Ransomware crims saying 'We'll burn your data if you get a negotiator' can't be legally paid off anyway
- Reference: 1631705615
- News link: https://www.theregister.co.uk/2021/09/15/grief_corp_ransomware_negotiator_rage/
- Source link:
Grief Corp is the latest criminal crew to warn its victims with instant data destruction if it suspects a mark has engaged a mediator.
In a statement posted to its Tor-hosted blog, Grief Corp said: "We wanna play a game. If we see professional negotiator from Recovery Company™ – we will just destroy the data. Recovery Company™ as we mentioned [earlier] will get paid either way."
[2]
The news comes after a rival ransomware gang calling itself RagnarLocker said it would do something similar, prompting a spot of bandwagon-jumping among the criminal fraternity.
[3]
[4]
As Reg readers know only too well, ransomware is an extortion operation. After deploying a software payload on to a target's network to scramble all of its files, the criminals behind the ransomware demand a sizeable payment in cryptocurrency to provide a decryption utility – and to prevent sensitive corporate and/or personal data from being dumped online.
Threat analyst Brett Callow of infosec firm Emsisoft, who was quoted by RagnarLocker in its blog post demanding companies stop hiring ransomware negotiation experts, told The Register : "The fact that gangs don't want their victims to involve... [or] enlist help from negotiators or law enforcement is a solid indicator that that's exactly what they should do. Calling in [reputable help] helps organizations recover from incidents for the least amount of money."
[5]
There was something else worth knowing about Grief Corp, added Callow: The crew is under US financial sanctions, having previously rebranded itself from its US Office of Foreign Assets Control-recognised name of DoppelPaymer. Sanctions were imposed on DoppelPaymer's parent firm, Evil Corp, back in [6]December 2019 . American-linked businesses, therefore, cannot buy off these crooks without exposing themselves to further risks from regulators.
[7]Confessions of a ransomware negotiator: Well, somebody's got to talk to the criminals holding data hostage
[8]Biz tells ransomware victims it can decrypt their files... by secretly paying off the crooks and banking a fat margin
[9]EU slaps extra sanctions on Russian spy chief and APT28 malware dev over 2015 Bundestag hack
[10]Ransomware-hit law firm gets court order asking crooks not to publish the data they stole
Callow continued: "Grief has an added incentive to keep negotiators at bay. It's one of Evil Corp's many brands and Evil Corp is subject to OFAC sanctions. Negotiators know this and will advise organizations accordingly."
Earlier this month, [11]ransomware negotiator Nick Shah gave an interview to El Reg in which he suggested that most ransomware gangs' negotiating skills were quite weak. Negotiations are usually carried out through what Shah called "the help desk from hell" – that is, their equivalent of first-line customer support (many of the ransomware gangs currently attacking orgs are based in [12]ex-Soviet countries whose governments turn a blind eye to their activities).
Current UK government advice wavers between never paying off ransomware criminals and refusing to condemn cyber insurance companies whose policies will buy off criminal gangs. Paying off ransomware crooks merely fuels their twisted trade and spurs them on to do it again. Not paying helps kill their business model.
The EU (and UK by extension) has historically somewhat lacked in terms of financial sanctions on identified ransomware criminals, when compared with the US, though the bloc did [13]begin crackdowns last year .
[14]
Although a post-Brexit UK could impose its own sanctions, so far its moves have [15]largely mirrored Five Eyes (and EU) action on Russian cyber spies . ®
Get our [16]Tech Resources
[1] https://www.theregister.com/2021/09/03/how_to_be_a_ransomware/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YUIYvRbSsbNXdASzidl7VQAAAFc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YUIYvRbSsbNXdASzidl7VQAAAFc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YUIYvRbSsbNXdASzidl7VQAAAFc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YUIYvRbSsbNXdASzidl7VQAAAFc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://home.treasury.gov/news/press-releases/sm845
[7] https://www.theregister.com/2021/09/03/how_to_be_a_ransomware/
[8] https://www.theregister.com/2019/06/24/red_mosquito_rm_data_recovery_ransomware/
[9] https://www.theregister.com/2020/10/23/eu_sanctions_gru_russian_hackers/
[10] https://www.theregister.com/2021/07/06/ransomware_4_new_square_chambers/
[11] https://www.theregister.com/2021/09/03/how_to_be_a_ransomware/
[12] https://www.washingtonpost.com/world/europe/russia-ransomware-cyber-crime/2021/06/11/e159e486-c88f-11eb-8708-64991f2acf28_story.html
[13] https://www.theregister.com/2020/07/31/eu_sanctions_hackers/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YUIYvRbSsbNXdASzidl7VQAAAFc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[15] https://www.theregister.com/2020/10/23/eu_sanctions_gru_russian_hackers/
[16] https://whitepapers.theregister.com/
Ransomware is just the new kidnap gang
New? I remember getting Ransomware in the early 2000s. Instead of crypto, they wanted cash to be mailed to a certain location.
I like the US idea.
Just call the a criminal / terrorist organisation and make it an offence to pay them.
Re: I like the US idea.
Simple solutions for simple minds.
It is easy for us to say "don't pay"
but if you have been attacked then things might look very different.
Yes: there should be good backups but not everyone does. Yes: bad backups is stupid/negligent/... but it happens.
Sacking the IT director or the bean counter director who refused to fund good backups does not solve today's problem.
A requirement for companies with more than 100 employees to have to have their backups externally audited once a year might be a way forwards but is unlikely to be the silver bullet: affordable audits are never 100%.
Re: It is easy for us to say "don't pay"
Sacking the IT director or the bean counter director who refused to fund good backups does not solve today's problem.
But it goes a long way in preventing tomorrow's. Pour encourager les autres .
Re: It is easy for us to say "don't pay"
Probably the IT director acted on orders of the financial director. Sack him too?
Re: It is easy for us to say "don't pay"
Yes: there should be good backups but not everyone does. Yes: bad backups is stupid/negligent/... but it happens.
If you're that incompetent, possibly you deserve to go out of business.
Doing backups is a necessary task and cost of business, like keeping the lights on, maintaining a website, tracking your finances, and paying your employees.
Re: It is easy for us to say "don't pay"
"If you're that incompetent, possibly you deserve to go out of business."
In most companies, especially small companies, IT is not the primary product, and probably isn't even a product at all. It's a set of tools to help market/sell/manufacture/account-for whatever the company's main product is. Telling a widget manufacturer that they "deserve" to go out of business because they hired some flashy, smooth-talking pseudo-IT guy to run their systems and they subsequently got ransomed, is a bit of a stretch. There's probably 1 or 2 IT guys in the company, but hundreds of floor workers actually making widgets. All of those folks "deserve" to be out of a job because the IT guy is an idiot? Get a grip.
Re: It is easy for us to say "don't pay"
In the following tale it wasn't ransomware but, to the effect, it's the same as if it were.
In the (late) 90's I was called to "rescue" a largish occupational health company that had all of their information (I really mean everything, client info, contracts, test results, payroll) in a single 700 MB Access application. They had an hardware failure that crashed the .mdb and their most recent backup copy was over a month old. Unfortunately (for them), we were unable to restore it, we only managed to salvage parts of tables, unlinked to anything else.
They ended up losing several contracts over the issue but, hey!, they weren't in IT and didn't know any better at the time.
BUT.... do you think they learned the lesson? Well think again because they just rebuilt from the backup copy and manually re-inputted all that could be saved from the crashed file, leaving everything else as before.
I really have no idea if this was part of the reason but they are now, in fact, out of business.
Re: It is easy for us to say "don't pay"
If anyone "deserves" to be punished, it's the management that allowed the company to be put in such a position. The boots on the ground employees likely have little to no say in the direction of the IT department, even the IT staff themselves, while the upper managrment does. If the employee was not directed to do something, and something bad happens to the company because of it, it's the manager's fault. Get rid of that manager, salvage what you can, and those hundred some innocent employees hopefully get to keep their jobs.
If we see professional negotiator from Recovery Company™ – we will just destroy the data.
I think it's a bluff. It takes time, patience and resources (= investment) to catch the fish. I don't seriously believe they'll cut the line because they _think_ the catch might turn out less than what they bargained for. In fact, I expect the bad guy to start recruiting for counter-negotiatiors...
Re: If we see professional negotiator from Recovery Company™ – we will just destroy the data.
There's also the fact that there's no incentive for them to actually delete any exfiltrated data, besides a potential increase to legal woes if they get caught. Who's going to stop them extorting the same mark twice with the same data, after all?
"Oh hey we found some juicy data in your previously extorted files, so we're extorting you again! Surprise, a criminal organization lied!"
They called themselves "Evil Corp"?
Seriously? Evil Corp? Did they think they were in an Austin Powers movie or something?
Re: They called themselves "Evil Corp"?
The paperwork for sanction placed againt them was delivered to the courthouse in a very slow moving steamroller. Save the enviroment! Flatten bumpy roads! It's a win-win!
burn data ?
"Ransomware crims saying 'We'll burn your data if you get a negotiator' can't be legally paid off anyway"
Wait, they're using an OVH DC ?
Ransomware is just the new kidnap gang, but no need to actually be present, nor keep someone locked up in order to extort money.
So yes, best advice is : Don't pay them, because it just encourages them.
Downside is : If you don't have secure backups of your data, it could seriously harm or collapse your business - which is why they pay, and then pay again and again, and other businesses suffer as a result as the gangs see profit and go after more marks.
Perhaps finding out how much such ransom would be and paying that into IT for enhanced security, backups etc. would be a lot more beneficial - after all, every minute your data is encrypted and unusable is costing you money...
But preaching to the converted: We all know this. Shame so many managers/directors/investors don't.