This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Finding the weakness: introduction of leakware as ransomware’s adaptation to countermeasures

Download resources

About this session

Vicky Desjardins traces ransomware from the 1989 AIDS trojan, mailed on floppy disks with a ransom payable to a post office box in Panama, through the lockerware and fake-antivirus scareware of the late 2000s to the crypto-ransomware wave that began in 2013 with Bitcoin, then grew with the Internet of Things and ransomware-as-a-service. She reviews the standard countermeasures, anti-malware, backups, critical patching and cyber insurance, and why each falls short: signatures miss new strains, snapshot replication copies the encryption, unsupported software cannot be patched, and insurance rarely covers recovery costs (Baltimore refused a ransom of roughly 76,000 dollars and spent over ten million rebuilding). Her thesis is that leakware, or double extortion, is criminals' adaptation to those defences: by threatening to publish stolen data rather than merely withholding a key, attackers make backups irrelevant and put reputation and clients at stake, amplified by public taunts on social media. The Maze group illustrates the shift with LG, Xerox and Southwire, whose leaked data stayed online despite a court order. She closes on prevention through sustained investment, training, patching and password hygiene.

There is a constant race between the introduction to cybersecurity practices and attack adaptation to surpass these countermeasures. As public and private organizations grow more resilient and implement measures to limit an attack’s impact, ransomware is also evolving to bypass these new countermeasures. Leakware is a type of ransomware whereby extortion is based on releasing the victims’ data if they do not pay instead of not decrypting the data.
Consequentially, cyber-resilient countermeasures such as offline backups, reverse engineering or file recovery services are ineffective in avoiding paying the ransom and still be able to have the files back. The leakware extortion is set so that a payment is incited due to values of data remaining confidential. This presentation aims to offer an overview of ransomware attacks’ transformation since 2013, and how leakware became an adaptation to countermeasures set against ransomware. We will discuss the potential impacts of leakware on organizations. We will conclude with a short presentation on what future countermeasure could be used to limit the risk of leakware. This presentation will contribute to a better understanding of how and why adaptation occurs and why cybersecurity practices must also change with the trends.  

Key takeaways

  • Assume backups no longer end the negotiation: leakware threatens publication, so protect confidentiality (access control, encryption at rest, minimisation) as seriously as recovery.
  • Check whether your backup design survives ransomware; snapshot and continuous replication faithfully copy deletion and encryption to the target.
  • Read the cyber insurance policy for what it excludes; the ransom is often a fraction of the recovery bill for hardware, software and retraining.
  • Decide in advance how a pay-or-not decision would be made, including who you trust to return data and the reputational cost of a public leak site.
  • Retire or isolate unsupported software, patch on the vendor cycle and train staff, since most entry points remain human error or known vulnerabilities.

Speakers

Vicky Desjardins
Vicky Desjardins
Ph.D student · School of Criminology, Montreal Univ.
Vicky Desjardins est une candidate au doctorat en criminologie à l'Université de Montréal, spécialisée dans le domaine complexe des méthodologies d'attaques par rançongiciels. Ses recherches doctorales portent sur des stratégies innovantes visant à… Read moreRead less

Vicky Desjardins est une candidate au doctorat en criminologie à l'Université de Montréal, spécialisée dans le domaine complexe des méthodologies d'attaques par rançongiciels. Ses recherches doctorales portent sur des stratégies innovantes visant à perturber de manière préventive les scripts d'attaque, contribuant ainsi de manière significative à l'évolution du paysage de la cybersécurité. Les activités académiques de Vicky comprennent une expertise en matière de priorisation des risques et d'analyse du comportement criminel, enrichie par son mémoire de maîtrise sur la priorisation des cas de sollicitation sexuelle en ligne présentant un potentiel élevé de contact hors ligne. Vicky dirige également la réponse aux cyberincidents, jouant un rôle crucial dans le confinement et la neutralisation des acteurs de la menace, ce qui souligne son expertise pratique dans le domaine.

Resources

Tags

More from GoSec 2021

Also from Vicky Desjardins

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.