Ransomware has evolved with the times. The initial approach of crypto-ransomware attackers is to gain access to your network or computer, inject and trigger malware that encrypts data, lock the user out of the computer, and finally demand a ransom from the victim, usually in the form of cryptocurrency, as was the case with the infamous WannaCry in 2017.

Ransomware 2.0 is on the rise: what you need to know
The victim may use the backup to restore the data, but still faces the risk that the data will be exposed or used to harm customers and partners. Even if the victim pays the ransom, there is no guarantee because the attacker still has the data and may exploit it anyway. In addition to crypto-ransomware, there are many types, including screen-locking ransomware, commonly seen on mobile devices, which does not encrypt data but locks the device and displays a ransom demand. Exfiltration software or Doxware steals data and may also encrypt it; wipers or vandal ransomware destroys data.

How are ransomware attacks evolving?
The ransomware we see today is often a multi-stage process that uses reconnaissance to identify the right target within an organization, and then often uses phishing and social engineering to gain access to the target computer or network. Since then, ransomware has aimed to evade detection and exploit vulnerabilities to infect more devices. The infamous WannaCry ransomware, believed to be deployed by North Korea, was a crypto-worm that spread across the Internet and infected more than 200,000 computers around the world. Modern ransomware often targets cloud storage and SaaS platforms (targeting organizations that store data and applications there). This has become more common after the shift to remote work during the COVID-19 pandemic.

Another characteristic of ransomware 2.0 is that it is often developed by third parties other than the attackers, a phenomenon known as RaaS (Ransomware as a Service). RaaS allows less skilled attackers to use sophisticated ransomware tools developed by experts and distribute the ransom among the parties. Recent attacks also reveal a new ransomware vector that infects the software supply chain. Ransomware is delivered to organizations and other victims who download what appear to be official apps or software patches, potentially impacting large numbers of users with a single infiltration. Another vector that has emerged recently is called thread hijacking, where ransomware attackers infiltrate an organization’s online conversations to deploy malware.
How else is ransomware 2.0 different from its predecessor?
Ransomware has come a long way since the simple P.C. Cyborg of the last century and has become a sophisticated and lucrative product, developed to be sold as RaaS on the dark web, and resellers have recently been spending heavily to recruit downline organizations. Ransomware developers have even been known to acquire different strains of malware to maximize the efficiency of their illicit operations. Today, ransomware often targets specific organizations and individuals with customized attacks, with the goal of maximizing profits and pressuring victims to pay.

Modern ransomware is more sophisticated than its early days because it uses automated tools and methods that allow attackers to quickly find vulnerabilities, spread malware across the network, and obtain specific sensitive data. As sophistication increases, there is also greater collaboration between ransomware actors. These threat actors often form partnerships with each other and even share resources, making it easier for organizations, governments, and security teams to deal with the problem.
The growing popularity of cryptocurrencies is also a factor in ransomware, as most ransom payments have traditionally come in this form or other difficult-to-trace payment methods. Researchers have found that ransomware attackers are adaptable and are adopting newer, more difficult-to-track, privacy-focused cryptocurrencies such as Monero and Zcash, making them more difficult for cybersecurity and government agencies to track.
How to deal with ransomware 2.0?
When it comes to ransomware, as with most cybersecurity threats—prevention is better than cure. To this end, organizations should invest in data security and use different types of network security solutions, from endpoint protection to network monitoring tools, as well as well-defined identity and access controls, including multi-factor authentication and network segmentation. AI-based threat detection and proactive threat hunting are an increasingly popular defense method. Vulnerability assessments should be conducted and action plans should be formulated in the event of a crisis event to enable faster detection and repair to reduce losses.

Another important aspect of prevention is educating company employees about online health and identifying phishing and social engineering attempts. Companies should also keep all software up to date and install the latest patches to ensure vulnerabilities are patched as soon as they are discovered. Organizations should also encrypt data and perform regular backups, both in the cloud and offline.
Finally, if all precautions are not enough and you do become a victim of ransomware, you should contact law enforcement and be advised not to pay. After all, there is no guarantee that the data will be recovered, it may still be leaked even after paying, and you are funding criminals.
Source: KOCPC Chinese