
Cybercriminals are increasingly working like businesses, with different groups handling different parts in a single cyberattack, a new report has revealed.
Latest findings by cybersecurity experts show ransomware attacks are no longer always carried out by one hacker or one group.
Instead, criminals are dividing the work among specialists who steal passwords, break into company systems, develop hacking tools and finally steal or lock data to demand ransom.
Cyber security firm ESET, Global Chief Security Evangelist, Tony Anscombe says the model has created a division of labour within the cybercrime economy, with criminal groups developing tools that are then supplied to other attackers.
“What happened was there was a phishing email that came in. They're doing the phishing piece, getting the credentials, that initial access piece. The stolen credentials or network access can then be sold on the dark web to affiliates, who take over the next stage of the attack,” Anscombe said
According to the experts, affiliates typically conduct reconnaissance, move laterally across an organisation's network and identify valuable data before deciding what to encrypt, damage or steal.
Behind them are ransomware-as-a-service operators that develop and provide the tools used in attacks, creating a cybercrime ecosystem where different players perform specialised functions.
“Ransomware groups develop tools that can switch off a company’s security systems, then give those tools to other hackers to use in attacks,” Anscombe said.
These security systems normallywatch computers for signs of hacking and stops suspicious activity. Hackers are now developing tools that candisable those protections first, making it easier to break into the company’s systems and lock or steal its data.
ESET East Africa Lead Cybersecurity Engineer Allan Juma, said the growing use of vulnerable legitimate drivers gives attackers a way to undermine security systems that businesses rely on to protect their networks.
“There are thousands and thousands of vulnerable drivers out there just waiting to be exploited with just little effort,” Juma said.
The development means businesses face a more complex threat because the tools used against them can be sourced from different parts of the cybercrime ecosystem.
He compared the structure to a conventional distribution model involving manufacturers, distributors, resellers and customers, except that the products being exchanged are tools and services used to compromise organisations.
For Kenyan businesses, the trend raises the stakes for organisations that have traditionally viewed ransomware primarily as a technical security problem.
Banks, insurers, telecommunications firms, retailers and other companies with large volumes of customer and financial data face the risk of dealing with an entire network of specialised attackers rather than a single threat actor.
The division of labour also means that an organisation can be targeted by attackers who did not develop the malware or initially gain access to its systems.
Juma said the evolution of ransomware is also being accelerated by artificial intelligence, which is giving attackers new ways to develop and modify malicious tools.
“Add AI to that particular mix and you have a potentially limitless source of new variants of these EDR killers,” he said.
The experts said ransomware operators are also adapting their tactics quickly to overcome security controls and environmental obstacles.