who could be paid by a company to maintain backups of the company's data.
Re: 80% of orgs that paid the ransom were hit again
#136Earlier quoted context omitted.
It appears that some of the major ransomware gangs are operating from Russia and are tolerated by the government, as long as they don't hit domestic targets. The US cannot really send special forces there without risking a massive escalation.
I'm sure the US has hundreds of spies and personnel in Russia at any point in time. But sending a spy to a software developers house and assassinating them probably isn't going to stop the problem - more people will spring up doing the same.
Russia has always been notoriously hard to spy on.
I would not be surprised if there was only a handful of well placed assets and most of the spying being done electronically.
Re: 80% of orgs that paid the ransom were hit again
#137Looks like ransomware criminals are going for the subscription model.
Re: 80% of orgs that paid the ransom were hit again
#138Earlier quoted context omitted.
Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.
If only organizations would backup their own data. Then they could just restore and avoid paying. I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.
Some of these guys encrypt over a period of time which is long enough to exceed the backup rotation. Their code decrypts on request, until the trigger day, when it posts the banners and deletes itself.
Re: 80% of orgs that paid the ransom were hit again
#139Earlier quoted context omitted.
It doesn’t even have to be the same attacker. The attacker could just as easily sell the info to another attacker. Plus, if the original vuln used to gain access is still open, there’s no reason why somebody else doesn’t find it later.
Which vulnerability did the attackers use to gain initial access? Do the attackers disclose this along with decrypting the data? And are you sure they didn't leave a sleeper Trojan behind for later?
Re: 80% of orgs that paid the ransom were hit again
#140Doesnt this just mean that 80% of orgs that were hit with ransomware attacks just didn't bother to fix their infosec, and got hit again because they left the same holes open to be exploited? Fool me once, shame on you. Fool me twice, shame on me.