{"id":519364,"date":"2021-09-09T06:50:42","date_gmt":"2021-09-09T04:50:42","guid":{"rendered":"https:\/\/businesstech.co.za\/news\/?p=519364"},"modified":"2021-09-09T06:50:42","modified_gmt":"2021-09-09T04:50:42","slug":"protect-your-organisation-as-ransomware-as-a-service-ramps-up-its-ddos-attack-offering","status":"publish","type":"post","link":"https:\/\/businesstech.co.za\/news\/industry-news\/519364\/protect-your-organisation-as-ransomware-as-a-service-ramps-up-its-ddos-attack-offering\/","title":{"rendered":"Protect your organisation as ransomware-as-a-service ramps up its DDoS attack offering"},"content":{"rendered":"<p>The services industry has traditionally included sectors ranging from social assistance and health care to transportation and scientific services.<\/p>\n<p>However, it doesn\u2019t end there, because the human talent for innovation can turn almost anything into a service.<\/p>\n<p>We also find \u2013\u00a0 rather less top-of-mind for most people \u2013 the offer of hitmen-as-a-service, usually associated, at least in Hollywood, with large and well-muscled men in expensive suits and sunglasses.<\/p>\n<p>A few years ago, this area of business moved into the cyber arena as well.<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/networksunlimited.africa\/products\/security\/netscout?utm_source=BusinessTech&amp;utm_medium=Article&amp;utm_campaign=September+2021\" target=\"_blank\" rel=\"noopener\"><strong>Click here to learn more about NETSCOUT\u00a0<\/strong><\/a><\/strong><\/li>\n<\/ul>\n<p>And so we present: ransomware-as-a-service.<\/p>\n<p>Today, one of its latest offerings is a \u2018triple threat\u2019 that turns Distributed Denial of Service (DDoS) attacks into an even more lethal cyber weapon against organisations.<\/p>\n<p>Carole Hildebrand, Senior Strategic Marketing Writer at NETSCOUT, calls it\u00a0<strong><a href=\"https:\/\/www.netscout.com\/blog\/triple-extortion-tactics-rise-ransomware-gangs?utm_source=BusinessTech&amp;utm_medium=Sponsored+Article+&amp;utm_campaign=September+2021+\" target=\"_blank\" rel=\"noopener\"><strong>\u2018the rise of ransomware gangs\u2019<\/strong><\/a><\/strong>.<\/p>\n<p>She explains: \u201cLike any smart entrepreneur, threat actors know that their business is only as successful as their latest innovation.<\/p>\n<p>And when it comes to parting unsecured organisations from their money, those innovations never stop.<\/p>\n<p>\u201cThe latest involves integrating attacks into a ransomware-as-a-service (RaaS) portfolio to create the so-called triple cyberextortion attack.<\/p>\n<p>It\u2019s a little bit ransom, a little bit DDoS extortion, and a lot of trouble.\u201d<\/p>\n<p>NETSCOUT is a leading global provider of service assurance, security and business analytics, distributed throughout Africa by Networks Unlimited.<\/p>\n<p>In its \u20182020 2H Threat Intelligence Report: DDoS in a time of pandemic\u2019, NETSCOUT observed a huge upsurge in DDoS attacks over the past year or so, including multiple record-breaking events such as the most DDoS attacks in a single year (more than 10 million).<\/p>\n<p>\u201cThe pandemic period to date has certainly facilitated the emergence of an increasingly complex threat landscape,\u201d comments Risna Steenkamp, General Manager: ESM Division at Networks Unlimited.<\/p>\n<p>\u201cDDoS attacks are an attempt to exhaust the resources available to a network, application or service, so that genuine users cannot gain access and the business accordingly cannot deliver the services it offers.&#8221;<\/p>\n<p>&#8220;Today, the purported \u2018triple threat\u2019 adds in two other factors on top of a DDoS threat.\u201d<\/p>\n<p>As outlined by Hildebrand, cybercriminals are now adding file encryption and data theft into DDoS attacks, creating a potent mix for a threat attacker\u2019s new modus operandi.<\/p>\n<p>The triple threat works as follows:<\/p>\n<p><strong>File encryption:<\/strong>\u00a0In a traditional ransomware attack method, cybercriminals breach a network and encrypt valuable data, making the data, and sometimes the entire system, unavailable to the victim organisation.<\/p>\n<p>The attackers then demand payment in return for a decryption key.<\/p>\n<p>In 2017, the Wannacry ransomware worm spread rapidly across computer networks, infecting core system processes and encrypting data files.<\/p>\n<p>In the end, this attack affected more than\u00a0<strong><a href=\"https:\/\/securityintelligence.com\/articles\/cyber-extortion-what-you-need-to-know-in-2021\/?utm_source=BusinessTech&amp;utm_medium=Sponsored+Article+&amp;utm_campaign=September+2021+\" target=\"_blank\" rel=\"noopener\"><strong>200,000 computers<\/strong><\/a><\/strong>\u00a0across 150 countries.<\/p>\n<p><strong>Data theft:<\/strong>\u00a0Here, cybercriminals steal the data before locking the victim out.<\/p>\n<p>They then threaten to publicly expose and\/or sell the stolen data unless they are paid.<\/p>\n<p>This second level of extortion makes it harder for victims to ignore ransomware threats, because even those who can use backups to restore data remain at risk of data exposure.<\/p>\n<p>Examples of massive data breaches of global companies include the following: creative, marketing and document management company Adobe (October 2013; 153 million user records stolen); Equifax, one of the largest credit bureaux in the United States (July 2017; 147.9 million customers); professional networking site LinkedIn (2012 and 2016; 165 million users); the hotel group Marriot International (2014 to 2018; 500\u00a0 million customers); social media site MySpace (2013; 360 million customers), and search engine Yahoo (2013 to 2014; three billion user accounts and the biggest data breach ever),\u00a0<strong><a href=\"https:\/\/www.csoonline.com\/article\/2130877\/the-biggest-data-breaches-of-the-21st-century.html?utm_source=BusinessTech&amp;utm_medium=Sponsored+Article+&amp;utm_campaign=September+2021+\" target=\"_blank\" rel=\"noopener\"><strong>to name just a few.