The ransomware warning sign we should all have on our radar

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Wallis Romzek, Principal Data Scientist, SpyCloud


  • In 2023, over 80% of companies were affected by ransomware in the preceding 12 months.
  • By looking more closely at how ransomware attacks happen, we can spot warning signs sooner and act on them to prevent future attacks.
  • In the fight against ransomware, the best defence is one built on data and aligned properly to the threats a company faces.

The cybersecurity community talks a lot about ransomware attacks: who the latest ransomware gangs are, common attack vectors, how much companies are shelling out in ransom payments and what the proper incident response protocols are for security teams.

That all matters, of course. By and large though, security teams are already aware of the threat ransomware poses due to firsthand experience. In 2023, 81% of companies were affected by ransomware in the preceding 12 months. Reported effects vary widely, from needing to purchase a solution to combat ransomware attacks, to being actively targeted, to actually paying a ransom. Regardless, the rate of companies affected by ransomware has remained consistently high since 2021.

The far-reaching impacts of ransomware, combined with the fact that we’re on track for the second costliest year for ransomware in history, means it’s time to take another look at the ransomware problem and think about tackling it from a new angle. By looking more closely at how ransomware attacks happen in the first place – through means that may not be on security teams’ radars yet – we can spot warning signs sooner and act on them to defend against attacks altogether.

How ransomware usually starts

Let’s start with one of the most common entry points for a ransomware attack: compromised credentials.

Criminals love authentication credentials because they are a reliable lever for gaining access to systems and information that allow them to perpetrate crimes. Threat actors often get their hands on credentials by using infostealer malware, which is typically deployed through malicious websites, botnets or phishing emails.

With one click, a user can become infected, allowing the malware to steal a wide variety of information stored on the user’s machine – from private data, such as credit card numbers, to usernames and passwords and even web session cookies that open doors to corporate resources.

And, when one door opens many others often do, too. SpyCloud research shows that 72% of users whose data was exposed in two or more breaches in 2022 reused their passwords across applications. That means that nearly three in four people were actively using a compromised password, making it pretty easy for threat actors to take one exposed credential pair and gain access to their information and files across multiple accounts, including work applications.

Discover

How is the World Economic Forum addressing rising cybersecurity challenges?

What new research says about the infostealer malware

Here’s where it gets interesting. With access credentials gained via infostealer malware, threat actors can connect dots to then steal, encrypt and ransom sensitive or proprietary data across an enterprise system – launching a full-blown ransomware attack. For the first time, cutting-edge research confirms this is what (at least some) threat actors are doing. The presence of an infostealer infection is indeed an early warning signal of the potential for ransomware.

In a sample of North American and European companies that experienced a ransomware attack in 2023, nearly one in three were infected with infostealer malware in the months leading up to the attack (2023 SpyCloud Ransomware Defence Report).

What does this mean for security teams?

As a risk signal, an infostealer malware presence should trigger companies’ ransomware radar and motivate a comprehensive malware remediation response.

We can’t say with certainty that a ransomware attack follows an infostealer malware infection every time. Only threat actors themselves know how they intend to use the information they steal. But, infostealer malware presence is a good starting point for better defence and prevention.

We can use this starting point to build out a broader picture to understand the role that infostealers play in a ransomware attack. This will improve awareness of potential threats and better inform security defence priorities and tactics.

So, how do we build upon the role of infostealer infections in a ransomware kill chain?

First, we broaden our perspective. We assess the circumstances that preceded the infection. Patching priorities that focus on exploitable vulnerabilities, for example, may make it more difficult for a threat actor to gain entry in the first place. Security awareness training that keeps up with modern attacker techniques could have a similar mitigating effect on the risk of infostealer malware.

We also consider the steps an attacker is likely to take after infection and the data to which they have access. Perhaps single sign-on credentials and additional application access are the actor’s targets. Or, perhaps malicious actors are after crypto wallets.

Collecting and evaluating signals around infostealer malware can shed light on a company’s status and circumstances and help to locate infostealer malware appropriately in a ransomware kill chain. These additional signals will add context and nuance to our understanding of infostealer malware and might even serve as additional early warning signals themselves.

Second, we act on what we know – and keep watching. We get to work monitoring for, and remediating, infostealer malware infections and take steps to limit the potential damage that could result from data exfiltration.

Then we continue to collect and evaluate data and signals as companies either fall victim to or evade ransomware attackers. Over time, these signals will reveal patterns that will further contextualize the infostealer-ransomware connection. They will allow researchers to leverage large-scale analytics and machine-learning algorithms to understand it, learn from it and use it to support defensive tactics.

In the fight against ransomware, the best defence is one built on data and aligned appropriately to the threats a company faces. An organization’s vulnerability to ransomware attacks will rely in part on its unique environment, characteristics and needs. Our research at SpyCloud indicates, however, that the connection between infostealer infections and ransomware attacks persists regardless of company shape or size.

