ESTsecurity (CEO Jung Jin-il), a security specialist, announced on the 13th that it blocked a total of 177,732 ransomware attacks in the first quarter of 2022 through the 'behavior-based pre-emptive ransomware blocking' feature built into its ALYac antivirus program.
According to the statistics, ransomware attacks blocked by ALYac in the first quarter totaled ▲177,732, which on a daily basis works out at ▲around 1,974 ransomware attacks blocked per day on average.
These statistics count only attacks blocked through the 'behavior-based pre-emptive ransomware blocking feature' of the free ALYac antivirus program provided to individual users, so the total number of attacks is estimated to be far higher once pattern-based attacks are included.
ESTsecurity identified the key ransomware trends of the first quarter of 2022 as ▲the Russia-Ukraine war and ransomware, ▲the still highly active VenusLocker group, ▲Magniber ransomware distributed through typosquatting and ▲continued ransomware damage at global companies.
The most notable issue of the first quarter of 2022 was ransomware attacks related to Russia's invasion of Ukraine. The war between Russia and Ukraine has caused worldwide disruption socially, economically and in many other ways, and ransomware groups are exploiting the issue too. A prime example is HermeticRansom. That ransomware was not aimed at extorting money; it was confirmed to have served as a decoy for a wiper attack intended to delete data on Ukrainian systems. Alongside this, a Ukrainian security researcher leaked the source code of Conti ransomware, in what is presumed to have been retaliation for Conti posting a notice supporting the Russian government.
The VenusLocker group also remains highly active. Distributing ransomware in Korea continuously since 2017, the group has recently kept distributing ransomware in Korea using content on résumés, copyright violations and the like. It previously distributed Makop ransomware continuously, and signs of it distributing LockBit ransomware have recently been detected as well.
Signs of Magniber ransomware being distributed through typosquatting were also found again. Typosquatting is an attack technique that redirects users to a different page when they enter a domain address incorrectly or misspell it. Magniber ransomware is being distributed to Chrome and Edge browser users through typosquatting, and the page the attacker lures them to prompts them to download an MSI file. MSI is the extension used by Windows Installer, so a user who runs the file without suspicion is infected with the ransomware.
Ransomware damage at global companies also continues. Luxury clothing brand Moncler was attacked by BlackCat (or AlphV) ransomware in December 2021 and had data leaked, with the leaked data published on the Tor dark web network in January this year. Aviation services company Swissport International was also hit by ransomware, delaying some flights, and Nvidia too was attacked, with some systems confirmed to have been affected.
An ESTsecurity ESRC representative said: "Not only are ransomware attacks increasing continuously of late, their distribution methods are also evolving in line with the social environment," adding, "With more employees working from home to prevent the spread of COVID-19, companies must make it mandatory to check the OS and software security update status of remote work terminals that connect to the internal network, and run employee security awareness training alongside it."
ESTsecurity, meanwhile, is working closely with the Korea Internet & Security Agency (KISA) on ransomware information gathering and coordinated response, in order to prevent harm to Korean users from ransomware infection.
Other ransomware newly discovered or worth noting in the first quarter of 2022, as identified by ESRC, is as follows.