ESTsecurity (CEO Jung Jin-il), a security specialist, announced on the 8th that it blocked a total of 148,689 ransomware attacks in the second quarter of 2022 through the 'behavior-based pre-emptive ransomware blocking' feature built into its ALYac antivirus program.
According to Security Response Center (ESRC) statistics, ransomware attacks blocked by ALYac in the second quarter totaled ▲148,689, which on a 30-day basis works out at ▲around 1,652 ransomware attacks blocked per day on average. That is about 29,000 fewer than in the first quarter, but the company assessed the ransomware threat as still high.
These statistics count only attacks blocked through the 'behavior-based ransomware blocking feature' of the free ALYac product provided to individual users, so the total number of attacks would be far higher if pattern (signature) based detections were included.
Behavior-based ransomware blocking counts among ALYac users have shown a stark difference since June, turning to a markedly downward trend. Pattern-based detection figures show little change, however, so a range of possibilities — including a temporary lull caused by variant attacks — should be left open, and the situation watched over a longer period through the third quarter.
ESTsecurity identified the key ransomware trends of the second quarter of 2022 as ▲the prevalence of Korea-tailored Makop and LockBit ransomware distributed by the VenusLocker group through emails impersonating résumés and copyright violation notices, ▲distribution of Magniber ransomware through typosquatting techniques, and ▲wiper attacks disguised as ransomware related to Russia's invasion of Ukraine.
The ransomware distribution group known as VenusLocker has been active in Korea for a long time. It has recently been distributing NSIS-based variants of Makop or LockBit ransomware, and ESRC is continuously tracking the group. It is also not ruling out the possibility that a third threat actor is imitating the vectors VenusLocker used in the past, and is conducting further investigation into this.
The group is currently maintaining its ransomware threat in cunning ways that exploit users' work needs and psychological anxiety. Typical examples include posing as sending an attachment containing a résumé, or using claims that the recipient has violated the copyright of an image file.
Magniber ransomware was also rampant. It uses the so-called 'typosquatting' attack technique, in which mistyping a website address leads to a malicious site with similar English spelling. This quarter many users were deceived by this ransomware disguised as a Windows update installer and infected with no defense.
In addition, with the war continuing after Russia's invasion of Ukraine, anonymous cyber groups declared which country they support and launched cyberattacks against the other side. A Chaos ransomware variant found in May infects a user's computer and changes file extensions to 'fuckazov', where azov is understood to refer to Ukraine's Azov Battalion.
New ransomware also appeared: WannaFriendMe, which uses the .Ryuk extension and is understood to be close to a variant of Chaos ransomware. What is unusual about this ransomware is that instead of bitcoin or Ethereum it sells its decryption tool (Ryuk Decrypter) through the Roblox game store and induces victims to pay the ransom in Robux coins. The related posting has since been deleted.
Next, a good deal of ransomware was found targeting ESXi, the platform of the VMware ESXi virtualization platform widely used by companies. Black Basta ransomware, found in April 2022, initially targeted Windows systems, but a Linux variant found subsequently was specially designed to target only ESXi servers. With variants such as Cheerscrypt — a variant of Cheers ransomware targeting only ESXi servers — also being found, ransomware targeting ESXi servers is expected to keep increasing.
ESRC Director Moon Jong-hyun said: "Ransomware is being deployed through varied means beyond traditional email, including typosquatting and combination with APT attacks; although the statistics showed a lull during June, it remains one of the leading cyber threats in existence and vigilance must never be relaxed," adding, "In particular, web servers in operation should always be kept on the latest version, and constant effort must go into security management so that servers do not fall victim to ransomware attacks through file upload vulnerabilities or webshell installation." He added: "Regular data backups and employee security awareness training are needed to prepare for known, similar threats."
ESTsecurity, meanwhile, is working closely with the Korea Internet & Security Agency (KISA) on ransomware information gathering and coordinated response, in order to prevent harm to Korean users from ransomware infection.