720-891-1663

Return to list of client alerts

A New Strategy for Ransomware Operators

Like all businesses, you either evolve or die.

In this case, it is the ransomers that are evolving.

As the White House is calling for federal agencies to figure out how to make ransomware unprofitable, the Cl0p ransomware group seems to be doing quite well, thank you.

So what is their strategy?

Steal your data and demand a ransom or sell your data.

Some people are saying that seems hard. But, in reality, hackers have always been able to gain a foothold inside corporate networks so that they can steal your data, so that doesn’t seem hard to us.

What Cl0p did was rather than use social engineering to get in, they used an existing vulnerability. And they didn’t bother with the encrypting part because people are getting better about backups.

Typically, finding and exploiting these vulnerabilities is hard. On the other hand, if you don’t have to spend money developing software to encrypt and decrypt data, you can use that savings to just buy vulnerabilities.

The key takeaway for business owners is that the value to ransomers is in the data and if they steal your data, they will figure out how to make money from it and you will pay for that – either by paying the ransom to buy back your own data or in defending your company in lawsuits – or both.

Consider yourself warned. If you need help shoring up your defenses, please contact us. Credit: Dark Reading