Assessing the State of Multifaceted Extortion Operations
Apr 11, 2024
auto_awesome
Kimberly Goody leads Mandiant's Cyber Crime Analysis team, specializing in ransomware, while Jeremy Kennelly is a lead analyst with expertise in data theft. They dive deep into the evolution of multifaceted extortion, revealing a sharp rise in ransomware payments, with averages exceeding $1 million. They discuss why manufacturing and small enterprises are increasingly targeted due to limited security and assess the healthcare sector's vulnerabilities. Notably, they highlight shifts in tactics used by attackers, emphasizing a troubling trend in exploit-based operations.
In 2023, ransomware payments reached historic highs, indicating threat actors are diversifying tactics by leveraging data theft alongside direct attacks.
Geopolitical events have significantly reshaped the cybercrime landscape, pushing criminal groups to adapt operations and exploit vulnerabilities amidst global tensions.
Deep dives
Rise of Multifaceted Extortion
The discussion emphasizes the increasing prevalence of multifaceted extortion methods, moving beyond traditional ransomware alone. In 2023, the extortion landscape was marked by a significant rise in both ransomware payments and the number of victims as recorded on data leak sites. The analysis indicated that ransom payments reached historic highs, with a notable portion exceeding $1 million. This trend reveals how threat actors are diversifying their tactics to maximize earnings by leveraging both direct ransomware attacks and data theft for additional leverage.
Shifts in Cybercrime Ecosystem
The impact of geopolitical events, particularly the war in Ukraine, substantially redefined the cybercrime landscape in 2022 and 2023. As criminal groups adapted their operations in response to state interests, some traditional ransomware operations faced disruption and restructuring. The data showed a resurgence in attacks, with incident counts surpassing pre-2022 levels. The actions of law enforcement and the rapid evolution of threat actors illustrate that the cybercrime ecosystem is dynamic, with ongoing fluctuations resulting from external pressures.
Technological Trends in Attacks
An essential insight is the shift from malware-based intrusions, specifically the decline in Cobalt Strike Beacon usage, towards reliance on legitimate remote access tools. This change indicates that threat actors are adapting their methods to bypass defenses developed by cybersecurity professionals. Although the usage of recognized reconnaissance tools remains high, the integration of legitimate software complicates attribution and detection efforts. Consequently, defenders face growing challenges as cybercriminals continue to exploit weaknesses without relying solely on traditional malware.
Future Prospects in Ransomware and Extortion
Looking ahead, the podcast suggests that while there will be continuous adaptations in the threat landscape, significant shifts in the ransomware industry may be limited without substantial external influences. The expectation is that the extortion market will maintain its current trajectory, as financially motivated threat actors remain highly invested in this lucrative arena. New groups may emerge to fill gaps left by disrupted operations, sustaining the cycle of attacks. Overall, cybercriminals are unlikely to pivot to entirely new models unless more profitable alternatives arise.
Kimberly Goody, Head of Mandiant's Cyber Crime Analysis team and Jeremy Kennelly, Lead Analyst of the same team join host Luke McNamara to breakdown the current state of ransomware and data theft extortion. Kimberly and Jeremy describe how 2023 differed from the activity they witnessed the year prior, and how changes in the makeup of various groups have played out in the threat landscape, why certain sectors see more targeting, and more.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode