News: 1648036872

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Lockbit wins ransomware speed test, encrypts 25,000 files per minute

(2022/03/23)


Ransomware moves more quickly than most organizations can respond. Though knowing they have a specific limited window should help inform where to put their defenses, according to security data shop Splunk.

The vendor's research team Surge today published [1]research on how long it takes 10 of the big ransomware families including Lockbit, Conti, and REvil to encrypt 100,000 files. While the criminal gangs' speeds varied, Surge found the median ransomware variant can encrypt nearly 100,000 files totaling 53.93GB in 42 minutes and 52 seconds.

Also: Lockbit was the fastest, and 86 percent faster than the median. The fastest Lockbit sample encrypted just under 25,000 files per minute.

[2]

However, the research is more than just an interesting read on ransomware families' encryption speeds, according to Ryan Kovar, who leads the Splunk Surge team. Security teams can use this knowledge to improve their defenses, he told The Register .

[3]

[4]

Focusing on ransomware mitigation and response doesn't work because most encryption speeds are too fast, anywhere from four minutes to three hours, he said.

"This reactive approach is really around a lack of knowledge of how ransomware works," Kovar said. "What we wanted to do is see if we could provide the evidence for people to start looking left of boom."

[5]

Investing in tools that focus on prevention and earlier detection provide more bang for their buck, he added. This includes the basics like better patching and conducting an asset inventory, as well as using multi-factor authentication and tools that look for attackers on the network before they deploy ransomware binaries.

"There's a lot of value in having detections that show that ransomware is executed, especially on giant networks," Kovar continued.

"But if you have $100, and you can start moving your detections left and finding things before they encrypt, whether that be ransomware in flight or focusing on the tools that the ransomware operators use to get in the network and move laterally, there's a lot of value there."

[6]

In addition to publishing the research, Surge will also release the data on bots.splunk.com so that security teams can review it.

[7]Microsoft investigates Lapsus$'s boasts of Bing, Cortana code heist

[8]AvosLocker group is targeting US critical infrastructure, FBI says

[9]Exotic Lily is a business-like access broker for ransomware gangs

[10]CISOs face 'perfect storm' of ransomware and state-supported cybercrime

To determine how quickly ransomware encrypts, the researchers selected 10 ransomware families with 10 separate binaries from each family. They then created an Amazon Web Services virtual private cloud for each family and executed all of the samples against four hosts: two running the operating system Windows 10 and the other two running Windows Server 2019. All of the performance telemetry from the endpoint hosts was then sent to a central Splunk instance for analysis.

Surge selected the 10 ransomware families, sourced from VirusTotal, based on their prevalence over the past two years. The families, listed from fastest to slowest are: LockBit, Babuk, Avaddon, Ryuk, REvil, BlackMatter, Darkside, Conti, Maze and Mespinoza.

LockBit's median encryption time remained the fastest, five minutes and 50 seconds, consistently across the different hardware types. "That was really surprising," Kovar said.

However, this lined up with previous research about LockBit that found the criminal group only encrypts 4KB of each file, thus breaking the data, before moving on to the next file. For comparison: other ransomware families encrypt the entire file, which obviously takes longer.

Mespinoza was the slowest with a median duration of almost two hours.

"It's kind of like a car: if someone cuts the gas line or flattens a car and turns it into a tube, either way you can't drive. But it's a lot faster just to cut the gas line," Kovar said. "And that's kind of how LockBit ransomware works."

This also supports LockBit's claim of the "fastest ransomware" on its Tor website.

"So seeing that difference on the same files on the same systems being executed by the different ransomware family, and seeing that they're not all created equal was a fascinating outcome," Kovar said.

In addition to releasing this data for other researchers to analyze, Surge has future ransomware topics it wants to explore in upcoming research. According to the report:

"We hope to evaluate the patterns that ransomware exhibits when encrypting files, ransomware worming behavior, how to cluster similar ransomware binaries based on fuzzy hashing algorithms, and future analysis of ransomware family attribution over time." ®

Get our [11]Tech Resources



[1] https://www.splunk.com/en_us/blog/security/ransomware-encrypts-nearly-100-000-files-in-under-45-minutes.html

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YjtSQsJ0vDo6Z7sO5rXkkwAAAM8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YjtSQsJ0vDo6Z7sO5rXkkwAAAM8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YjtSQsJ0vDo6Z7sO5rXkkwAAAM8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YjtSQsJ0vDo6Z7sO5rXkkwAAAM8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YjtSQsJ0vDo6Z7sO5rXkkwAAAM8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/03/21/microsoft_lapsus_breach_probe/

[8] https://www.theregister.com/2022/03/21/avoslocker-ransomware-critical-infrastructure-fbi/

[9] https://www.theregister.com/2022/03/18/exotic_lily_iab_google/

[10] https://www.theregister.com/2022/03/18/ciso_security_storm/

[11] https://whitepapers.theregister.com/



CommonBloke

Honest question, how feasible is it to create a script that frequently scans the running processes and kills anything that's running file encryption? Put simply, detect any process running file encryption and immediately kill it.

I mean, I understand that if whoever's attacking managed to get root access, you're 100% fcked. But when it's a user's fault for running a compromised program, this could stop the problem before much harm is done.

mootpoint

I think the problem with this approach would be identifying that the process is running encryption. I'd imagine these would be custom written rather than using any identifiable system processes.

Zippy´s Sausage Factory

The first thought in my head was to detect anything reading and writing files continually. The problem there is that reading files continually is going to raise a false positive on (for example) an antivirus scan, while continually writing files is going to hit other things like encrypting disks and compressing files. And a way to mark that process as being safe to do what it's doing is going to be able to be commandeered by ransomware anyway.

Anonymous Coward

There are products which monitor files for changes, multiple files being changed concurrently or in quick succession etc to help alert for this sort of thing.

While those are good, decent backups online/offline, well configured RBAC and a layered approach to security are arguably better.

Ultimately many would simply not stop an attack quick enough so it's best to prevent.

Encryption is a legit process

Anonymous Coward

Encryption is a legit process and a vital part of many software solutions, so shutting down all file encryption processes isn't exactly a feasible option

Kudos to the coder

Danny 2

We might not agree with their aims, but being the fastest is admirable coding. I remember spending nights to strip excess machine code. Lockbit - evil, da, but efficient!

[Leni Riefenstahl's cinematography might seem cliched today in the age of Trump/Putin rallies but recall she was innovative]

Go to a movie tonight. Darkness becomes you.