November 11, 2019 By David Bisson 3 min read

Last week in security news, researchers revealed that the average ransomware payment surpassed $40,000 between the second and third quarters of 2019. Speaking of ransomware, security professionals explored an emerging means of distribution for the Nemty family and investigated the Buran ransomware-as-a-service (RaaS) platform. Others also observed multiple binaries of DoppelPaymer hosted on a server along with samples of TinyPOS malware and other digital threats.

Top Story of the Week: Ransomware Payments Grew in Q3 2019

In its “Q3 Ransomware Marketplace” report, Covewave found that the average ransomware payment had increased by 13 percent to $41,198 between the second and third quarters of 2019. Even so, the security firm’s researchers observed that the rate of increase for ransom payments had largely plateaued. They attributed this development to victims’ growing efforts to recover their files without paying ransomware attackers.

According to the report, victims began looking for other means of recovering their files despite the fact that they received a working decryptor after paying the ransom in 98 percent of infections. Additionally, 94 percent of victims found that the decryptor provided by attackers successfully recovered their affected data.

Source: iStock

Also in Security News

  • Digital Attack Strikes Renewable Energy Provider: Back in March, renewable energy provider SPower was the first U.S. company of its kind to suffer a digital attack against its IT infrastructure. The attack was also the first to compromise connections with power installations on U.S. soil.
  • First Wave of BlueKeep Attacks Underwhelm Security Observers: Security researchers saw a wave of attacks exploiting the BlueKeep zero-day vulnerability disclosed by Microsoft in May. But as reported by WIRED, those attacks didn’t cause as much destruction as experts feared, as they mainly consisted of installing and running a cryptocurrency miner on vulnerable machines.
  • Over 40 Million Users Exposed to Malicious Android Emoji Keyboard: Upstream blocked over 14 million suspicious transactions from 110,000 Android devices that had downloaded ai.type, an emoji keyboard. The keyboard disappeared from the Google Play store in June 2019, but the security firm noted that the 40 million users who had already installed the keyboard were still at risk.
  • Nemty Relying on Trik Botnet for Distribution: Symantec revealed that Nemty ransomware has partnered with the Trik botnet. This new technique expanded the reach of Nemty, a threat that also uses the RIG exploit kit and malspam campaigns as means of delivery.
  • Ransomware, POS Malware and Other Threats Hosted by Single C&C: Researchers at Cisco Talos uncovered a command-and-control (C&C) server that hosted several different binaries of the BitPaymer-derived DoppelPaymer ransomware family. They also found that the server contained TinyPOS malware, Mimikatz and tools for remotely connecting to Windows systems.
  • Buran Revealed to Have Evolved From Other Ransomware Families: McAfee analyzed the behavior, TTPs and artifacts of a Buran sample and determined that the ransomware was in fact an evolution of Jumper, a family that emerged two months before Buran. Jumper was the second iteration of the family’s lineage; researchers identified VegaLocker as its origin point.
  • Malvertisers Leveraged Fake Blockchain Ad to Distribute Capesand EK: Back in October, Trend Micro saw a malvertising campaign abruptly switch tactics and use a blockchain ad to begin linking to a new exploit kit instead of RIG. Researchers analyzed the exploit kit, which they named Capesand, and found it was unique in that its source code did not contain its exploit code.
  • Firefox Bug Abused by Tech Support Scammers to Prey Upon Users: Bleeping Computer found that digital fraudsters are using a Firefox browser lock bug to prevent users from closing the browser tab without viewing a fake tech support page. This scam instructed users to contact an illegitimate Windows Support line that likely tried to trick them into buying fake antivirus software.
  • Vulnerable Routers at Risk of Gafgyt Infection, DDoS Attacks: Palo Alto Networks’ Unit 42 research team uncovered an updated variant of the Gafgyt malware family. It found that the malware could target vulnerable wireless routers and enlist them into botnets for the purpose of conducting distributed denial-of-service (DDoS) attacks.

Security Tip of the Week: Defend Against a Ransomware Infection

Security professionals can help defend their organizations against a ransomware infection by using test phishing engagements to evaluate employees’ awareness of phishing attacks, one of the most common ransomware distribution vectors. Companies should also implement a backup strategy and regularly test it to make sure they can recover their files in the event of a ransomware infection.

More from

Cybersecurity dominates concerns among the C-suite, small businesses and the nation

4 min read - Once relegated to the fringes of business operations, cybersecurity has evolved into a front-and-center concern for organizations worldwide. What was once considered a technical issue managed by IT departments has become a boardroom topic of utmost importance. With the rise of sophisticated cyberattacks, the growing use of generative AI by threat actors and massive data breach costs, it is no longer a question of whether cybersecurity matters but how deeply it affects every facet of modern operations.The 2024 Allianz Risk…

Autonomous security for cloud in AWS: Harnessing the power of AI for a secure future

3 min read - As the digital world evolves, businesses increasingly rely on cloud solutions to store data, run operations and manage applications. However, with this growth comes the challenge of ensuring that cloud environments remain secure and compliant with ever-changing regulations. This is where the idea of autonomous security for cloud (ASC) comes into play.Security and compliance aren't just technical buzzwords; they are crucial for businesses of all sizes. With data breaches and cyber threats on the rise, having systems that ensure your…

Adversarial advantage: Using nation-state threat analysis to strengthen U.S. cybersecurity

4 min read - Nation-state adversaries are changing their approach, pivoting from data destruction to prioritizing stealth and espionage. According to the Microsoft 2023 Digital Defense Report, "nation-state attackers are increasing their investments and launching more sophisticated cyberattacks to evade detection and achieve strategic priorities."These actors pose a critical threat to United States infrastructure and protected data, and compromising either resource could put citizens at risk.Thankfully, there's an upside to these malicious efforts: information. By analyzing nation-state tactics, government agencies and private enterprises are…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today