{"id":5803,"date":"2017-01-18T22:14:05","date_gmt":"2017-01-18T22:14:05","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/01\/18\/news-18\/"},"modified":"2017-01-18T22:14:05","modified_gmt":"2017-01-18T22:14:05","slug":"news-18","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/01\/18\/news-18\/","title":{"rendered":"Everyone Is $$$ To Cybercriminals Using Ransomware"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"169\" src=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/01\/money-children-300x169.gif\" class=\"attachment-medium size-medium wp-post-image\" alt=\"Everyone Is A Source Of Revenue For Criminals Using Ransomware\" style=\"float: left; margin-right: 5px;\" srcset=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/01\/money-children-300x169.gif 300w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/01\/money-children-768x432.gif 768w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/01\/money-children-1024x576.gif 1024w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/01\/money-children-640x360.gif 640w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/01\/money-children-900x506.gif 900w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/01\/money-children-440x248.gif 440w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/01\/money-children-380x214.gif 380w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>I used to love sitting on the floor and watching Saturday morning cartoons. One of my favorite gags was when a character got really, really hungry. In order to emphasize the point, everything and everyone around them turned to food.<\/p>\n<p>The newspaper stand owner became a large hand. The baby in a stroller was suddenly a roast chicken. The parent rolling that stroller was a hot dog.<\/p>\n<p>Everything in the scene reinforced the point that eating something was an all-consuming thought.<\/p>\n<p>Cybercriminals think of Internet users in a similar way.<\/p>\n<p>When a criminal looks around, they see every internet user turned to Dollars, Yen, Euros, and Yuan. All of these users are there to nourish the criminal\u2019s wallet instead of their stomach.<\/p>\n<p>This is the comparison that came to mind as I read through <a href=\"http:\/\/blog.trendmicro.com\/organization-prepared-extortionists-come-calling\/\">Jon\u2019s summary<\/a> of the <a href=\"http:\/\/www.databreachtoday.com\/whitepapers\/2016-ransomware-response-study-w-2983\">ISMG survey on ransomware<\/a>.<\/p>\n<h3><strong>53% And Rising<\/strong><\/h3>\n<p>The survey lays out a dismal landscape. More than 50 percent of those polled have been victims of ransomware in some way, shape, or form recently. Nineteen percent are being attack more than 50 times per month and a disturbing 42 percent don\u2019t know how often they\u2019re being attacked with ransomware.<\/p>\n<p>These stats should be major warning flags for defenders.<\/p>\n<p>Despite our efforts, users are still being attacked by ransomware and we\u2019re only going to see an increase in efforts in 2017.<\/p>\n<p>Even though predictions are usually hit or miss (though I like to think <a href=\"http:\/\/www.trendmicro.com\/vinfo\/us\/security\/research-and-analysis\/predictions\/2017\">Trend Micro\u2019s<\/a> are a tiny bit more accurate), I\u2019m confident making that statement. I\u2019ll even go a step further. In 2017 we\u2019re going to see more variants, attacks, and high profile payouts.<\/p>\n<p>The reason is simple: <b>money<\/b>.<\/p>\n<h3><strong>1 Billion Or More<\/strong><\/h3>\n<p>In early 2016, Mikko Hypponen <a href=\"https:\/\/audioboom.com\/posts\/4550088-ransom-trojans-and-mac-security-with-mikko\">spoke to a statistic<\/a> pulled from research done at F-Secure. <a href=\"https:\/\/twitter.com\/mikko\">Mikko<\/a> said that the 40 criminal gangs they were tracking had pulled in $300 million Euros (~$318 million USD) over the past two years (covering 2014\u20132015). That\u2019s about $13 million USD a month.<\/p>\n<p>Looking back at 2016, speculation has the total take home for criminals at <b>1 billion USD<\/b> and\u2014as stated in <a href=\"http:\/\/www.csoonline.com\/article\/3154714\/security\/ransomware-took-in-1-billion-in-2016-improved-defenses-may-not-be-enough-to-stem-the-tide.html?linkId=33051801\">the article<\/a> \u2014I think that might be low.<\/p>\n<p>That\u2019s a 1 billion reasons to continue to invest in this type of crime. And the investment needed to run these campaigns continues to drop as we\u2019ve seen the necessary tools available for sale or rent on the underground.<\/p>\n<p>That level of availability has removed the technical knowledge requirements from running a campaign. No specialized knowledge needed, low risk, and a big payoff? That\u2019s a dream combination for criminals.