04:00 PM
Connect Directly

Microsoft: Ransomware Decline Reversed in March 2017

Researchers discovered 71 new ransomware families in the first half of 2017, when attacks picked up after several months of decline.

Ransomware encounters consistently declined from August 2016 through March 2017, when the trend reversed and attacks became more frequent and complex, Microsoft researchers found.

Microsoft's Security Intelligence Report, which summarizes the threat landscape for the first quarter of 2017, highlighted a global increase in ransomware. In a new, second report released this week the the company, researchers take a deeper dive into the evolution of ransomware and explore how attacks became more complex in the first half of this year.

New ransomware families are being released at a faster rate and contributed to the March turnaround. In the first half of 2017, researchers discovered 71 new ransomware families, an increase from the 64 new families uncovered during the same timeframe in 2016.

"From a timeline perspective, around March and April, major ransomware families, like Locky, which were dormant early in the year came back with some major campaigns, contributing to the turnaround," says Microsoft security expert Tanmay Ganacharya.

Several new families stand out for their complexity, using techniques that had never been used in previous families, or had been improved on. Spora, for example, overtook established ransomware operation Cerber as the most common ransomware family during the first half of 2017. Researchers attribute the growth to its ability to spread via network drives and removable drives.

The report contains details on global ransomware outbreaks WannaCry and new variant of Petya, which was frequently called NotPetya in the aftermath of the attack. Both attacks wreaked havoc on Windows users in May and June 2017.

"WannaCrypt and Petya defied the trend of more targeted and localized attacks and became the first global malware attacks in quite a while," writes Microsoft in a blog post. "They generated worldwide mainstream interest. Interestingly, this attention might have added more challenges for attackers," who could not access their monitored Bitcoin wallets.

NotPetya, WannaCry, Spora, and other new ransomware variants incorporate complex techniques that enable a faster and more dangerous spread than earlier forms of malware.

New forms of ransomware use exploits to move laterally, as demonstrated in Spora's ability to spread via network drives. WannaCry exploited the EternalBlue vulnerability (CVE-2017-0144), and NotPetya expanded on this by abusing both EternalBlue and EternalRomance (CVE-2017-0145) to affect out-of-date systems. Both exploits were addressed in earlier security updates.

Other complex techniques include credential theft, which NotPetya did by stealing from Credential Score or using a credential dumping tool. Credential theft poses a security challenge to networks where users log in with local administrative privileges and have active sessions open on several machines. In case of NotPetya, stolen login data could provide the same level of access that users have on other devices.

"The Petya outbreak is testament to the importance of credential hygiene," the researchers wrote. "Enterprises need to constantly review privileged accounts, which have unhampered network access and access to corporate secrets and other critical data."

Ransomware can also spread via network scanning; NotPetya, for example, scanned infected networks to connect with other machines. When it found them, it tried to transfer copies of malware using stolen credentials, and scanned for network shares to try and grow further.

WannaCry used a different strategy and scanned IP addresses to seek computers vulnerable to the EternalBlue exploit. This technique allowed it to spread outside the network to machines that hadn't been updated with the necessary patch.

"We expect that cybercriminals will continue to use threats like ransomware because history has shown people will pay to unlock their devices," Ganacharya says. Based on the current climate, it's possible there could be twice as many ransomware attacks in 2017 than in 2016.

"Specifically, we expect to see a combination of mass-targeted, low-sophistication ransomware families and some highly sophisticated targeted ransomware attacks, especially against older platforms that don’t have the security robustness of the modern operating systems," he says.

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Strategist
9/8/2017 | 4:43:01 PM
Ransomeware Upsurge in 2017
I now neglect to worry about what type of malware is causing havoc. The problem is simple (not necessarily the solution); the internet is full of holes, like a sieve, and the need is to tackle the holes and not the individual shape of the holes (type of malware). Even the old vintage malware methods still work today which must tell the intelligent person that the 'patch, watch, pray and hope' methods aren't working. What is needed is a review  of all flaky products which fuel the internet and make them fit a new, secure architecture or be replaced. Governments and large companies can enforce this new regime as a condition of purchase; no fit new standard, no buy. It is done in other IT areas. There are too many people making good livings out of the status quo, for example, people in the know selling security services to gullible companies in the knowledge that their income is  safe in the current status of cybersecurity, sometimes relying on the old standby of FUD.
8 Ways Hackers Monetize Stolen Data
Steve Zurier, Freelance Writer,  4/17/2018
Securing Social Media: National Safety, Privacy Concerns
Kelly Sheridan, Staff Editor, Dark Reading,  4/19/2018
Firms More Likely to Tempt Security Pros With Big Salaries than Invest in Training
Sara Peters, Senior Editor at Dark Reading,  4/19/2018
Register for Dark Reading Newsletters
White Papers
Current Issue
How to Cope with the IT Security Skills Shortage
Most enterprises don't have all the in-house skills they need to meet the rising threat from online attackers. Here are some tips on ways to beat the shortage.
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.