Get all your news in one place.
100's of premium titles.
One app.
Start reading
TechRadar
TechRadar
Benedict Collins

New ransomware-as-a-service caters to cybercriminals with commercial expansion

Ransomware.

New evidence suggests that the popular Play ransomware is now being rented out to cybercriminals.

Known as ransomware-as-a-service (RaaS), cybercriminals can pay to use the malware itself alongside the infrastructure needed to pull off an attack.This is a relatively new phenomenon and can provide a steady stream of revenue for malicious cyber gangs.

Security firm Adlumin has been tracking various attacks across multiple industries all leveraging the Play ransomware and found striking similarities between the attacks, suggesting it is being offered in the RaaS format. The similarities between separate attacks included copied passwords in the creation of high-privilege accounts and the same folders used for malware delivery.

Pay-per-Play

In a report, Adlumin stated, “The unusual lack of even small variations between attacks suggests that they are being carried out by affiliates who have purchased the ransomware-as-a-service (RaaS) and are following step-by-step instructions from playbooks delivered with it.

“When RaaS operators advertise ransomware kits that come with everything a hacker will need, including documentation, forums, technical support, and ransom negotiation support, script kiddies will be tempted to try their luck and put their skills to use.”

RaaS has been highlighted by multiple threat intelligence organisations as a growing sector within cybercriminal enterprise, as highly organized cyber gangs rent out their infrastructure, tactics, techniques and procedures to fledgling groups or individuals looking to make some money without the necessary investments in their own architecture.

In the wake of some ransomware attacks, cybercriminals have been known to leverage stolen data by threatening to sell/release it as a means of further extorting organizations and forcing them to pay. The US, alongside a number of other leading economies, recently signed a pledge to never pay a ransom to cybercriminals again.

Via The Hacker News

More from TechRadar Pro

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.