Remote Encryption Attacks Surge: How One Vulnerable Device Can Spell Disaster

Share:

Ransomware groups are increasingly switching to remote encryption in their attacks, marking a new escalation in tactics adopted by financially motivated actors to ensure the success of their campaigns.

“Companies can have thousands of computers connected to their network, and with remote ransomware, all it takes is one underprotected device to compromise the entire network,” Mark Loman, vice president of threat research at Sophos, said.

“Attackers know this, so they hunt for that one’ weak spot’ — and most companies have at least one. Remote encryption is going to stay a perennial problem for defenders.”

Remote encryption (aka remote ransomware), as the name implies, occurs when a compromised endpoint is used to encrypt data on other devices on the same network.

In October 2023, Microsoft revealed that around 60% of ransomware attacks now involve malicious remote encryption in an effort to minimize their footprint, with more than 80% of all compromises originating from unmanaged devices.

“Ransomware families known to support remote encryption include Akira, ALPHV/BlackCat, BlackMatter, LockBit, and Royal, and it’s a technique that’s been around for some time – as far back as 2013, CryptoLocker was targeting network shares,” Sophos said.

A significant advantage to this approach is that it renders process-based remediation measures ineffective and the managed machines cannot detect the malicious activity since it is only present in an unmanaged device.

The development comes amid broader shifts in the ransomware landscape, with the threat actors adopting atypical programming languages, targeting beyond Windows systems, auctioning stolen data, and launching attacks after business hours and at weekends to thwart detection and incident response efforts.

Remote Encryption Attacks

Sophos, in a report published last week, highlighted the “symbiotic – but often uneasy – relationship” between ransomware gangs and the media, as a way to not only attract attention, but also to control the narrative and dispute what they view as inaccurate coverage.

This also extends to publishing FAQs and press releases on their data leak sites, even including direct quotes from the operators, and correcting mistakes made by journalists. Another tactic is the use of catchy names and slick graphics, indicating an evolution of the professionalization of cyber crime.

“The RansomHouse group, for example, has a message on its leak site specifically aimed at journalists, in which it offers to share information on a ‘PR Telegram channel’ before it is officially published,” Sophos noted.

While ransomware groups like Conti and Pysa are known for adopting an organizational hierarchy comprising senior executives, system admins, developers, recruiters, HR, and legal teams, there is evidence to suggest that some have advertised opportunities for English writers and speakers on criminal forums.

“Media engagement provides ransomware gangs with both tactical and strategic advantages; it allows them to apply pressure to their victims, while also enabling them to shape the narrative, inflate their own notoriety and egos, and further ‘mythologize’ themselves,” the company said.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:59 am, Jan 22, 2025
weather icon 3°C
L: 2° | H: 3°
mist
Humidity: 90 %
Pressure: 1007 mb
Wind: 1 mph SE
Wind Gust: 2 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 4 km
Sunrise: 7:52 am
Sunset: 4:31 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
2° | 3°°C 1 mm 100% 5 mph 95 % 1006 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
2° | 8°°C 1 mm 100% 17 mph 94 % 1005 mb 0 mm/h
Fri Jan 24 9:00 pm
weather icon
6° | 10°°C 1 mm 100% 24 mph 91 % 1004 mb 0 mm/h
Sat Jan 25 9:00 pm
weather icon
4° | 6°°C 0.89 mm 89% 8 mph 86 % 1012 mb 0 mm/h
Sun Jan 26 9:00 pm
weather icon
5° | 8°°C 0.2 mm 20% 14 mph 86 % 1011 mb 0 mm/h
Today 3:00 am
weather icon
3° | 3°°C 0 mm 0% 3 mph 90 % 1006 mb 0 mm/h
Today 6:00 am
weather icon
3° | 3°°C 0.8 mm 80% 3 mph 92 % 1006 mb 0 mm/h
Today 9:00 am
weather icon
3° | 4°°C 1 mm 100% 3 mph 94 % 1005 mb 0 mm/h
Today 12:00 pm
weather icon
4° | 4°°C 0.8 mm 80% 4 mph 91 % 1003 mb 0 mm/h
Today 3:00 pm
weather icon
4° | 4°°C 0 mm 0% 5 mph 89 % 1002 mb 0 mm/h
Today 6:00 pm
weather icon
3° | 3°°C 0 mm 0% 3 mph 87 % 1003 mb 0 mm/h
Today 9:00 pm
weather icon
2° | 2°°C 0 mm 0% 4 mph 95 % 1004 mb 0 mm/h
Tomorrow 12:00 am
weather icon
2° | 2°°C 0 mm 0% 3 mph 94 % 1004 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€101,415.65
4.40%
Ethereum(ETH)
€3,192.40
2.59%
XRP(XRP)
€3.06
2.81%
Tether(USDT)
€0.96
0.13%
Solana(SOL)
€241.91
6.62%
Dogecoin(DOGE)
€0.353595
6.42%
USDC(USDC)
€0.96
0.00%
Shiba Inu(SHIB)
€0.000020
2.88%
Pepe(PEPE)
€0.000015
2.70%
Peanut the Squirrel(PNUT)
€0.354125
-1.82%
Scroll to Top