GuidePoint Security has released new research intelligence that explores the differences between the ransomware groups we “see on TV” – the large, established, and well-resourced RaaS operations – and the smaller, ad hoc, opportunistic, or “immature” ransomware groups that operate more quietly, generally impacting less well-defended victims.
GuidePoint Security’s researchers highlight the increased risks and behaviors associated with such groups and provide two case studies of immature, high-risk groups – Phobos and DATAF LOCKER – that they observed during recent incident response efforts.
Popular images, depictions, and understanding of modern ransomware groups often focus on the largest and most established groups, maintaining media attention through high-profile attacks and sensationalist extortion tactics.
While this segment of the ransomware ecosystem exists and remains, relevant, immature ransomware groups operating on the fringe continue to harm smaller and less well-defended organizations, often without a recognizable brand or name to aid in attributing and ascribing deceitful behavior.
You can read the research here.
Related
This entry was posted on April 11, 2024 at 9:01 am and is filed under Commentary with tags GuidePoint. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Increased Risk Among Immature Threat Actors, Ransomware Operators: Research From GuidePoint Security
GuidePoint Security has released new research intelligence that explores the differences between the ransomware groups we “see on TV” – the large, established, and well-resourced RaaS operations – and the smaller, ad hoc, opportunistic, or “immature” ransomware groups that operate more quietly, generally impacting less well-defended victims.
GuidePoint Security’s researchers highlight the increased risks and behaviors associated with such groups and provide two case studies of immature, high-risk groups – Phobos and DATAF LOCKER – that they observed during recent incident response efforts.
Popular images, depictions, and understanding of modern ransomware groups often focus on the largest and most established groups, maintaining media attention through high-profile attacks and sensationalist extortion tactics.
While this segment of the ransomware ecosystem exists and remains, relevant, immature ransomware groups operating on the fringe continue to harm smaller and less well-defended organizations, often without a recognizable brand or name to aid in attributing and ascribing deceitful behavior.
You can read the research here.
Share this:
Like this:
Related
This entry was posted on April 11, 2024 at 9:01 am and is filed under Commentary with tags GuidePoint. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.