The 2022 ThreatLabz State of Ransomware Report

Ransomware assaults elevated by yet one more 80% between February 2021 and March 2022, primarily based on an evaluation of ransomware payloads seen throughout the Zscaler cloud. Double-extortion assaults, which embrace information exfiltration along with encryption, are rising even quicker at 117% year-over-year.
The 2022 ThreatLabz State of Ransomware report breaks down a yr’s value of intelligence from a range of sources, together with over 200B every day transactions and 150M every day blocked threats throughout the Zscaler Zero Trust Exchange, and reveals that ransomware is turning into much more engaging to criminals. Attackers are in a position to wage more and more worthwhile campaigns primarily based on three main developments:

Supply chain assaults that exploit trusted vendor relationships to breach organizations and multiply the harm of assaults by enabling risk actors to hit a number of (generally lots of or 1000’s) of victims on the identical time.Ransomware-as-a-service that makes use of affiliate networks to distribute ransomware on a large scale, permitting hackers who’re specialists in breaching networks to share income with essentially the most superior ransomware teams.Multiple-extortion assaults that make the most of information theft, distributed denial of service (DDoS) assaults, buyer communications, and extra as layered extortion techniques to extend ransom payouts. Supply chain assaults, ransomware-as-a-service ecosystems, and multi-extortion techniques have all elevated the amount and success charges of assaults.
In this report, ThreatLabz gives a complete have a look at the ransomware risk panorama to offer trending information, predictions, and protection steering. Our report features a deep dive into the assault sequences, sufferer profiles, and enterprise impression of the highest 11 ransomware households, together with:
ContiLockBitPYSA/MespinozaREvil/SodinokibiAvaddonClopGriefHiveBlackByteAvosLockerBlackCat/ALPHV
Percentage change in double-extortion assaults by {industry}
Key Findings
Ransomware assaults elevated by 80% year-over-year, accounting for all ransomware payloads noticed within the Zscaler cloud.
Double extortion ransomware elevated by 117%. Some industries noticed notably excessive progress of double-extortion assaults, together with healthcare (643%), meals service (460%), mining (229%), schooling (225%), media (200%), and manufacturing (190%).
Manufacturing was essentially the most focused {industry} for the second straight yr, making up nearly 20% of double-extortion ransomware assaults.
Supply chain ransomware assaults are on the rise. Exploiting trusted suppliers lets attackers breach a big quantity of organizations all of sudden, together with organizations that in any other case have sturdy protections in opposition to exterior assaults. Supply chain ransomware assaults of the previous yr embrace damaging campaigns in opposition to Kaseya and Quanta in addition to a quantity of assaults exploiting the Log4j vulnerability.
Ransomware as a service is driving extra assaults. Ransomware teams proceed to recruit associates via underground felony boards. These associates compromise giant organizations and deploy the group’s ransomware, sometimes in change for about 80% of the ransom funds obtained from victims. Most (8 out of 11) of the highest ransomware households of the previous yr have generally proliferated through ransomware-as-a-service fashions.
Law enforcement is cracking down. A quantity of final yr’s prime ransomware households—notably these concentrating on essential providers—attracted consideration from regulation enforcement businesses world wide. Three of essentially the most notorious ransomware households of the previous two years had property seized by regulation enforcement in 2021.
Ransomware households aren’t going away—they’re simply rebranding. Feeling elevated warmth from regulation enforcement, many ransomware teams have disbanded and reformed below new banners, the place they use the identical (or very related) techniques.
The Russia-Ukraine battle has the world on excessive alert. There have been a number of assaults related to the Russia-Ukraine battle, with some combining a number of techniques, resembling HermeticWiper and PartyTicket ransomware. So far, most of this exercise has focused Ukraine. However, authorities businesses have warned organizations to be ready for extra widespread assaults because the battle persists.
Zero belief stays the very best protection. To reduce the possibility of a breach and the harm a profitable assault may cause, your group should use defense-in-depth methods that embrace decreasing your assault floor, implementing least-privilege entry management, and repeatedly monitoring and inspecting information throughout your surroundings.
How to guard your self in opposition to ransomware
