BotNet News

Your source for Online Security News

Ransomware is malware that encrypts your files or data, leaving you locked out and a demand for a ransom payment to regain access. Attackers typically infect a target through a malicious link or attachment sent via email. Once they gain access, the threat actor changes a display background to a message and demands a ransom paid in cryptocurrency to unlock files or restore access to the affected system.

While early attacks focused on consumers, ransomware gangs quickly realized they could make more money targeting businesses. They improved the malware to better evade detection, stolen credentials, and exploited vulnerabilities. They also grew their victim base from individual consumers to include organizations with thousands of employees. Attackers also launched more targeted attacks against high-value targets such as hospitals, police departments, schools, and critical infrastructure like gas pipelines.

The latest strains, like Black Basta, Medusa, and NotPetya, shifted the calculus away from recovery costs toward damage to the organization’s reputation. They also boosted their median ransom demand to $1M and threatened to expose victims’ most sensitive information on public sites. The result is that fewer victims are paying the ransoms demanded.

The threat landscape continues to evolve as attackers develop new tools to exploit the weaknesses they find. For example, threats such as cryptominers, which use a victim’s computer to generate cryptocurrency, require a large amount of electricity. Some malware variants are even capable of infecting systems and networks to rob them of the computing power needed to operate. It is critical for CISOs to continually assess the current state of cyberattacks against their organizations and follow trusted guidance, including that provided by federal law enforcement agencies and security vendors.