跳到主体内容

More Than 75% of Crypto Ransomware in 2016 Came From the Russian-Speaking Cybercriminal Underground

2017年2月17日

Out of 62 new crypto ransomware families discovered by Kaspersky Lab researchers in 2016, at least 47 were developed by Russian-speaking cybercriminals

Out of 62 new crypto ransomware families discovered by Kaspersky Lab researchers in 2016, at least 47 were developed by Russian-speaking cybercriminals. This is one of the findings of an overview of the Russian-speaking ransomware underground, conducted by Kaspersky Lab researchers. The review also found that small groups with limited capabilities are transforming into large criminal enterprises that have the resources and intent to attack private and corporate targets worldwide.

Crypto ransomware – a type of malware which encrypts its victim’s files and demands a ransom in exchange for decryption – is one of the most dangerous types of malware today. According to Kaspersky Lab telemetry, in 2016 more than 1,445,000 users (including businesses) around the globe were attacked by this type of malware. In order to better understand the nature of these attacks, Kaspersky Lab researchers conducted an overview of the Russian-speaking underground community. One of the major conclusions is that the increase in crypto ransomware attacks observed in recent years is the result of a very flexible and user-friendly underground ecosystem, allowing criminals to launch crypto ransomware attack campaigns with almost any level of computer skills and financial resources.

Kaspersky Lab researchers identified three levels of criminal involvement in the ransomware business:

  • The creation and update of new ransomware families
  • The development and support of affiliate programs distributing ransomware
  • The participation in affiliate programs as a partner

The first type of involvement requires a participant to have advanced code-writing skills. The cybercriminals who create new ransomware strains are the most privileged members of the ransomware underground world, as they are the ones who create the key element of the whole ecosystem.

On the second level of the hierarchy, there are the developers of the affiliate programs. These are the criminal communities which – with the help of different additional tools, like exploit kits and malicious spam – deliver the ransomware issued by the malware creators.

The partners of affiliate programs are on the lowest level of the whole system. Utilizing different techniques they help the owners of affiliate programs to distribute the malware in exchange for a share of the ransom received by owners of the program. Only intent, a readiness to conduct illegal actions, and couple of bitcoins are required for participants of affiliate programs to enter this business.

According to Kaspersky Lab estimations, the overall daily revenue of an affiliate program may reach tens or even hundreds of thousand dollars, of which around 60% stays in the criminals’ pockets as net profit.

Moreover, during their research into the underground ecosystem and multiple incident response operations, Kaspersky Lab researchers were able to identify several large groups of Russian-speaking criminals specializing in crypto ransomware development and distribution. These groups may unite tens of different partners, each with their own affiliate program, and the list of their targets includes not only ordinary Internet users, but also small and medium-sized companies and even enterprises. Initially targeting Russian and CIS users and entities, these groups are now shifting their attention to companies located in other parts of the world. 

«It is hard to say why so many ransomware families have a Russian-speaking origin, but what is more important is that we’re now observing their development from small groups with limited capabilities to large criminal enterprises that have resources and the intent to attack more than just Russian targets. We’ve seen something similar with financial malware groups, like Lurk. They also started with massive attacks on online banking users, and then evolved into sophisticated groups capable of robbing large organizations, like banks. Sun Tzu said: If you know the enemy and know yourself, you need not fear the result of a hundred battles. That’s why we’ve created this overview: ransomware gangs are turning into very powerful enemies, and for the public and the security community, it is really important we learn as much about them as possible,» - said Anton Ivanov, security researcher at Kaspersky Lab, and the author of the overview.

Read more about how Russian-speaking underground ransomware ecosystem works on Securelist.com

More Than 75% of Crypto Ransomware in 2016 Came From the Russian-Speaking Cybercriminal Underground

Out of 62 new crypto ransomware families discovered by Kaspersky Lab researchers in 2016, at least 47 were developed by Russian-speaking cybercriminals
Kaspersky logo

关于卡巴斯基

卡巴斯基是一家成立于1997年的全球网络安全和数字隐私公司。卡巴斯基以“网络免疫”理念引领行业创新,致力于保护消费者、企业、关键基础设施和政府机构免受网络威胁,迄今为止已保护超过 10 亿台设备。

卡巴斯基秉持“Cybersecurity True to Business”的理念,专注于交付明确成果、保障营收、减轻团队负担并避免业务中断。卡巴斯基深厚的威胁情报和安全专业知识不断转化为创新解决方案和服务,服务于从小型企业到大型集团等各种规模的组织,将成熟的 AI 驱动型保护技术与简洁高效的管理和专家支持相结合。

卡巴斯基的解决方案经独立测试认可,深受全球数百万个人用户及近 20 万家企业的信赖,帮助客户更早识别威胁、更快速响应,以更强的信心与自由空间开展业务,保护对客户至关重要的资产。了解更多详情,请访问 www.kaspersky.com.cn

相关文章 企业新闻