<\/p>\n<h3><strong>Scaling A Criminal Campaign<\/strong><\/h3>\n<p>Investment in these campaigns is easy to justify\u2014well, easy to a criminal\u2014because of the extremely low cost of scaling out these crimes.<\/p>\n<p>In the physical world, with each additional victim there is additional risk for criminals. With each crime committed, law enforcement gathers more evidence, continues to build a case, and is more and more likely to capturing or stop the criminals.<\/p>\n<p>Cybercrimes are fundamentally different.<\/p>\n<p>Each victim adds evidence but it\u2019s almost an exact duplicate of the previous victims because the entire process is automated. Once the basic infrastructure of a ransomware campaign is setup there\u2019s near zero cost or risk to attack more victims.<\/p>\n<p>This imbalance results in cybercriminals infecting as many victims as possible in order to increase their profits. And why wouldn\u2019t they? If attacking another victim is as easy as changing a number in a tool or adding a new email address to a list, the only reason not to scale up a campaign is to avoid detection.<\/p>\n<p>Given the low odds of being caught, prosecuted, and convicted, there\u2019s little deterrent for criminals.<\/p>\n<h3><strong>No More Ransomware<\/strong><\/h3>\n<p>The only way that we\u2019ll see less ransomware attacks in 2017 and beyond is if the economics change.<\/p>\n<p>We know that there\u2019s nothing substantial that we can do to reduce the cost of launching attacks. The technology is out there and it continues to improve. What will be effective is reducing the profit that criminals are making from these efforts. The only way to do that is to refuse to pay.<\/p>\n<p>That\u2019s the official recommendation from almost every security company and law enforcement agency, Trend Micro included.<\/p>\n<p>I whole heartedly agree with that position but also understand the dilemma facing people and organizations whose critical data has been encrypted and that they can no longer access.<\/p>\n<p>But looking at the bigger picture, the only way that ransomware will stop is if it\u2019s not a massive profit centre for criminals. If they continue to make millions\u2014if not billions\u2014then there is simply too much money at stake to stop.<\/p>\n<p>How has ransomware impacted you or your business? Let me know on Twitter where <a href=\"https:\/\/twitter.com\/marknca\">I\u2019m @marknca<\/a> or <a href=\"https:\/\/ca.linkedin.com\/in\/marknca\">on LinkedIn<\/a>.<\/p>\n<p><a href=\"http:\/\/blog.trendmicro.com\/everyone-is-to-cybercriminals-using-ransomware\/\" target=\"bwo\" >http:\/\/feeds.trendmicro.com\/TrendMicroSimplySecurity<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"169\" src=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/01\/money-children-300x169.gif\" class=\"attachment-medium size-medium wp-post-image\" alt=\"Everyone Is A Source Of Revenue For Criminals Using Ransomware\" style=\"float: left; margin-right: 5px;\" srcset=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/01\/money-children-300x169.gif 300w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/01\/money-children-768x432.gif 768w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/01\/money-children-1024x576.gif 1024w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/01\/money-children-640x360.gif 640w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/01\/money-children-900x506.gif 900w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/01\/money-children-440x248.gif 440w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/01\/money-children-380x214.gif 380w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>I used to love sitting on the floor and watching Saturday morning cartoons. One of my favorite gags was when a character got really, really hungry. In order to emphasize the point, everything and everyone around them turned to food. The newspaper stand owner became a large hand. The baby in a stroller was suddenly&#8230;<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10413],"tags":[4503,3765,714,10423],"class_list":["post-5803","post","type-post","status-publish","format-standard","hentry","category-security","category-trendmicro","tag-cybercrime","tag-ransomware","tag-security","tag-underground-economy"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/5803","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=5803"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/5803\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=5803"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=5803"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=5803"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}