If that is the case, a ransomware prevention plan can only be considered comprehensive if it includes monitoring for and remediating infostealer

malware exposure.

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

© UNICEF/Amer Almohibany Destroyed buildings in Harasta, Ghouta. A suburb of Damascus, Ghouta was the site of a deadly chemical weapons attack in August 2013.

Undeclared chemical weapons found in Syria, including type used in notorious Ghouta massacre

This article is published in association with United Nations. Chemical weapons inspectors have uncovered a significant cache of previously undeclared chemical weapons in Syria – including rockets of the same type used in the notorious 2013 Ghouta attack – in what the UN’s top disarmament official called a “momentous discovery” for international security. Izumi Nakamitsu briefed […]
© UNICEF Vanessa Frazier, Special Representative on Children and Armed Conflict, during a visit to frontline areas in Ukraine.

Growing up with sirens: UN child rights envoy on the toll of the Ukraine-Russia war

This article is published in association with United Nations. Children in Ukraine have been profoundly impacted by years of war, sheltering in underground schools – or forced to study online – and living with the psychological strain of constant air raid sirens that could spell death for them and their families. But children on both sides […]
OCHA/Charlotte Cans The El Niño-induced drought in Ziway Dugda, Oromia region of Ethiopia, is affecting every family and they don't have enough food at home to feed themselves. (file photo).

El Niño confirmed, set to fuel more extreme weather, says WMO

This article is published in association with United Nations. The UN urged all countries on Tuesday to bolster early warning systems after confirming the onset of El Niño, warning that the Pacific Ocean-warming phenomenon will bring above-average temperatures “nearly everywhere” and fuel more extreme weather. According to the World Meteorological Organization (WMO), there is an 80 […]
© UNICEF The aftermath of a Russian strike on a residential area in Kyiv, Ukraine’s capital.

UN deplores another wave of Russian attacks across Ukraine

This article is published in association with United Nations. Overnight attacks in three key cities in Ukraine have left several civilians dead, scores more injured, and homes, hospitals and shops destroyed or damaged, the UN Humanitarian Coordinator in the country said on Tuesday.  Matthias Schmale condemned the large-scale Russian assault on the capital Kyiv, as well as Dnipro and Kharkiv, […]
© WHO/Joël Lumbala A shipment of essential medical supplies for the Ebola response arrives at Bunia airport in Ituri province, DR Congo.

DR Congo Ebola outbreak: Nurses discharged after full recovery

This article is published in association with United Nations. Four nurses who fell ill with Ebola in the eastern Democratic Republic of the Congo (DRC) have been discharged from hospital after recovering from the often-fatal illness that sparked an international health alert.  “More recoveries are expected, especially when people are diagnosed early and able to access care, and […]
This article is published in association with United Nations.

Under fire, Kharkiv is already building for a peaceful tomorrow

This article is published in association with United Nations. Every day in Kharkiv begins with uncertainty: air raid sirens interrupt sleep; missiles strike residential neighbourhoods, industrial sites, and roads. Anxious citizens rush into metro stations during bombardments and children study underground. Yet amid the destruction, Ukraine’s second-largest city is doing something that may seem almost impossible […]
© UNOCHA A heavily damaged apartment building in Sloviansk, eastern Ukraine.

UN warns Ukraine war risks spiralling ‘out of control’

This article is published in association with United Nations. The United Nations on Thursday warned of a dangerous escalation in the war in Ukraine after a wave of large-scale Russian strikes and threats of further attacks, with Secretary-General António Guterres saying “the death spiral must stop.” Addressing the Security Council in New York, Mr. Guterres said […]
© WHO A frontline health worker in PPE (personal protective equipment) takes part in the Ebola response in eastern Democratic Republic of the Congo.

Ebola outbreak in DR Congo collides with conflict and hunger, WHO warns

This article is published in association with United Nations. The UN World Health Organization (WHO) on Wednesday warned that eastern Democratic Republic of the Congo faces a “catastrophic collision of disease and conflict” as a fast-spreading Ebola outbreak outpaces containment efforts in a region already battered by armed violence, mass displacement and acute hunger. WHO Director-General […]
© WFP/Michael Castofas WFP staff and responders handle boxes of supplies at a logistics site in DR Congo during the Ebola outbreak.

International airlines urged to stick to safety measures in wake of Ebola outbreak

This article is published in association with United Nations. As a deadly Ebola strain continues to spread in the Democratic Republic of the Congo (DRC), with cases confirmed in neighbouring Uganda, the UN aviation agency is urging governments and flight operators to closely follow guidelines put in place following the COVID-19 pandemic. The outbreak of the […]
© WHO Supplies to bolster the response against the Ebola outbreak in Ituri province arrive in the town of Bunia.

