Skip to main content

The purpose of ransomware

The purpose of ransomware



Ransomware, a phenomenon now very well known, serves one ultimate and obvious purpose:

  • Monetary gain for the cybercriminal(s).

However, multiple scenarios are, in fact, possible. Consider any and all of the following:

  • Deployed as ransomware, extortion;
  • Deployed as smokescreen;
  • Deployed to cause frustration;
  • Deployed out of frustration;
  • Deployed as a cover-up;
  • Deployed as a penetration test or user awareness training;
  • Deployed as a means of disruption and/or destruction.


Lets go over all of these briefly:


Deployed as ransomware, extortion

This has been the traditional approach - ransomware is installed on the victims machine, and its only purpose is to create income for the cybercriminal(s).

In fact, ransomware is simple extortion, but via digital means.

I could give 100s, if not 1000s of links as example, but this search query should suffice and show the current boom or trend in the cybercriminal landscape:
https://www.bleepingcomputer.com/search/?q=ransomware



Deployed as smokescreen

A very interesting occurrence indeed: ransomware is installed to hide the real purpose of whatever the cybercriminal or attacker is doing. This may be data exfiltration, lateral movement, or anything else, in theory, everything is a possible scenario... except for the ransomware itself.

This may happen more than you think and begs the question - what is the real purpose here?

Ransomware is obvious: files are encrypted, warning or extortion messages are scattered, and users as well as companies are unable to proceed working for days, depending on backup and recovery strategy.

Once youre hit by ransomware, more than 1 alarm bell should start ringing - you are royally compromised and, as such, should take appropriate measures immediately. There may be more than meets the eye.

Theres an article on Carnal0wnage, describing one of these events:
http://carnal0wnage.attackresearch.com/2016/03/apt-ransomware.html



Deployed to cause frustration

Another possible angle that goes hand in hand with the classic extortion scheme - deploying ransomware with intent of frustrating the victim. Basically, cyber bullying. While there may be a request for a monetary amount, it is not the purpose.

A notorious example of this is the Jigsaw ransomware:
https://www.bleepingcomputer.com/news/security/jigsaw-ransomware-decrypted-will-delete-your-files-until-you-pay-the-ransom/

Another example may be to send ransomware as a joke to your friends, and giving them a bad time. Dont.

In a related example; a victim of a tech support scam tricked the scammer into installing ransomware:
https://nakedsecurity.sophos.com/2016/08/15/tech-support-scammer-tricked-into-installing-ransomware/


Deployed out of frustration

Sometimes, an attacker may gain initial access to a server or other machine, but consequent attempts to, for example, exfiltrate data or attack other machine, is unsuccessful. This may be due to a number of things, but often due to the access being discovered, and quickly patched. On the other hand, it may have not been discovered yet, but the attacker is sitting with the same problem: the purpose as not fulfilled.

Then, out of frustration, or to gain at least something out of the victim, the machine gets trashed with ransomware.

Another possibility is a disgruntled employee, leaving ransomware as a present before leaving the company.

Darryl from Kahu Security has written an excellent article on the former occurrence:
http://www.kahusecurity.com/2017/not-your-typical-ransomware-infection/



Deployed as a cover-up

This may sound ambiguous at first, but imagine a scenario where a company may face sanctions, is already compromised, or has a running investigation.

The company or organisation deploying ransomware itself, is a viable way of destroying data forever, and any evidence may be lost. 

Another possibility is, in order to cover up a much larger compromise, ransomware is installed, and everything is formatted to hide what actually happened.

Again, there is also the possibility of a disgruntled employee, or even an intruder: which brings us back to deployed as a smokescreen.

There are some statistics referring to this as well, in a report by SentinelOne:
https://go.sentinelone.com/rs/327-MNM-087/images/Data%20Summary%20-%20English.pdf (PDF)



Deployed as a penetration test or user awareness training

Ransomware is very effective in the sense that most people know what its purpose is, and the dangers it may cause. As such, it is an excellent tool that can be used for demonstration purposes, such as a user awareness training. Another possibility is an external pentest, with same purpose.

An example is given by Malwarehunterteam, where KBC Group employed a phishing test, and consequently ransomware, meant as user awareness training:
https://twitter.com/malwrhunterteam/status/884361052682543105

This is a very good idea for any organisation or business in general. Are your users aware of the dangers that lie in, and beyond ransomware?



Deployed as a means of disruption and/or destruction

Last but not least -  while ransomware can have several purposes, it can also serve a particularly nasty goal: destroy a company or organisation, or at least take them offline for several days, or even weeks.

Again, there are some possibilities, but this may be a rivalry company in a similar business, again a disgruntled employee, or to disrupt large organisations on a worldwide scale.

