Posted inSecurity

Ransomware variants almost double in six months: report

The ransomware threat continues to adapt with more variants enabled by Ransomware-as-a-Service (RaaS).

Derek Manky, Chief Security Strategist & VP Global Threat Intelligence, FortiGuard Labs
Derek Manky, Chief Security Strategist & VP Global Threat Intelligence, FortiGuard Labs

Fortinet announced the latest semiannual FortiGuard Labs Global Threat Landscape Report.

“Cyber adversaries are advancing their playbooks to thwart defense and scale their criminal affiliate networks,” says Derek Manky, Chief Security Strategist & VP Global Threat Intelligence, FortiGuard Labs. “They are using aggressive execution strategies such as extortion or wiping data as well as focusing on reconnaissance tactics pre-attack to ensure better return on threat investment. To combat advanced and sophisticated attacks, organisations need integrated security solutions that can ingest real-time threat intelligence, detect threat patterns, and correlate massive amounts of data to detect anomalies and automatically initiate a coordinated response across hybrid networks.”

Highlights of the 1H 2022 report follow:

  • The ransomware threat continues to adapt with more variants enabled by Ransomware-as-a-Service (RaaS).
  • Work-from-anywhere (WFA) endpoints remain targets for cyber adversaries to gain access to corporate networks. Operational technology (OT) and information technology (IT) environments are both attractive targets as cyber adversaries search for opportunities in the growing attack surface and IT/OT convergence.
  • Destructive threat trends continue to evolve, as evidenced by the spread of wiper malware as part of adversary toolkits.
  • Cyber adversaries are embracing more reconnaissance and defense evasion techniques to increase precision and destructive weaponisation across the cyber-attack chain.

Ransomware remains a top threat and cyber adversaries continue to invest significant resources into new attack techniques. In the past six months, FortiGuard Labs has seen a total of 10,666 ransomware variants, compared to just 5,400 in the previous six-month period. That is nearly 100 percent growth in ransomware variants in half a year. RaaS, with its popularity on the dark web, continues to fuel an industry of criminals forcing organisations to consider ransomware settlements. To protect against ransomware, organisations, regardless of industry or size, need a proactive approach. Real-time visibility, protection, and remediation coupled with zero-trust network access (ZTNA) and advanced endpoint detection and response (EDR) are critical.