{"id":6611,"date":"2017-02-13T17:31:31","date_gmt":"2017-02-14T01:31:31","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/02\/13\/news-430\/"},"modified":"2017-02-13T17:31:31","modified_gmt":"2017-02-14T01:31:31","slug":"news-430","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2017\/02\/13\/news-430\/","title":{"rendered":"2016 Stat: 75% of ransomware comes from Russian-speaking criminal underground"},"content":{"rendered":"<p><strong>Credit to Author: Jeffrey Esposito| Date: Tue, 14 Feb 2017 00:30:43 +0000<\/strong><\/p>\n<p>The annual RSA conference will often overwhelm the average attendee. Between the great talks, the exhibition hall, the parties, and the city of San Francisco itself, there is a whole lot to take in.<\/p>\n<p> <a href=\"https:\/\/blog.kaspersky.com\/files\/2017\/02\/russian-ransomware-featured-1.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blog.kaspersky.com\/files\/2017\/02\/russian-ransomware-featured-1.jpg\" alt=\"2016 Stat: 75% of ransomware comes from Russian-speaking criminal underground\" width=\"1280\" height=\"840\" class=\"aligncenter size-full wp-image-14038\" \/><\/a> <\/p>\n<p>It typically takes <em>some<\/em> time for the talks to really pick up and build up steam to drop a fact that makes you say\u2026<b><em>wow<\/b><\/em> or <b><em>damn<\/b><\/em>. However, this year, it took me all of six hours from landing in the city from frigid Boston.<\/p>\n<p>While sitting in the <a href=\"https:\/\/www.rsaconference.com\/blogs\/rsac-2017-ransomware-summit\" target=\"_blank\">RSAC 2017 Ransomware Summit<\/a>, I was floored when I heard <a href=\"https:\/\/twitter.com\/antonivanovm\" target=\"_blank\">Anton Ivanov<\/a>, a senior malware analyst at Kaspersky Lab, drop the following tidbit.<\/p>\n<p>Out of the 62 crypto ransomware families discovered by the company&#8217;s researchers in the past year, 47 of them were developed by Russian-speaking cybercriminals \u2014 that&#8217;s a whopping 75%. What makes that figure even more staggering is that these ransomware families according to Kaspersky Lab telemetry attacked more than 1.4 million people around the globe in 2016.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"550\">\n<p lang=\"en\" dir=\"ltr\">We released decryption tool for <a href=\"https:\/\/twitter.com\/hashtag\/CryptXXX?src=hash\">#CryptXXX<\/a> (&quot;.crypt&quot;, &quot;.cryp1&quot;, &quot;.crypz&quot;). In most cases full decryption is possible! <a href=\"https:\/\/t.co\/qAlWUlDHVE\">pic.twitter.com\/qAlWUlDHVE<\/a><\/p>\n<p>&mdash; Anton Ivanov (@antonivanovm) <a href=\"https:\/\/twitter.com\/antonivanovm\/status\/811136563123986432\">December 20, 2016<\/a><\/p>\n<\/blockquote>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Over the course of his talk, Anton delved into the research that the team conducted, breaking down the aspects of criminal involvement with ransomware (outside of the whole ransomware-being-a-crime thing).<\/p>\n<ul>\n<li>Creation and updating of ransomware families.<\/li>\n<li>Affiliate programs to distribute ransomware.<\/li>\n<li>Participation in affiliate programs as a partner.<\/li>\n<\/ul>\n<div id=\"attachment_14037\" style=\"width: 1010px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/blog.kaspersky.com\/files\/2017\/02\/ransomware-business-structure.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blog.kaspersky.com\/files\/2017\/02\/ransomware-business-structure.png\" alt=\"The structure of a professional ransomware group contains the malware writer, affiliate program owners, partners of the program, and the manager who connects them all into one invisible enterprise\" width=\"1000\" height=\"815\" class=\"size-full wp-image-14037\" \/><\/a><\/p>\n<p class=\"wp-caption-text\">The structure of a professional ransomware group contains the malware writer, affiliate program owners, partners of the program, and the manager who connects them all into one invisible enterprise<\/p>\n<\/div>\n<p>What really stood out to me on this was, if we know so much about this type of crime, why do we still see it? As Ivanov notes, it really comes down to the money and barriers to entry into this business. <em>If you are interested in a more technical read on this, I suggest hopping over <a href=\"https:\/\/securelist.com\/analysis\/publications\/77544\/a-look-into-the-russian-speaking-ransomware-ecosystem\" target=\"_blank\">to Securelist, where this research was broken out more thoroughly<\/a>.<\/em><\/p>\n<p>If you think about it, this talk and topic was quite fitting to sit in on given that this city once housed some bad dudes in an isolated prison in the Bay.<\/p>\n<h2>Protecting yourself against ransomware<\/h2>\n<ol>\n<li>Back up your files religiously. You can do this to the cloud or to an external device. I do both, but remember if you are logged in or the external drive is connected, ransomware can lock them as well.<\/li>\n<li>Install antivirus that monitors for ransomware. Kaspersky Total Security and Kaspersky Internet Security both employ <a href=\"https:\/\/blog.kaspersky.com\/ransomware-protection-video\/8765\/\" target=\"_blank\">System Watcher, which monitors for the kind of suspicious activity<\/a> that is often associated with a ransomware attack.<\/li>\n<li> Don&#8217;t open attachments from unknown senders. Be selective about who you trust in terms of opening documents and clicking links that came via e-mail.<\/li>\n<\/ol>\n<div data-track=\"{&quot;category&quot;:1894,&quot;id&quot;:13657,&quot;post_author&quot;:&quot;Jeffrey Esposito&quot;,&quot;post_id&quot;:14036,&quot;post_pub_date&quot;:&quot;2017-02-14&quot;,&quot;post_categories&quot;:&quot;Special Project, Threats&quot;,&quot;post_tags&quot;:&quot;crypto-ransomware, GReAT, Ransomware, research&quot;}\" class=\"kasbanner-banner kasbanner-image\">     <a title=\"KIS-trial-ransomware banner\" target=\"_blank\" href=\"https:\/\/special.s.kaspersky-labs.com\/s2if53l8zel58sede5kd\/kis16.0.0.614a%20bcen_9092.exe\"><img decoding=\"async\" src=\"https:\/\/kasperskycontenthub.com\/daily-global\/files\/2016\/12\/ransomware_EN-1.png\"><\/a> <\/div>\n<p>If you are infected with ransomware and have not backed up your files, please <b>do not<\/b> pay the ransom. Instead visit <a href=\"https:\/\/www.nomoreransom.org\/\" target=\"_blank\">No More Ransom<\/a>, our collaborative project with law enforcement agencies and even some competitors to help eradicate ransomware.<\/p>\n<p><a href=\"https:\/\/blog.kaspersky.com\/russian-ransomware\/14036\/\" target=\"bwo\" >https:\/\/blog.kaspersky.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Jeffrey Esposito| Date: Tue, 14 Feb 2017 00:30:43 +0000<\/strong><\/p>\n<p>Three-quarters of crypto-ransomware in 2016 came from the Russian-speaking criminal underground.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10425,10378],"tags":[11323,10458,3765,1931,10444,10438],"class_list":["post-6611","post","type-post","status-publish","format-standard","hentry","category-kaspersky","category-security","tag-crypto-ransomware","tag-great","tag-ransomware","tag-research","tag-special-project","tag-threats"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6611","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=6611"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6611\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=6611"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=6611"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=6611"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}