The ransomware warning sign we should all have on our radar

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Wallis Romzek, Principal Data Scientist, SpyCloud


  • In 2023, over 80% of companies were affected by ransomware in the preceding 12 months.
  • By looking more closely at how ransomware attacks happen, we can spot warning signs sooner and act on them to prevent future attacks.
  • In the fight against ransomware, the best defence is one built on data and aligned properly to the threats a company faces.

The cybersecurity community talks a lot about ransomware attacks: who the latest ransomware gangs are, common attack vectors, how much companies are shelling out in ransom payments and what the proper incident response protocols are for security teams.

That all matters, of course. By and large though, security teams are already aware of the threat ransomware poses due to firsthand experience. In 2023, 81% of companies were affected by ransomware in the preceding 12 months. Reported effects vary widely, from needing to purchase a solution to combat ransomware attacks, to being actively targeted, to actually paying a ransom. Regardless, the rate of companies affected by ransomware has remained consistently high since 2021.

The far-reaching impacts of ransomware, combined with the fact that we’re on track for the second costliest year for ransomware in history, means it’s time to take another look at the ransomware problem and think about tackling it from a new angle. By looking more closely at how ransomware attacks happen in the first place – through means that may not be on security teams’ radars yet – we can spot warning signs sooner and act on them to defend against attacks altogether.

How ransomware usually starts

Let’s start with one of the most common entry points for a ransomware attack: compromised credentials.

Criminals love authentication credentials because they are a reliable lever for gaining access to systems and information that allow them to perpetrate crimes. Threat actors often get their hands on credentials by using infostealer malware, which is typically deployed through malicious websites, botnets or phishing emails.

With one click, a user can become infected, allowing the malware to steal a wide variety of information stored on the user’s machine – from private data, such as credit card numbers, to usernames and passwords and even web session cookies that open doors to corporate resources.

And, when one door opens many others often do, too. SpyCloud research shows that 72% of users whose data was exposed in two or more breaches in 2022 reused their passwords across applications. That means that nearly three in four people were actively using a compromised password, making it pretty easy for threat actors to take one exposed credential pair and gain access to their information and files across multiple accounts, including work applications.

Discover

How is the World Economic Forum addressing rising cybersecurity challenges?

What new research says about the infostealer malware

Here’s where it gets interesting. With access credentials gained via infostealer malware, threat actors can connect dots to then steal, encrypt and ransom sensitive or proprietary data across an enterprise system – launching a full-blown ransomware attack. For the first time, cutting-edge research confirms this is what (at least some) threat actors are doing. The presence of an infostealer infection is indeed an early warning signal of the potential for ransomware.

In a sample of North American and European companies that experienced a ransomware attack in 2023, nearly one in three were infected with infostealer malware in the months leading up to the attack (2023 SpyCloud Ransomware Defence Report).

What does this mean for security teams?

As a risk signal, an infostealer malware presence should trigger companies’ ransomware radar and motivate a comprehensive malware remediation response.

We can’t say with certainty that a ransomware attack follows an infostealer malware infection every time. Only threat actors themselves know how they intend to use the information they steal. But, infostealer malware presence is a good starting point for better defence and prevention.

We can use this starting point to build out a broader picture to understand the role that infostealers play in a ransomware attack. This will improve awareness of potential threats and better inform security defence priorities and tactics.

So, how do we build upon the role of infostealer infections in a ransomware kill chain?

First, we broaden our perspective. We assess the circumstances that preceded the infection. Patching priorities that focus on exploitable vulnerabilities, for example, may make it more difficult for a threat actor to gain entry in the first place. Security awareness training that keeps up with modern attacker techniques could have a similar mitigating effect on the risk of infostealer malware.

We also consider the steps an attacker is likely to take after infection and the data to which they have access. Perhaps single sign-on credentials and additional application access are the actor’s targets. Or, perhaps malicious actors are after crypto wallets.

Collecting and evaluating signals around infostealer malware can shed light on a company’s status and circumstances and help to locate infostealer malware appropriately in a ransomware kill chain. These additional signals will add context and nuance to our understanding of infostealer malware and might even serve as additional early warning signals themselves.

Second, we act on what we know – and keep watching. We get to work monitoring for, and remediating, infostealer malware infections and take steps to limit the potential damage that could result from data exfiltration.

Then we continue to collect and evaluate data and signals as companies either fall victim to or evade ransomware attackers. Over time, these signals will reveal patterns that will further contextualize the infostealer-ransomware connection. They will allow researchers to leverage large-scale analytics and machine-learning algorithms to understand it, learn from it and use it to support defensive tactics.