Ebola epidemic spreading rapidly and outpacing containment efforts

This article is published in association with United Nations. There are more than 900 suspected cases of the Bundibugyo strain of Ebola in the Democratic Republic of the Congo, and 220 suspected deaths, the head of the World Health Organization (WHO), Tedros Ghebreyesus, said on Monday. The latest outbreak of the deadly disease, which WHO has declared […]
This article is published in association with United Nations.

WHO chief calls for urgent Ebola action and pandemic preparedness

This article is published in association with United Nations. The recent Ebola and hantavirus outbreaks demonstrate that the world is still vulnerable to rapidly spreading infectious diseases, Tedros Ghebreyesus, the head of the World Health Organization (WHO), warned on Saturday at the close of the 79th World Health Assembly in Geneva. His call came as Ugandan […]
This article is published in association with United Nations.

UN agencies step up Ebola response in eastern DR Congo

This article is published in association with United Nations. United Nations agencies have moved swiftly to support efforts to contain the latest Ebola outbreak in eastern Democratic Republic of the Congo (DRC), delivering emergency medical supplies, protective equipment and logistics support. As health authorities in both the DRC and Uganda respond to the deadly resurgence, the […]
© UNICEF/Josue Mulala Emergency aid is prepared for delivery to Kasaï province in response to the recently declared Ebola virus disease outbreak in DR Congo.

Ebola risk is high inside DR Congo but it’s no pandemic emergency: WHO

This article is published in association with United Nations. The deadly Ebola outbreak in Democratic Republic of the Congo (DRC) and Uganda does not represent a global pandemic emergency, although the risk is high at a regional and national level, the UN health agency chief said on Wednesday. In an update on the fast-developing situation in […]
This article is published in association with United Nations.

How the Hormuz crisis keeps disrupting kitchens, ports and paychecks

This article is published in association with United Nations. The fragile ceasefire between the United States and Iran may have eased fears of a wider regional war, but persistent instability around the Strait of Hormuz continues to disrupt global trade, drive up energy costs and fuel a growing jobs and cost-of-living crisis. The fallout is being […]
© UNFPA Ukraine In March 2026, a maternity hospital in Odesa, Ukraine was attacked by Russian forces.

World News in Brief: More attacks in Ukraine, violence against children in Haiti, refugee IDs in Africa

This article is published in association with United Nations. Civilians, including humanitarians, continue to face great danger across war-torn Ukraine amid ongoing hostilities, according to the UN humanitarian relief coordination office there, OCHA. Over the past three days, frontline attacks killed at least 11 civilians and injured nearly 200 others, including five children, as reported by […]
UN Photo/Milton Grant Sculpture depicting St. George slaying the dragon. The dragon is created from fragments of Soviet SS-20 andUnited States Pershing nuclear missiles.

Nuclear terror threat ‘has never been so high’

This article is published in association with United Nations. The widespread availability of new technology, such as militarised drones and artificial intelligence, means that the current threat of nuclear terrorism is higher than it has ever been. The humanitarian, environmental, and economic consequences of a radiological or nuclear terrorist attack would be global, undermining international peace […]
© UNICEF/Nyan Zay Htet Recent disruptions to energy supplies and global supply chains have reverberated across development and humanitarian sectors, including relief efforts in Myanmar, where millions remain in need of assistance.

Global energy and trade disruption pushing millions towards poverty

This article is published in association with United Nations. Disruptions to global energy supplies and trade corridors are driving up the cost of food, transport and essential goods worldwide, slowing economic growth and increasing pressure on vulnerable households and debt-strapped developing countries. The warnings came during a special meeting of the UN Economic and Social Council […]
UN Photo/Eskinder Debebe UN Relief Chief Tom Fletcher (centre) along with Ambassador Mike Waltz (right) and Jeremy P. Lewin of the United States hold a joint press briefing on funding to the humanitarian system.

UN welcomes $1.8 billion US boost for humanitarian operations

This article is published in association with United Nations. An additional $1.8 billion in US humanitarian funding will allow the United Nations and its partners to expand emergency relief operations reaching millions of people worldwide, as rising global needs and funding shortfalls force aid agencies to scale back assistance. The funding announcement, made on Wednesday by […]
© WHO/Hanan Balkhy Displaced families are living in overcrowded tents and makeshift shelters, surrounded by waste and debris, with limited access to safe water and sanitation services.

World News in Brief: Mounting waste in Gaza, drone attacks in Sudan, aid truck struck in Ukraine

This article is published in association with United Nations. Mounting waste and limited access to sanitation sites are deepening health risks for families across Gaza, as humanitarian workers warn that overcrowded dumping areas and worsening living conditions threaten vulnerable communities. Ramiz Alakbarov, UN’s top aid official in Occupied Palestinian Territory visited a dumping site in Gaza […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com