Understanding Economic Motivation behind Ransom Attacks Fyodor Yarochkin Trend Micro Researcher | HITCON Review Board Member
Agenda • Evolution of Ransom Attacks • Where is the Profit? What are the Margins? • Conclusions
How it started
Social Engineering: FAKE AV
It is all about monetization “For financial needs of any level of dirtiness - SIM + A/C + Passport Copy”
Ransom done wrong give me 13439849038409238 dollars
Ransom done right (scalability is important) 1 USD 1 USD 1 USD 1 USD 1 USD 1 USD 1 USD 1 USD 1 USD 1 USD 1 USD 1 USD 1 USD 1 USD 1 USD 1 USD 1 USD 1 USD
old days August 2010: 300 ruble per unlock. 500M annual income, over 1M victims
Getting paid was a challenge
probing international market
2013 - BITCOIN AGE EVERYONE IS A TARGET! https://blockchain.info/address/ 18iEz617DoDp8CNQUyyrjCcC7XCGDf5SVb
Ransom4bc nsightful commenter:
biz is good
crypto locker Prices - March - 2017
340USD is the price for source code, Watson !!
only 30k Only 600USD Does not work in ex-USSR countries
builder sale - only $300
crypto locker builder
builder - nice UI :)
⽔氵⽔氵⽔氵 :)
http://www.ksl.com/?sid=43357235
Also redis, mongo, ES
Armada Collective
Booters Arbor Network Report on DDoS: less than 60 min 90% less than 1 Gbps 84%
booters are cheap Essyn.Club Stresser exotic-power.pw Stresser ipstressing.xyz Stresser blunter.black demonic.io Fruitstresser.net ipstressing.ga
vDos Stresser
related research work
Business is good, learn and replicate Kadyrovtsi Stealth Ravens “fake”Armada Collective Use fame of MIRAI to make it sound scary
copy cats Easy to Reproduce, bet on scare-tactics, better win ratios than in CASINO!
Copycats are prevalent
Extortion by Business Peers DDoS and sell a Security Product = PROOFFIITT !;)
It is all about money Bitcoin makes it easy! Anonymous, Global Everything can be “for RANSOM” NOW where are we heading to ..?!
also for mobile https://www.youtube.com/watch?v=W_B7uXNTNVg
Mobile (control panel)
browser locker
600 MLN of Rubles :) http://news.tut.by/society/483103.html
Everything “SMART”gets pwn3d already:)
So why Ransom is “HOT”? • Accessibility and Affordability of Ready-to-Use Technologies • Low entry barrier - Tools come with UI, support. All you need is to learn how to send ransom emails :) • High value and acceptable cost for a victim • Endless scalability and ease of reproduction for ransom cases PROFFFFFIT!!!
Questions? fyodor_yarochkin@trendmicro.com
Recommend
More recommend