Ransomware threats see major resurgence

(Image credit: Carlos Amarillo / Shutterstock)

Ransomware is making a comeback according to a new report from McAfee which observed that ransomware samples grew by 118 percent during the first quarter of this year as cybercriminals adopted new tactics to evade detection.

The cybersecurity firm's McAfee Labs Threats Report: August 2019 saw an average of 504 new threats per minute during Q1 alongside changes in ransomware campaign execution and code. Additionally over 2.2bn stolen account credentials were made available on the dark web over the course of the quarter and 68 percent of targeted attacks utilized spear-phishing for initial access while 77 percent relied on user actions to execute their campaigns.

McAfee fellow and chief scientist, Raj Samani stressed the fact that every cyberattack has a human cost, saying:

“The impact of these threats is very real. It’s important to recognize that the numbers, highlighting increases or decreases of certain types of attacks, only tell a fraction of the story. Every infection is another business dealing with outages, or a consumer facing major fraud. We must not forget for every cyberattack, there is a human cost.” 

Ransomware resurgence

McAfee Advanced Threat Research (ATR) also observed innovations in how cybercriminals launch ransomware campaigns with shifts in initial access vectors, campaign management and technical innovations in their code.

In Q1 2019, ransomware attacks increasingly targeted exposed remote access points such as Remote Desktop Protocol (RDP). RDP credentials were either purchased on the dark web or cracked through brute-force attacks and they can be used to gain admin privileges to distribute and execute malware on corporate networks.

McAfee researchers also observed how the cybercriminals behind ransomware attacks began to use anonymous email services to manage their campaigns instead of the traditional approach of setting up command-and-control (C2) servers.

Dharma (also known as Crysis), GandCrab and Ryuk were the most active ransomware families during the first quarter of this year with other notable ransomware families including Anatova (which McAfee exposed before it spread) and Scarab.

Lead scientist and senior principal engineer at McAfee, Christiaan Beek provided further insight on ransomware's resurgence, saying:

“After a periodic decrease in new families and developments at the end of 2018, the first quarter of 2019 was game on again for ransomware, with code innovations and a new, much more targeted approach. Paying ransoms supports cybercriminal businesses and perpetuates attacks. There are other options available to victims of ransomware. Decryption tools and campaign information are available through tools such as the No More Ransom project.” 

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Biometrics add another layer of security to passwordless authentication
Data leak
Hacked Tata Technologies data leaked by ransomware gang
Latest in News
Cristin Milioti in Black Mirror season 7
Netflix launches trailer for Black Mirror season 7, giving us a look at its first-ever sequel episode and an unexpected returning character
A graphic of the PC Gaming Show
Get ready for a bounty of PC games on June 8, as the PC Gaming show is back
A close up of The Daily podcast from Pocket Casts' web page
‘Podcasting shouldn’t be locked behind walled gardens’: Pocket Casts slams Spotify and makes its web player free to all
A smartphone on a sofa showing the WhatsApp, Telegram and Signal apps
Forget AI – WhatsApp is planning a simple messages feature that could be its most useful upgrade in years
NordicTrack Ultra 1
The new NordicTrack Ultra 1 treadmill looks like it was designed by an architect and costs $15,000
An Nvidia GeForce RTX 5070
Nvidia RTX 5080 stock is so barren that retailers are holding competitions where you can "win" the right to buy one for MSRP