Blockchain & AI
NETWALKER RANSOMWARE-AS-A-SERVICE RAKES IN MORE THAN $25M OF BITCOIN IN 4 MONTHS
According to cybersecurity company McAfee, those behind NetWalker ransomware have raked in more than $25m USD since March 2020.
Ransomware-as-a-service
Use of the ransomware, which was first discovered in August 2019 and initially known as Mailto, increased noticeably in March according to McAfee Advanced Threat Research (ATR).
Furthermore, the ATR team says it has discovered a large sum of Bitcoins (BTC) linked to NetWalker, which they say suggests the extortion attempts have been effective, with victims having no option but to pay the ransoms.
Specifically, between 1 March and 27 July, 2,795 BTC were collected by the cybercriminals using NetWalker.
Investigators say NetWalker has evolved into a more stable and robust ransomware-as-a-service (RaaS) model, which likely means its operators are now attracting “broader range of technically advanced and enterprising criminal affiliates.”
This revenue sharing model means the ransoms received from attacks are split between different addresses, making the criminals harder to trace, and further incentivising more ransom attempts. Interestingly, it also looks like NetWalker operators are now using SegWit addresses, rather than legacy Bitcoin addresses – taking advantage of lower costs and faster transactions.
Investigators also note that, despite NetWalker being a relative newcomer, its underground advertising has been well received and the ransomware seems to have a good reputation among crooks. This has led them to deduce that one of those most actively promoting it, despite going by the new moniker “Bugatti”, is probably a seasoned, experienced and well-respected cybercriminal.
A worsening problem
According to McAfee, those using NetWalker are mostly targeting western European and US-based businesses – even hospitals, as evidenced by June’s attack on the Crozer-Keystone Health System.
Coordinated, sophisticated ransomware attacks are an escalating problem for businesses around the world, with Cointelegraph quoting a threat analyst from Emsisoft as saying companies paid more than $25 billion in ransom demands in 2019 alone.
As previously reported, it is thought multinational tech company Garmin may have paid a $10m crypto ransom to hackers in late July, after criminals encrypted its internal network, disrupting many of the company’s services, including customer support and navigation. The specific ransomware used in that attack was WastedLocker.
In the same month, US travel firm CWT fell victim to Ragnar Locker ransomware, and is thought to have paid out $4.5m to regain control of its systems.
AYO.NEWS says:
As we’ve said before, when a major company is hit by a sophisticated ransomware attack, it’s hard to see they have any other option than to pay up – every day that goes by is lost business, they risk incurring the wrath of their clients, and there doesn’t seem to be anything law enforcement can do except try and track down the crooks after the event.
‘AYO.NEWS says’ features the opinion of the author and does not necessarily reflect the views of Pentagon Digital Limited or its affiliates or associates.
All original content featured on this site is © Pentagon Digital Limited, 2020