Fraud Management & Cybercrime
,
Ransomware
,
Social Engineering
Silent Ransom Bucks Trend of Fewer Victims Paying, and Paying Less When They Do
Ransomware hackers, faced with declining willingness to exceed to extortion, are resorting to ever more outlandish pressure tactics – including sending disguised hackers to steal sensitive data in person.
See Also: Experts Offer Insights from Theoretical to the Realities of AI-enabled Cybercrime
A clutch of U.S. law firms have unknowingly ushered ransomware hackers into their offices after falling for their cover story of being IT personnel there to perform computer maintenance.
This strategy has proven to be lucrative. “By threatening public exposure of sensitive legal records exfiltrated through targeted social engineering, the group secured large payments,” said ransomware response firm Coveware in a Wednesday trends report.
The group in question is Silent Ransom. Also tracked as Luna Moth, Chatty Spider and UNC3753, the group has a history of using social engineering. The FBI warned earlier this month the group has escalated its attacks by sometimes coming on-site. Although its affiliates have attacked “many sectors including those in the insurance, finance and healthcare industries, the group has consistently targeted U.S.-based law firms since spring 2023,” the bureau said in a May alert.
Still, high-stakes in person visits aren’t the group’s only method and threat actors going onsite at a target’s environment, while on the increase, isn’t the norm. The FBI said the Silent Ransom group typically still sends mass emails to targets, instructing them to phone them back to address a phishing attack, or phone targets outright. Once establishing voice contact, a member of the group attempts to remotely trick the target into installing remote access tools or sharing credentials.
Only if that attempt fails will Silent Ransom send a hacker to a victim location to gain access in person. “In this scheme, the threat actor tells the victim they need to image the device or create a backup file to address potential impacts from the phishing email,” the FBI’s alert said.
To guard against these types of attacks, the FBI urged organizations to ensure all employees validate visitors’ credentials, including making copies of their identification, as well as “develop and communicate policies regarding when and how IT support will communicate and authenticate themselves to employees.” The bureau also requested any surveillance videos from firms that got hit by this type of attack, to help them identify and track the perpetrators.
The success of these physical infiltration attacks is notable in part because overall the ransomware business model is deflating (see: Breach Roundup: Extortionists Annoyed by Waning Ransomware).
From the first to the second quarters of this year, the quantity of victims who paid a ransom dropped from 23% to 19% – an all-time low – while payments by victims who suffered only data theft plummeted from 29% to 15%, based on thousands of cases Coveware investigated.
Median ransom payments dropped by 50% from the first to the second quarter, reaching $150,000, although the firm found the average ransom paid did surge by 176% to reach $1.9 million in the second quarter, thanks in large part to Silent Ransom’s targeting of major law firms.
While the record-low 19% of victims paying a ransom last quarter is a milestone, “we need to push it even closer to zero,” and better information sharing between “policymakers, law enforcement, industry leaders, insurance carriers and victims” will be key, said Magnus Jelen, Coveware lead director of incident response for the U.K. and EMEA.
Jelen emphasized the importance of securing data as well as possible, because once it gets stolen, no amount of money ever guarantees attackers will delete it (see: Instructure Pays ShinyHunters Ransom to Little Likely Return).
“We see too many cases where the opposite turns out to be true. The data is kept and published anyway. Paying criminals for a promise no one can audit or enforce is not the way forward. Hope is not a strategy,” he said.
