• About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Privacy Policy
  • Contact us
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • Channel Awards 2024
    • All events
  • GITEX
  • Digital Magazine
No Result
View All Result
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • Channel Awards 2024
    • All events
  • GITEX
  • Digital Magazine
No Result
View All Result
CXO Insight Middle East
No Result
View All Result

Four Key Ransomware Trends You Shouldn’t Ignore

by CXO Staff
September 5, 2021
in Opinions

Mohammed Al-Moneer at Infoblox, sheds light on key ransomware trends that regional organisations should take note of to secure their businesses.

ransomware

Trend 1 – Ransomware attacks continue to grow

Ransomware is once again front and center. This year has turned out to be one of the worst years for ransomware. Why? Because that’s where the big money is. Large potential return on investment makes ransomware extortion activities highly compelling for threat actors. Verizon’s 2021 Data Breach Investigations Report notes, “The novel fact is that 10 percent of all breaches now involve ransomware.”

Cybereason’s recent ransomware study of nearly 1,300 security professionals reveals that more than half of organizations have fallen victim to ransomware attacks. In addition, 80 percent of businesses that have paid ransoms have suffered second ransomware attacks, often from the same threat actors.  66 percent of organizations surveyed reported significant loss of revenue after a ransomware attack, 53 percent of organizations indicated that their brand and reputation were damaged as a result of a successful attack, and 32 percent reported losing C-level talent as a direct result of ransomware attacks. As many as 26 percent of organisations reported that ransomware attacks forced their businesses to close temporarily.

Trend 2 – Ransomware as a Service expands

The ransomware attacks on JBS and Colonial Pipeline are examples of criminal organizations using RaaS platforms. Many potential threat actors lacking the skills to build and launch their own ransomware attacks can buy what they need through the dark web. Nearly two-thirds of ransomware attacks during 2020 came from RaaS-based platforms.

RaaS platforms include support, community forums, documentation, updates, and more. They are closely modelled after the type of support offered with legitimate SaaS products. Some RaaS websites offer supporting marketing literature and user testimonials. The cost is relatively low. In some cases, affiliates can sign up for a one-time fee or for a monthly subscription. Some RaaS platforms are set up without any initial fees and share the fees associated with a successful attack. Other platforms might have charges for special features, such as the view of a status update of active ransom infections, the number of files encrypted, and payment information.

The use of highly targeted RaaS attacks has been lucrative for threat actors. RaaS attacks that target large organizations can, in turn, ask for large ransoms. In these highly targeted cases, threat actors sometimes use carefully researched social-engineering tactics, such as well-crafted emails to entice targets to click dangerous URLs or open malicious attachments. In other cases, threat actors may target a vulnerability that is particular to or commonly used by their target victim group.

Trend 3 – Ransomware leak sites are a new threat actor tactic of choice

Threatening to post a victim’s data on a data-leak site increases the leverage of a ransomware threat actor and is another part of their strategy, in addition to encrypting a victim’s files. The damage of this exposure might be greater than the financial damage of agreeing to pay the ransom the actor has demanded.

Trend 4 – Ransomware distribution methods remain tried and true

Attackers continue to use tried and true ransomware distribution methods – their tactics, techniques, and procedures work well for them and these attack vectors continue to bring them success. The four distribution methods are malicious websites, malspam email, the remote desktop protocol, and USB memory sticks. Depending on the report cited, time period, and companies surveyed, the percentages of ransomware attacks that use these distribution methods have varied significantly.

  • A malicious website distributes harmful downloads to users socially engineered to click links to that site. In addition to setting up their own spoofed site, threat actors can find and exploit vulnerabilities in a legitimate website and implant malicious code on it. Alternatively, they may use it to redirect the target to another website under their control. Some of the most well-known media and sports websites in the world have at some point been compromised or hijacked.
  • Threat actors consistently use email campaigns employing social engineering tactics as distribution methods for their malware, downloaders or malicious links. Some attacks are highly targeted against one individual or organization, a technique known as spear-phishing, but others are larger, broader campaigns.
  • RDP has become a highly effective and dangerous attack vector. Several years ago, one study noted that over 10 million online machines were configured with an open port, 3389. It has become a simple matter for threat actors to use search engines, such as Shodan, to locate these devices. Threat actors can gain access to RDP servers by using default passwords on servers that have not been updated. Alternatively, the actors can use brute-force techniques to break in, or they can use open-source password crackers.
  • USB memory sticks have been used to distribute many types of malware, including ransomware and that has not changed over many years. Threat actors leave USB drives in coffee shops, airports, mailboxes, and corporate lounges, for unsuspecting targets to pick up and use. Once a weaponized USB drive is inserted into a computer, the ransomware encrypts files on the device and propagates within the network.
Tags: featuredInfobloxransomware
ShareTweet

Related Posts

Channel Vision Strategy: Empowering cyber resilience
Opinions

What most businesses get wrong about data security

In today's AI-driven world, vast amounts of data are generated daily across industries like finance, e-commerce, healthcare, and government services....

June 11, 2025
Why private cloud matters
Opinions

Why private cloud matters

As digital transformation accelerates across industries, private cloud has become a vital infrastructure model for organisations seeking the flexibility of...

June 9, 2025

Discussion about this post

Latest Issue

Tech predictions for 2024 and beyond

Amazon’s Werner Vogels on how cloud, data, and culture are shaping AI

June 13, 2025
WSO2 acquires API analytics and monetisation startup Moesif

Bold visions, stronger partnerships: AWS co-innovates across the Middle East

June 13, 2025
NTT DATA launches AI-powered SDI services for Cisco products

NTT DATA launches AI-powered SDI services for Cisco products

June 13, 2025

The most trusted source of strategic intelligence for IT decision makers in the Middle East.

About

  • About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Contact Us

Policies

  • Privacy Policy

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f X-twitter Linkedin
Separated they live in Bookmarksgrove right at the coast of the Semantics, a large language ocean. A small river named Duden.

About

  • About Us
  • Site Map
  • Contact Us
  • Career

Policies

  • Help Center
  • Privacy Policy
  • Cookie Setting
  • Term Of Use

Join Our Newsletter

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f Twitter Youtube Instagram

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Join our mailing list
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
No Result
View All Result
  • News
  • Opinions
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
  • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CX50 Oman
    • CXO50
    • ICT Awards
      • Dubai
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • Channel Awards 2023
    • All events
  • Videos
  • GITEX GLOBAL
  • Digital Magazine

© 2024 - CXO Insight Middle East. All Rights Reserved.