The scale of ransomware threat is examined in a new report from FireEye: Ransomware’s Threat over Critical Infrastructure and Industrial Production, particularly IT and OT vulnerabilities. Since at least 2017, there has been a significant increase in public disclosures of ransomware incidents impacting industrial production and critical infrastructure organisations.
Well-known ransomware families like WannaCry, LockerGoga, MegaCortex, Ryuk, Maze, and now SNAKEHOSE, have cost victims across a variety of industry verticals many millions of dollars in ransom and collateral costs. These incidents have also resulted in significant disruptions and delays to the physical processes that enable organisations to produce and deliver goods and services.
In 2017, FireEye also observed campaigns such as NotPetya and BadRabbit, where wiper malware with worm-like capabilities was released to disrupt organisations while masquerading as ransomware. While these types of campaigns pose a threat to industrial production, the adoption of post-compromise deployment presents three major twists in the plot.
An actor’s capability to obtain financial benefits from post-compromise ransomware deployment depends on many factors, one of which is the ability to disrupt systems that are the most relevant to the core mission of the victim organisations. As a result, Ransomware expects mature actors to gradually broaden their selection from only IT and business processes, to also OT assets monitoring and controlling physical processes.
If you would like to join our community and read more articles like this then please click here.
Business cyber security cyber threats hack industry IT ransomware