[ad_1]
Funds raised by ransomware attacks fell to $456.8 million in 2022 from a high of $765.6 million in 2021, according to a new report from analytics firm Chainalysis.
Crypto-related ransomware attacks have seen a sharp drop in success rate over the past 12 months.
Crypto-ransomware activity
The graph below shows the rise and fall of funds acquired through ransomware attacks over the past 6 years. A dramatic increase was seen in 2020 as stolen funds reached $765 million, and 2021 saw similar amounts stolen by bad actors.
Source: Chain Analysis
Although the Chainalysis report acknowledges that “the true totals are much higher” because it is likely that there are addresses belonging to ransomware attackers that have not yet been identified, the drop indicates that victims are becoming aware of these attacks. Accordingly, Chainalysis has issued a statement supporting this sentiment.
“[Ransomware payments falling] doesn’t mean attacks are down… We believe much of the decline is due to victim organizations increasingly refusing to pay ransomware attackers.
Ransomware strains explode
Although payments to remove ransomware have dropped dramatically, the number of ransomware strains has exploded in 2022. A strain is a type of ransomware with common variants: Royal, Ragnar, Quantum, Play, Hive, and Lockbit.
Fortinet, a leading cybersecurity hardware and software company, reported over 10,000 unique strains active throughout 2022.
Strains have a decreasing lifespan as malicious actors continue to vary attack vectors to optimize the volume of stolen funds. For example, in 2012, strains lasted 3,907 days, while in 2022 the average duration was only 70 days. Consequently, cybersecurity solutions have to deal with an increasing number of active constraints in their defense strategy.
Ransomware funds
Funds acquired through ransomware attacks are laundered through several routes. The majority of funds are still sent to popular centralized exchanges. However, P2P exchanges, a popular solution for ransomware attackers in 2018, now represent only a tiny percentage of the overall volume.
After centralized exchanges, a persistent method of money laundering uses darknet markets designated as “illicit” in the chain analysis table below. Finally, mixing services are the second most important part, allowing attackers to “wash” crypto with little recourse from global authorities.
Source: ChainalysisThe investigation of on-chain data
Chainalysis used on-chain data to identify “affiliate” marketplaces for ransomware, in which third parties receive a “small, fixed portion of the product” in a ransomware-as-a-service model.
“We can think of this as the gig economy, but for ransomware. A rideshare driver might have their Uber, Lyft, and Oja apps open at the same time, creating the illusion of three separate drivers on the road, but in reality , it’s the same car.
On-chain data has allowed companies like Chainalysis to trace bad actors across the blockchain and eventually identify the next attack vector. For example, Conti, a popular ransomware strain, was disbanded in May 2022. Yet, on-chain data revealed that Conti-connected wallets are now switching to other strains such as Royal, Quantum, and Ragnar.
Ransomware attackers “have repurposed wallets for multiple attacks launched nominally under other constraints”, making tracing activity relatively basic.
Drop in ransomware payments
The number of successful ransomware attacks has decreased due to better understanding of the landscape, improved security measures, and better chain investigation capabilities. As a result, victims refuse to pay abusers, as many are connected to OFAC-sanctioned parties.
In 2019, only 24% of victims refused to pay, while in 2022 the percentage rose to 59%. Paying a ransomware bounty to a party on OFAC’s sanctions list might now be “legally riskier.” Allan Lisk, intelligence analyst at Recorded Future, told Chainalysis;
With the threat of penalties looming, there is the additional threat of legal consequences for payment [ransomware attackers.]
The consequences of non-payment of ransomware demands can often be devastating for victims, who often lose access to essential data. However, as the illicit industry becomes less financially viable, the hope is that the number of attacks will also decrease, thus reducing the number of victims.
Either way, the role of cryptocurrency in ransomware attacks is clear. It is a method to steal hundreds of millions of dollars worth of crypto every year. However, that doesn’t mean there isn’t more loss for traditional financial assets, many of which are not traceable via blockchain.
|
Sources 2/ https://news.google.com/__i/rss/rd/articles/CBMiQ2h0dHBzOi8vY3J5cHRvc2xhdGUuY29tL2NyeXB0by1yYW5zb213YXJlLXBheW1lbnRzLWZhbGwtNDAtaW4tMjAyMi_SAUlodHRwczovL2NyeXB0b3NsYXRlLmNvbS9jcnlwdG8tcmFuc29td2FyZS1wYXltZW50cy1mYWxsLTQwLWluLTIwMjIvP2FtcD0x?oc=5 The mention sources can contact us to remove/changing this article |
[ad_2]