<\/strong><\/a><\/strong><\/p>\n<p><strong>DDoS attacks:<\/strong>\u00a0Such attacks have been commonly used as a standalone extortion method.<\/p>\n<p>Now, adding this attack methodology into the RaaS operations adds further pressure onto the victim, as maintaining business operability and availability places further strain onto the cybersecurity teams already dealing with the first two events, namely the data theft and data encryption.<\/p>\n<p>At the end of August 2020, a series of cyberattacks on the New Zealand Stock Exchange over five consecutive days forced it to halt trading for a number of hours for four out of those five days.<\/p>\n<p>This was part of a\u00a0<strong><a href=\"https:\/\/fortune.com\/2020\/08\/31\/ddos-attacks-2020-new-zealand-stock-exchange\/?utm_source=BusinessTech&amp;utm_medium=Sponsored+Article+&amp;utm_campaign=September+2021+\" target=\"_blank\" rel=\"noopener\"><strong>global DDoS extortion campaign<\/strong><\/a><\/strong>\u00a0that went on over a number of months to target other organisations around the world.<\/p>\n<p>Hildebrand explains, \u201cBy combining file encryption, data theft, and DDoS attacks, cybercriminals have essentially hit a ransomware trifecta designed to increase the possibility of payment.<\/p>\n<p>According to\u00a0Bleeping Computer, SunCrypt and Ragnor Locker were early users of this tactic.<\/p>\n<p>Since then, other ransomware operators have jumped aboard, including\u00a0Avaddon and Darkside, the perpetrator of the Colonial Pipeline incident.\u201d<\/p>\n<p>The cyberattack on the American Colonial Pipeline Company in May 2021 instigated a shutdown of the almost 9,000 kilometre long pipeline that carries 45 percent of the fuel used on America\u2019s East Coast.<\/p>\n<p>It caused a rise in petrol prices, as well as the panic buying of petrol across the American Southeast region, and\u00a0<a href=\"https:\/\/www.technologyreview.com\/2021\/05\/24\/1025195\/colonial-pipeline-ransomware-bitdefender\/?utm_source=BusinessTech&amp;utm_medium=Sponsored+Article+&amp;utm_campaign=September+2021+\" target=\"_blank\" rel=\"noopener\"><strong>closures of thousands of petrol stations.<\/strong><\/a><\/p>\n<p>Hildebrand notes that, because DDoS attacks are inexpensive and easy to launch, and likely to increase the chance that a victim will pay the required ransom, it is a \u2018smart business move\u2019 to add these attacks to a list of ransomware services on offer.<\/p>\n<p>\u201cThe bottom line is that increasing pressure tactics ups the likelihood of a payoff, making ransomware an increasingly disruptive form of cybercrime that affects not only companies but also governments, schools, and public infrastructure,\u201d she explains.<\/p>\n<p>Companies therefore need to adhere to some fundamental protections, such as trying to avoid a network breach; returning to basics like backing up valuable data, running vulnerability assessments, patching and updating computer systems to avoid compromise; staying up-to-date with the latest threat intelligence; and using proper DDoS protection against the current trends, in which DDoS attacks are increasing in size, frequency and complexity.<\/p>\n<p>\u201cA business needs to protect itself against all types of potential DDoS threats,\u201d notes Steenkamp, \u201cand also implement the necessary protection against network breaches involving both encryption of data as well as data theft, in order to avoid a triple extortion attack.\u201d<\/p>\n<p>\u201cIf at all possible, you don\u2019t want your organisation to land up on any kind of list of companies that have suffered noteworthy data breaches \u2013 that is always the wrong kind of news, and the worst possible publicity.\u201d<\/p>\n<p>\u201cRather be on the \u2018front foot\u2019 with your defences against the threat attackers that are now offering ransomware-as-a-service.\u201d<\/p>\n<p>Please contact Janco Taljaard at\u00a0<a href=\"mailto:janco.taljaard@nu.co.za\" target=\"_blank\" rel=\"noopener\"><strong>janco.taljaard@nu.co.za<\/strong><\/a>\u00a0for more information.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The services industry has traditionally included sectors ranging from social assistance and health care to transportation and scientific services.<\/p>\n","protected":false},"author":57,"featured_media":519376,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10459],"tags":[12148],"class_list":["post-519364","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-news","tag-networks-unlimited"],"_links":{"self":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/519364","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/users\/57"}],"replies":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/comments?post=519364"}],"version-history":[{"count":8,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/519364\/revisions"}],"predecessor-version":[{"id":519734,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/519364\/revisions\/519734"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media\/519376"}],"wp:attachment":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media?parent=519364"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/categories?post=519364"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/tags?post=519364"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}