In the fight against ransomware, the best defence is one built on data and aligned appropriately to the threats a company faces. An organization’s vulnerability to ransomware attacks will rely in part on its unique environment, characteristics and needs. Our research at SpyCloud indicates, however, that the connection between infostealer infections and ransomware attacks persists regardless of company shape or size.

If that is the case, a ransomware prevention plan can only be considered comprehensive if it includes monitoring for and remediating infostealer

malware exposure.

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

© WFP/Khadija Dia Food is distributed to displaced families sheltering in a school in Tariq Jdide, Beirut.

Middle East war risks pushing 45 million more people into acute hunger

This article is published in association with United Nations. The Middle East war could cause the worst disruption to lifesaving humanitarian work since COVID, the UN World Food Programme (WFP) warned on Tuesday, as the UN chief again demanded an end to the widening conflict. “The Secretary-General asserts once more that the war in the Middle […]
© World Vision Smoke rises in Beit Mery, close to the Lebanese capital, Beirut, following an airstrike.

Middle East war’s ‘spiral of conflict’ drives mounting civilian toll

This article is published in association with United Nations. The widening war in the Middle East and its growing impact on civilians came under scrutiny at the UN in Geneva on Monday, as independent experts briefing the Human Rights Council warned of escalating violence following the onset of Israeli and US strikes on Iran and counterstrikes […]
© Mousawat A mother and child displaced by the conflict in Lebanon receiving care at a clinic.

Middle East war: Women in Lebanon forced to give birth on roadside

This article is published in association with United Nations. As the UN Secretary-General touched down in Beirut on Friday in solidarity with the people of Lebanon, UN agencies highlighted the dangers for civilians and particularly pregnant women and migrant workers, amid ongoing airstrikes and rocket fire between Hezbollah fighters and Israel.  “There’s 11,600 pregnant women who […]
© WFP/Arete/Ali Yunes Some residents of Beirut who have been displaced by the conflict are now living on the streets of the Lebanese capital.

‘Perfect storm’: Lebanon crisis deepens as civilians bear the brunt

This article is published in association with United Nations. Lebanon is facing a “perfect storm of unpredictable challenges” as conflict, mass displacement and dwindling humanitarian resources converge, the UN’s Resident and Humanitarian Coordinator in Lebanon, Imran Riza, has warned. The current escalation began on 2 March, when outgoing fire by Hezbollah drew a strong retaliation from […]
© WFP/Maxime Le Lijour People living in Gaza have received humanitarian aid from the UN throughout the conflict with Israel.

UN relief chief condemns ‘$1 billion-a-day’ cost of war in Middle East

This article is published in association with United Nations. The UN’s emergency relief chief on Wednesday condemned the “$1 billion-a-day” cost of the war in the Middle East, at a time when humanitarian needs are soaring and aid funding is falling dangerously short. “We’re seeing the consequences spread faster than we can respond”, warned the UN emergency […]
© UNICEF/Azizullah Karimi Afghan returnees from Iran gather at the Islam-Border, near Herat in western Afghanistan (file).

‘Toxic rain’ warning from oil depot strikes amid ongoing Middle East war

This article is published in association with United Nations. Toxic “black rain” linked to strikes on oil depots, mass displacement and continuing disruption to aid supply chains are upending lives across the Middle East and beyond after 10 days of war in the region, UN humanitarians said on Tuesday.  Speaking to reporters in Geneva, UN Human […]
© UNHCR People gather at the Masnaa border point in Lebanon as they wait to cross into Syria.

Nearly 700,000 displaced in Lebanon as Middle East crisis escalates

This article is published in association with United Nations. On day 10 of the war engulfing the Middle East, UN agencies on Monday reported massive displacement across the region, along with surging food and fuel prices that risk increasing hunger and suffering for the most vulnerable. In Lebanon alone, nearly 700,000 people including around 200,000 children […]
UN Photo/Pasqual Gorriz Smoke rises in Beirut, Lebanon, following the outbreak of hostilities across the Middle East.

Lebanon ‘dragged back into turmoil’, UN envoy warns

This article is published in association with United Nations. Lebanon has been “dragged back into a state of turmoil and violence”, the UN’s top envoy in the country warned on Saturday, after the latest round of regional strikes triggered a fast‑escalating crisis along the Blue Line. What had been fragile but real momentum, she said, has […]
UNHCR Smoke rises after an airstrike in Beirut, Lebanon.

MIDDLE EAST LIVE: Strikes continue across Middle East as humanitarian concerns grow

This article is published in association with United Nations. Highlights Production team: Vibhu Mishra with Daniel Johnson in GenevaToday 12:15 μ.μ. UN rights office warns displacement orders in Lebanon affecting hundreds of thousands The UN human rights office has warned that large-scale displacement orders and ongoing airstrikes in Lebanon are worsening the suffering of civilians already affected […]
© UNICEF/Ramzi Haidar Destroyed buildings and debris in the southern suburbs of Beirut, Lebanon, following airstrikes.