Whether a easy ransomware assault, a double- or triple-extortion assault, a self-contained risk household, or a RaaS assault executed by an affiliate community, the protection technique is similar: make use of the ideas of zero belief to restrict vulnerabilities, forestall and detect assaults, and restrict the blast radius of profitable breaches. Here are some finest practices suggestions to safeguard your group in opposition to ransomware:
Get your functions off of the web. Ransomware actors begin their assaults by performing reconnaissance in your surroundings, searching for vulnerabilities to take advantage of, and calibrating their strategy. The extra functions you’ve revealed to the web, the simpler you’re to assault. Use a zero belief structure to safe inside functions, making them invisible to attackers.Enforce a constant safety coverage to stop preliminary compromise. With a distributed workforce, you will need to implement a safety providers edge (SSE) structure that may implement constant safety coverage regardless of the place your customers are working (in workplace or remotely).Use sandboxing to detect unknown payloads. Signature-based detection is just not sufficient within the face of quickly altering ransomware variants and payloads. Protect in opposition to unknown and evasive assaults with an inline, AI-powered sandbox that analyzes the habits quite than the packaging of a file.Implement a zero belief community entry (ZTNA) structure. Implement granular user-to-application and application-to-application segmentation, brokering entry utilizing dynamic least-privileged entry controls to eradicate lateral motion. This permits you to reduce the information that may be encrypted or stolen, decreasing the blast radius of an assault.Deploy inline information loss prevention. Prevent exfiltration of delicate info with trust-based information loss prevention instruments and insurance policies to thwart double-extortion methods.Keep software program and coaching updated. Apply software program safety patches and conduct common safety consciousness worker coaching to cut back vulnerabilities that may be exploited by cybercriminals.Have a response plan. Prepare for the worst with cyber insurance coverage, a knowledge backup plan, and a response plan as half of your general enterprise continuity and catastrophe restoration program.
To maximize your probabilities of defending in opposition to ransomware, you have to embrace layered defenses that may disrupt the assault at every stage—from reconnaissance to preliminary compromise, lateral motion, information theft, and ransomware execution.
The Zscaler Zero Trust Exchange is a number one safety service edge (SSE) platform, delivering unmatched ransomware safety throughout each stage of the assault chain to dramatically scale back your probability of being attacked and mitigate potential damages.
Zscaler natively integrates industry-leading zero belief capabilities that:
Minimize the assault floor: Zscaler’s cloud native proxy-based structure reduces the assault floor by making inside apps invisible to the web, thus eliminating potential assault vectors.Prevent compromise: Zscaler delivers full inspection and authentication of all visitors, together with encrypted visitors, to maintain malicious actors out, leveraging instruments resembling browser isolation and inline sandboxing to guard customers from unknown and evasive threats.Eliminate lateral motion: Zscaler safely connects customers and entities on to functions—not networks—to eradicate the chance of lateral motion, and surrounds your crown jewel functions with sensible decoys for good measure.Stop information loss: Zscaler inspects all visitors outbound to cloud functions to stop information theft, and makes use of cloud entry safety dealer (CASB) capabilities to determine and remediate vulnerabilities in information at relaxation.
To study extra about at the moment’s prime ransomware threats and easy methods to shield your group in opposition to them, obtain a free copy of “The 2022 ThreatLabz State of Ransomware Report.”
About ThreatLabz
ThreatLabz is the safety analysis arm of Zscaler. This world-class crew is answerable for looking new threats and guaranteeing that the 1000’s of organizations utilizing the worldwide Zscaler platform are at all times protected. In addition to malware analysis and behavioral evaluation, crew members are concerned within the analysis and improvement of new prototype modules for superior risk safety on the Zscaler platform, and frequently conduct inside safety audits to make sure that Zscaler merchandise and infrastructure meet safety compliance requirements. ThreatLabz frequently publishes in-depth analyses of new and rising threats on its portal, analysis.zscaler.com.
Stay up to date on ThreatLabz analysis by subscribing to our Trust Issues publication at the moment.
*** This is a Security Bloggers Network syndicated weblog from Blog Category Feed authored by Deepen Desai. Read the unique publish at: https://www.zscaler.com/blogs/security-research/2022-threatlabz-state-ransomware-report

https://securityboulevard.com/2022/06/the-2022-threatlabz-state-of-ransomware-report/

Recommended For You