A recent and notorious example of such an attack is the latest Petya variant, also referred to as EternalPetya, or NotPetya. A blog post from Kaspersky suggests the main purpose is a wiper:
https://securelist.com/expetrpetyanotpetya-is-a-wiper-not-ransomware/78902/

In a way, this also falls back to the frustration, and cover-up scenarios.



Closing thoughts

As weve seen, ransomware can serve a plethora of purposes; whether it is deployed by a nation-state actor, the more common cybercriminal, or your neighbor disgruntled at your tree hanging over their wall, one thing is for sure: you are, and have been compromised!

In more recent years, targeted ransomware has become a common phenomenon, this means ransomware either tailored to your environment, or manually installed - the latter often via hacked RDP or VNC services.

The most famous example is no doubt Samas, also known as SamSam:
https://www.bleepingcomputer.com/news/security/samas-ransomware-group-made-at-least-450-000/

Other examples include: CrySiS and derivatives, RSAutil and PetrWrap. 

While targeted ransomware attacks are occurring as early as 2013, in most recent years, they have become more fearful, due to the ransomware also encrypting files.

Conclusion: ransomware is and will always be ransomware - but it may have a twist and an additional purpose.

For further reading, I gladly introduce a shameless plug by referring you to 2 of my blog posts:
Ransomware: a Q&A
Ransomware prevention

If you can think of any other targeted ransomware, or purposes for ransomware, do not hesitate to leave some feedback in the comment section, or contact me on Twitter.


download file now

Popular posts from this blog

Ragnos1997 Low Specs Patches for low PC Download

Ragnos1997 Low Specs Patches for low PC Download Ragnos1997 Low Specs Patches for Low PC Full Download "Let your system breathe, and enjoy even the latest games on your low end hardware. Only with Low Specs Experience�" Which games are affected ? ALAN WAKE ALAN WAKE�S AMERICAN NIGHTMARE ALIEN: ISOLATION ALIEN: COLONIAL MARINES 7 DAYS TO DIE AMERICAN TRUCK SIMULATOR ANNO 2205 ARMA III ASSASSIN�S CREED ASSASSIN�S CREED II ASSASSIN�S CREED BROTHERHOOD ASSASSIN�S CREED REVELATIONS ASSASSIN�S CREED III ASSASSIN�S CREED III LIBERATION HD ASSASSIN�S CREED IV BLACK FLAG ASSASSIN�S CREED UNITY ASSASSIN�S CREED ROGUE ASSASSIN�S CREED SYNDICATE BATMAN ARKHAM ORIGINS BATMAN ARKHAM ORIGINS BATTLEFIELD BAD COMPANY 2 BATTLEFIELD 3 BATTLEFIELD 4 BATTLEFIELD HARDLINE BATTLEFIELD 1 BIOSHOCK INFINITE BORDERLANDS BORDERLANDS 2 BORDERLANDS THE PRE-SEQUEL CALL OF DUTY BLACK OPS CALL OF DUTY BLACK OPS II CALL OF DUTY BLACK OPS III CALL OF DUTY GHOSTS CALL OF DUTY ADVANCED WARFARE CALL OF DUTY INFIN...

TDATS fourth birthday festive greetings to you all!

TDATS fourth birthday festive greetings to you all! No music here....just a thanks to all the people who have been following this blog, four years down the line and I am still finding new ideas and receiving helpful pointers from readers who are often more informed than me....so thanks to you all. Please reply here or email me with any tips and ideas for the blog....you can also join in and contribute to TDATS news in the fb group.....I have some new ideas in the works....the next post in a few days, in time to be a Christmas present to you all, will be a revealing interview and story regarding a great band that I dont think has been spotlighted anywhere as yet.....and I have more plans to do that kind of thing next year....there are plenty more themes in the works....any advice that readers would like to offer on South-East Asia, East-European and latin american bands would be gladly followed up and if you can think of any other themes that will go down well here let me know! Happy ho...

Ramayana Soul Sabdatanmantra � �地獄 Scattered Purgatory God of Silver Grass

Ramayana Soul Sabdatanmantra � �地獄 Scattered Purgatory God of Silver Grass Reviewed by Nathan Ford There are few who read this rag who would doubt that we place Kikagaku Moyo at the very pinnacle of the current Japanese psychedelic scene. That being the case, its not unusual at all to discover that Guruguru Brain, the label run by Kikagaku Moyos Tomoyuki Katsurada is a veritable treasure trove of adventurous psychedelia, inhabited by names known to few in the Western world. Their first release was a wonderful and essential sampler of modern Japanese psychedelia which can still be downloaded for free here, but its two more recent releases that we concern ourselves with today. Ramayana Soul is first on the turntable, and while the band are actually Indonesian, its obvious why Katsuradas interest was peaked. "Sabdatanmantra" is a joyous wonder that perfectly illustrates the singular way in which Eastern psychedelia embraces free form spontaneity without sacrificing a tune, or in...