MIDDLE EAST LIVE: Further escalation drives uncertainty and suffering

This article is published in association with United Nations. On day six of the war in the Middle East, there’s been no let-up in bombs, drones and rockets targeting Iran, Israel, Lebanon and many Gulf States, while NATO forces reportedly intercepted a missile fired at Türkiye by Iran, a claim denied by Tehran. We’ll bring you […]
UN Photo/Pasqual Gorriz Smoke rises in Beirut, Lebanon, following the outbreak of hostilities across the Middle East.

MIDDLE EAST LIVE: Conflict continues across region amid US, Israeli and Iranian strikes

This article is published in association with United Nations. Violence in the Middle East is continuing into a fifth day, with US and Israeli strikes against Iran and Iranian missile and drone attacks reported across several countries in the region. The escalating confrontation is disrupting airspace, transport and daily life while raising fears of a wider […]
© IAEA/Paolo Contri The Bushehr Nuclear Power Plant in Iran.

Iran crisis: Schoolgirls killed, thousands displaced and aid compromised

This article is published in association with United Nations. On the fourth day of Israeli and United States airstrikes against Iran and amid growing violence and instability in the Middle East, the UN urgently called for protection of civilians and warned of growing displacement and humanitarian needs. UN human rights office spokesperson Ravina Shamdasani also recalled […]
© Unsplash/Kamran Gholami Tehran, the capital of Iran. (file photo)

MIDDLE EAST LIVE: Strikes continue from US, Israel and Iran as UN urges restraint

This article is published in association with United Nations. Violent escalation in the Middle East has entered a third day as coordinated US and Israeli strikes against Iran aimed at regime change continue to cause loss of life and damage across the region, prompting Iranian missile and drone counter-strikes hitting targets in multiple countries. Explosions, airspace […]
Iran attacks

Deadly bombing of Iran primary school ‘a grave violation of humanitarian law’: UNESCO

This article is published in association with United Nations. The UN education agency, UNESCO, says that the bombing of a primary school during the US and Israeli military attacks on Iran on Saturday constitutes a grave violation of humanitarian law. The missiles reportedly destroyed a girl’s primary school in Minab, southern Iran, killing around 150 and […]
© UNRCO Iran Tehran, the capital of Iran.

Attacks on Iran and retaliatory strikes ‘undermine international peace and security’

This article is published in association with United Nations. UN Secretary-General António Guterres and the heads of UN agencies have condemned Saturday’s joint Israeli and US attacks on Iran and the Iranian retaliatory strikes on Israel and the Gulf Regions. The attack on Iran reportedly targeted military sites as well as the leadership of the Iranian […]
© WFP/Maxime Le Lijour A woman holds a child as a storm approaches Khan Younis in Gaza.

Palestine: UN rights chief highlights suffering, atrocity crimes ‘that remain unpunished

This article is published in association with United Nations. The UN rights chief Volker Türk on Thursday highlighted the “human-made disaster” across the Occupied Palestinian Territory stemming from Israel’s disregard for human rights norms and serious violations also committed by Hamas and other Palestinian armed groups. Citing a new report from his office (OHCHR) covering the […]
Ángela Soria Pitarch was born on March 28, 2003. She is currently a fifth-year medical student at the University of Valencia.

Not the Future, the Present: Young Voices Shaping Global Health in 2026

This article was exclusively written for The European Sting by Ms. Ángela Soria Pitarch was born on March 28, 2003. She is currently a fifth-year medical student at the University of Valencia. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to […]
© UNOCHA Many rural areas of Ukraine have been blasted by shelling and drone strikes. The country is also one of the most mined in the world, top UN aid officials warn.

Ukraine wakes to more violence as Russia’s invasion enters fifth year

This article is published in association with United Nations. The full-scale invasion of Ukraine by Russian troops on 24 February 2022 shattered the peaceful aspirations of an entire continent, but war must never be the new normal, UN General Assembly President Annalena Baerbock said on Tuesday. “Four years ago, people in Europe woke up in another […]
Fokah Wembe Darrell Dupray is a 4th-year medical student at Université des Montagnes, Bangangté Cameroon and a student leader within the Cameroon Medical Students’ Association (CAMSA).

From Local Barriers to Global Lessons: Practical Paths Toward Inclusive Healthcare

This article was exclusively written for The European Sting by Ms. Zainatun Nawwariyah is a fifth-year medical student at the Faculty of Medicine, University of North Sumatera, who is passionate about advancing medicine through research, advocacy, and service. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com