Skip to main content

Ransomware's Dangerous New Trick Is Double-Encrypting Your Data

 



Ransomware groups have always taken a more-is-more approach. If a victim pays a ransom and then goes back to business as usual-hit them again. Or don’t just encrypt a target’s systems; steal their data first, so you can threaten to leak it if they don’t pay up. The latest escalation? Ransomware hackers who encrypt a victim’s data twice at the same time.

Double-encryption attacks have happened before, usually stemming from two separate ransomware gangs compromising the same victim at the same time. But antivirus company Emsisoft says it is aware of dozens of incidents in which the same actor or group intentionally layers two types of ransomware on top of each other.

“The groups are constantly trying to work out which strategies are best, which net them the most money for the least amount of effort,” says Emsisoft threat analyst Brett Callow. “So in this approach you have a single actor deploying two types of ransomware. The victim decrypts their data and discovers it’s not actually decrypted at all.”

Some victims get two ransom notes at once, Callow says, meaning that the hackers want their victims to know about the double-encryption attack. In other cases, though, victims only see one ransom note and only find out about the second layer of encryption after they’ve paid to eliminate the first.

“Even in a standard single-encryption ransomware case, recovery is often an absolute nightmare,” Callow says. “But we are seeing this double-encryption tactic often enough that we feel it’s something organizations should be aware of when considering their response.”

Emsisoft has identified two distinct tactics. In the first, hackers encrypt data with ransomware A and then re-encrypt that data with ransomware B. The other path involves what Emsisoft calls a “side-by-side encryption” attack, in which attacks encrypt some of an organization’s systems with ransomware A and others with ransomware B. In that case, data is only encrypted once, but a victim would need both decryption keys to unlock everything. The researchers also note that in this side-by-side scenario, attackers take steps to make the two distinct strains of ransomware look as similar as possible, so it’s more difficult for incident responders to sort out what’s going on.

Ransomware gangs often operate on a revenue-sharing model, where one group builds and maintains a strain of ransomware and then rents its attack infrastructure to “affiliates” who carry out specific attacks. Callow says that double encryption fits into this model by allowing clients who want to launch attacks to negotiate splits with two gangs that can each provide a distinct strain of malware.

The question of whether to pay digital ransoms is a thorny and important one. And ransomware victims who choose to pay already need to be wary of the possibility that attackers won’t actually supply a decryption key. But the rise of double encryption as a strategy raises the additional risk that a victim could pay, decrypt their files once, and then discover that they need to pay again for the second key. As a result, the threat of double encryption makes the ability to restore from backups more crucial than ever.

“Remediating from backups is a long complex process, but double encryption doesn’t complicate it further,” Callow says. “If you decide to rebuild from backups you’re starting fresh, so it doesn’t matter how many times the old data has been encrypted.”

For ransomware victims who don’t have adequate backups in the first place or don’t want to take the time to reconstruct their systems from scratch, double encryption attacks pose an additional threat. If fear of double encryption attacks makes victims less likely to pay across the board, though, attackers could back off of the new strategy.


Originally published at https://www.wired.com.

Comments

Popular posts from this blog

Babuk ransomware is back, uses new version on corporate networks

  After announcing their exit from the ransomware business in favor of data theft extortion, the Babuk gang appears to have slipped back into their old habit of encrypting corporate networks. The criminals are currently using a new version of their file-encrypting malware and have moved the operation to a new leak site that lists a handful of victims. Gang’s still in the game The Babuk ransomware group became known at the beginning of the year but the gang says that their attacks had started in mid-October 2020, targeting companies across the world and demanding ransoms typically between $60,000 and $85,000 in bitcoin cryptocurrency. In some cases, victims were asked hundreds of thousands for data decryption. One of their most publicized victims is the Washinton DC’s Metropolitan Police Department (MPD). This attack likely pushed the threat actor into announcing its retirement from the ransomware business only to adopt another extortion model that did not include encryption....

Mega Comparison: Zoom vs Skype vs Microsoft Teams vs Google Meet vs Google Duo vs Messenger Rooms

Video calling tools have lately been topping the download charts due to the sudden surge in work from home culture. However, with the number of options available in the market, it gets quite confusing for people to settle with one. So, we tried some of the most popular services such as Zoom, Skype, Microsoft Teams, Google Meet, Duo, and Messenger Rooms for you to decide which one’s a better choice. Read on. Zoom vs Skype vs Microsoft Teams vs Google Meet vs Google Duo vs Messenger Rooms: Which one’s better? Zoom Video Call Being the current most popular video call service in the market, Zoom has got all the features and quirks one would demand. Everything works fine except for the virtual background feature, which needs you to have uniform lighting and an easily distinguishable background. Usage:  Zoom can be used by anyone, ranging from friends and family to small office meetings and large enterprise conferences. Cost:  Zoom is free to use, with the basic plan having certain ...

Bogus Android Clubhouse App Drops Credential-Swiping Malware

The malicious app spreads the BlackRock malware, which steals credentials from 458 services — including Twitter, WhatsApp, Facebook and Amazon. Researchers are warning of a fake version of the popular audio chat app Clubhouse, which delivers malware that steals login credentials for more than 450 apps. Clubhouse has burst on the social media scene over the past few months, gaining hype through its audio-chat rooms where participants can discuss anything from politics to relationships. Despite being invite-only, and only being around for a year, the app is closing in on 13 million downloads . However, as of now the app is only available on Apple’s App Store mobile application marketplace — there’s no Android version yet (though plans are in the works to develop one). Cybercriminals are swooping in on Android users looking to download Clubhouse by creating their own fake Android version of the app. To add a legitimacy to the scam, the fake app is delivered from a website purporting to b...