Cybersecurity Today

Exploring the Ransomware Ecosystem with Tammy Harper

9 snips
Aug 16, 2025
Tammy Harper, a senior threat intelligence researcher and certified dark web investigator at Flare, dives into the intricate world of ransomware. She discusses the evolution of ransomware from the AIDS Trojan to contemporary groups like Conti and LockBit, exploring their business models and tactics. Tammy unveils the role of cryptocurrency in ransomware, initial access brokers, and the rise of double and triple extortion techniques. Her insights on negotiation tactics and emerging groups make this an eye-opening guide for anyone curious about cybersecurity.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
INSIGHT

Ransomware As A Business Platform

  • Ransomware operates as a business platform with affiliate splits like 80/20 between affiliates and operators.
  • Initial access brokers sell exclusive, fresh access to high-value targets that affiliates then exploit.
ADVICE

Monitor Leak Sites Constantly

  • Monitor dedicated leak sites and use open-source tools like RansomLook to detect when victims are posted.
  • Maintain dark-web visibility because public leak blogs are a core pressure point for extortion.
INSIGHT

Key Events Drove Rapid Evolution

  • Ransomware evolved from crude lockers to efficient monetized services as affiliates and crypto payments matured.
  • The WannaCry worm and crypto payments were pivotal moments that scaled and commercialized the ecosystem.
Get the Snipd Podcast app to discover more snips from this episode
Get the app