Ransomware threats see major resurgence

(Image credit: Carlos Amarillo / Shutterstock)

Ransomware is making a comeback according to a new report from McAfee which observed that ransomware samples grew by 118 percent during the first quarter of this year as cybercriminals adopted new tactics to evade detection.

The cybersecurity firm's McAfee Labs Threats Report: August 2019 saw an average of 504 new threats per minute during Q1 alongside changes in ransomware campaign execution and code. Additionally over 2.2bn stolen account credentials were made available on the dark web over the course of the quarter and 68 percent of targeted attacks utilized spear-phishing for initial access while 77 percent relied on user actions to execute their campaigns.

McAfee fellow and chief scientist, Raj Samani stressed the fact that every cyberattack has a human cost, saying:

“The impact of these threats is very real. It’s important to recognize that the numbers, highlighting increases or decreases of certain types of attacks, only tell a fraction of the story. Every infection is another business dealing with outages, or a consumer facing major fraud. We must not forget for every cyberattack, there is a human cost.” 

Ransomware resurgence

McAfee Advanced Threat Research (ATR) also observed innovations in how cybercriminals launch ransomware campaigns with shifts in initial access vectors, campaign management and technical innovations in their code.

In Q1 2019, ransomware attacks increasingly targeted exposed remote access points such as Remote Desktop Protocol (RDP). RDP credentials were either purchased on the dark web or cracked through brute-force attacks and they can be used to gain admin privileges to distribute and execute malware on corporate networks.

McAfee researchers also observed how the cybercriminals behind ransomware attacks began to use anonymous email services to manage their campaigns instead of the traditional approach of setting up command-and-control (C2) servers.

Dharma (also known as Crysis), GandCrab and Ryuk were the most active ransomware families during the first quarter of this year with other notable ransomware families including Anatova (which McAfee exposed before it spread) and Scarab.

Lead scientist and senior principal engineer at McAfee, Christiaan Beek provided further insight on ransomware's resurgence, saying:

“After a periodic decrease in new families and developments at the end of 2018, the first quarter of 2019 was game on again for ransomware, with code innovations and a new, much more targeted approach. Paying ransoms supports cybercriminal businesses and perpetuates attacks. There are other options available to victims of ransomware. Decryption tools and campaign information are available through tools such as the No More Ransom project.” 

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
A hacker wearing a hoodie sitting at a computer, his face hidden.
Experts warn this critical PHP vulnerability could be set to become a global problem
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
A close-up of a phone screen showing the Telegram, Signal and WhatsApp apps
Agentic AI has “profound” issues with security and privacy, Signal President says
botnet
Another top security camera maker is seeing devices hijacked into botnet
Bluetooth
Top Bluetooth chip security flaw could put a billion devices at risk worldwide
Latest in News
TCL QM7K TV on orange background
TCL’s big, bright new mid-range mini-LED TVs have built-in Bang & Olufsen sound
Homepage of Manus, a new Chinese artificial intelligence agent capable of handling complex, real-world tasks, is seen on the screen of an iPhone.
Manus AI may be the new DeepSeek, but initial users report problems
Google Maps
Nightmare Google Maps glitch is deleting timelines, and there isn't a fix yet
Twitter social media application change logo to X. Elon Musk CEO of twitter rebranded Twitter to 'X'. Social media application technology concept.
X is down again – Elon Musk confirms 'massive cyberattack' as former Twitter site hit by fourth outage today
Joe Goldberg and Kate Lockwood sitting at a table and looking at the camera in You season 5.
Netflix releases a killer new trailer for You season 5 but my favorite character is missing from Joe's final chapter
Person using Dyson V8 vacuum
Dyson vacuums have one big problem and I don't understand why