07.09.2022
Blog
Cyber Security

The alarming rise of Ransomware as a Service (RaaS)

Ransomware as a Service is a new and serious trend. Large-scale ransomware attacks on businesses are repeatedly making the headlines. But the good news is: ‘The first line of defence is you’ – everyone can play their part in combating this threat.

Thorsten Kuhles
Cyber Security Incident Manager

Ransomware attacks on home users and businesses are no longer a rare occurrence. No business, regardless of the sector it operates in, is immune to them. Last year, the impact was felt across all sectors and in almost every region of the world. In July 2021, up to 1,500 organisations were paralysed following the compromise of Kaseya’s technical management software. The cybercriminals used an encryption Trojan to block access to IT systems in order to extort large ransoms. In early 2022, a major attack on Bernalillo County in New Mexico made headlines.

The chart below shows the rapid increase in single-ransom attacks and illustrates the growing popularity of this malware amongst criminals. Over the past two years, the number of ransomware attacks has almost doubled.

Source: BlackFog – The State of Ransomware

The apparent success of such cyber-attacks has triggered a veritable race amongst criminals in their search for similar vulnerabilities. Potential attackers see an opportunity to make money quickly and easily, relying primarily on users’ shortcomings. A new trend is currently emerging which makes it even easier for such attacks to spread and could become a nightmare for businesses: Ransomware as a Service (RaaS). This new business model for cybercriminals will account for a larger share of the threat landscape in 2022. It offers attackers a highly effective opportunity to ‘make’ money. Purchasing a RaaS kit eliminates the need for extensive programming experience or technical knowledge and provides access to sophisticated malware tools.

How does the RaaS model work?

RaaS is based on the Software-as-a-Service (SaaS) model, where software can be accessed online via a subscription. However, the Ransomware-as-a-Service (RaaS) model is evolving in its own way. This fully functional and independent ecosystem thrives in the underground, with its key players – including the operators who develop and distribute the ransomware. The operators are usually organised into a group with specific roles, such as leaders, developers, and infrastructure and system administrators.

How can you protect yourself proactively?

According to the Financial Crimes Enforcement Network (FinCEN) of the US Department of the Treasury, suspicious transactions linked to ransomware caused losses of around 590 million US dollars between January and June 2021. The FinCEN report also states that the ten largest hacker groups have traded bitcoins worth around US$5.2 billion over the past three years. This trend is fuelling greed and has led to a massive surge in attacks explicitly aimed at extorting money from RaaS victims. The simplicity of the method relative to the ‘profit’ makes it so attractive to criminals and so dangerous for businesses.

With an increase of more than 130 different ransomware strains since 2020, the likelihood of being attacked by one of these rapidly evolving variants is very high. To protect themselves, regular data backups and software updates are essential. Companies are also well advised to train their staff in cyber security awareness. Ransomware can be triggered by just a single careless click on a link in an email – which is why aware staff are the first line of defence. Appropriate awareness campaigns are a key measure to prevent attackers from gaining a foothold in the first place. In our Cyber Security focus area, we at Materna place great emphasis on the topic of awareness and advise you on trends and various areas requiring action. In an emergency, our experts can also assist with remediation and data recovery.

Thorsten Kuhles
Cyber Security Incident Manager

Thorsten Kuhles verantwortet als Cyber Security Incident Manager bei Materna die interne und externe Vorfallsbearbeitung. Zuvor war er langjährig u.a. im Bereich Pentesting und IT-Forensik bei der Bundeswehr sowie in Führungspositionen im Bereich Cyber Security bei namhaften Unternehmen tätig.