Malwarebytes-2019年勒索软件回顾报告(英文)-2019.8-28页_5mb
报告摘要
Ransomware Retrospective Summary
Core Content
This report provides an in-depth analysis of ransomware trends from Q2 2018 to Q2 2019, focusing on the shift from consumer to business targets. It highlights the evolution of ransomware families, regional impact, and the reasons behind the change in attack focus.
Main Points
- Shift in Target Focus: Ransomware has moved from targeting individual consumers to businesses and organizations, driven by higher financial returns.
- Increase in Business Detections: Business ransomware detections increased by 363% year over year, while consumer detections dropped by 12% YoY and 25% QoQ.
- Ransomware Families: Key families include GandCrab, Ryuk, Troldesh, Phobos, and Rapid. Ryuk and Phobos showed significant growth, especially in 2019.
- Regional Analysis: North America accounted for nearly 50% of all ransomware detections, followed by EMEA at 35%, LATAM at 10%, and APAC at 7%.
- Country Breakdown: The United States had the highest ransomware detections (53%), followed by Canada (10%), UK (9%), Brazil (7%), and others. Texas, California, and New York were the top US states affected.
- Legacy Infrastructure: Cities, education, and healthcare sectors are particularly vulnerable due to outdated systems and limited funding for cybersecurity.
Key Ransomware Families and Trends
GandCrab
- Overview: A RaaS model ransomware family that was the most active for consumers and second for businesses.
- Trend: Detections declined by 43% YoY and 33% QoQ. Despite its retirement announcement, it remains active.
- Impact: Declined in both consumer and business detections by the end of 2019.
Ryuk
- Overview: A highly damaging ransomware family that targets businesses.
- Trend: Detections increased by 88% over Q1 2019. It remained a top threat for businesses.
- Method: Often delivered through phishing campaigns and lateral movement via malware like Emotet and TrickBot.
Troldesh
- Overview: An older ransomware family that primarily targets Russia.
- Trend: Consumer detections increased by 162% YoY but declined by 55% QoQ. Business detections outpaced consumer ones in Q2 2019.
- Spread: Spread via malspam and compromised CMS platforms like WordPress and Joomla.
Phobos
- Overview: A new ransomware family that emerged in 2019, similar to Dharma.
- Trend: Business detections surged by 940% from Q1 to Q2 2019, while consumer detections dropped by 55%.
- Method: Exploits RDP ports, uses persistence mechanisms, and has similar ransom note text and style to Dharma.
Rapid
- Overview: A ransomware family that has been active for years, evolving with new features.
- Trend: Detections increased by more than 200% in June 2019, but declined by 57% QoQ.
- Method: Spread through phishing emails and RDP exploits.
Legacy Families
- Cerber: First discovered in 2016, it was a RaaS pioneer. It declined significantly after the arrests of its affiliates in 2017 and is now considered "dead" by many.
- Locky: Another 2016 family, it declined in 2018 due to the rise of cryptomining and was later rebranded as Phobos.
Regional and Country Analysis
- North America: Dominated ransomware activity, with GandCrab and Ryuk being the most prevalent.
- Europe, Middle East, and Africa (EMEA): Second-largest region for ransomware, with similar top families to NORAM.
- Latin America and Asia Pacific: Smaller percentages of ransomware activity, but with a notable focus on GandCrab in APAC.
- Top Countries: The US (53%), Canada (10%), UK (9%), Brazil (7%), and others.
- Top US States: Texas, California, and New York had the highest ransomware detections, despite not being the most populous.
Conclusion
Ransomware has evolved significantly over the past few years, shifting from mass consumer attacks to highly targeted business campaigns. The financial incentives for targeting businesses are clear, as they offer larger ransom payouts and greater chances of payment. While some families like GandCrab and Cerber have declined, others like Ryuk and Phobos have surged. The global threat landscape is changing, and businesses must be prepared for increasingly sophisticated and targeted ransomware attacks.
试读结束,高清完整版pdf/doc/ppt,请点下载