Ransomware has become a popular weapon in the hands of malicious actors who try to harm governments, businesses and individuals on a daily basis. In such cases, the ransomware victim may suffer economic losses either by paying the ransom demanded or by paying the cost of recovering from the loss, if they do not comply with the attacker’s demands. In an incident in 2019, Baltimore, Maryland suffered a lockout and recovery is expected to pay US $18,2 million (ca. €15,4 million), although the city refused to pay the ransom. 1 With the growing number of incidents growing, it is evident that becoming a victim is not an ‘if’ but rather a ‘when’ hypothesis. However, in the majority of countries’ fights against ransomware, several challenges need to be addressed, such as the lack of coordination and collaboration between agencies and authorities, and the lack of legislation, that clearly criminalises ransomware attacks. Although cyber insurance policies exist since early 2000 2 , ransomware attacks are one of the main reasons for the increased interest in this type of insurance during the last 5 years. In some of the 2019 incidents 7 , the ransom or the costs of recovery was covered by such contracts. Unfortunately, if potential ransomware targets are known to be insured, the attackers assume that they will most probably be paid. Another downside for the victim is that insurance providers are paying the ransom in advance to mitigate the damage and to keep the victim’s reputation intact. However, such compliance by paying ransoms encourages the hacker community and ensures neither the victim’s recovery nor their reputation. 3


__Findings €10,1_ billion estimated to be paid in ransoms during 2019 The amount of paid ransoms was US €3,3 billion more than in 2018. 365%_ increase in detections in businesses in 2019 Ransomware detection in machines in business environments increased compared with the fists half of 2018. 22 66%_ of healthcare organisations experienced an attack More than 66% of healthcare organisations experienced a ransomware attack in 2019. 23 45%_ of attacked organisations paid the ransom This is the percentage of organisations attacked in 2019 that paid the ransom and half of them still lost their data. 37 28%_ of security incidents were attributed to malware Ransomware was the second most common functionality following malware C2 and was related to one-third (28%) of security incidents. 32


_ Ransomware aims higher

The Q1 and Q2 2019, ransomware attacks were fewer than those recorded in the same period during the previous 3 years. However, these ransomware attacks focused on high-profile targets. Throughout 2018, the deployment of Remote Access Trojan (RAT), downloaders and backdoors was noted but, during that year, that malware  remained idle. 9,10 It is now concluded that this software provided the attackers with the intelligence to identify vulnerable high-profile targets, willing to pay higher amounts of ransom. Following this vein, in the reporting year, ransomware expanded to other sectors beyond the healthcare industry, targeting industrial and manufacturing firms. Recently, the LockerGoga ransomware family was used to damage systems that control the physical equipment in production plants. 11

_ Cyber insurance more popular

Cyber insurance policies in 2019 represented an US $8 billion (ca. €6,7 billion) market in the United States alone. Although such products exist since the Y2K or Millennium bug, in recent years they have become more appealing to governmental organisations, cities, healthcare organisations and several other potential high-risk ransomware targets. The SamSam attack in Atlanta, Georgia and the Lake City, Florida, incident were covered by such policies. 16 As the ransom demands increase, cyber-insurance policies are becoming increasingly necessary for organisations and companies. However, common sense suggests that the victims must avoid caving in to demands, if possible. When the ransom demands are met not only is the attacker encouraged to repeat the act but the victim may also not recover as in several cases the attacker do not keep their end of the bargain.


Several successful ransomware families such as SamSam, BitPaymer and CrySiS target RDP servers to initiate an attack. 20 Unfortunately, many organisations still use RDP instead of the more secure Virtual Private Network (VPN) for remote access. The problems with the RDP is that it suffers from vulnerabilities that can be exploited and the RDP service may rely on internet-facing servers which are easily accessed. More than 800.000 systems with RDP services have been reported to be unpatched and vulnerable; among them, systems in the IP range of the Microsoft Azure data centre. 51 Although Microsoft assured the public that these systems belonged to a third-party, an issue arises regarding cloud service providers’ security. _Open Remote Desktop Protocol (RDP) is a high risk

_ The most wanted

LOCKERGOGA_ was first reported in January 2019 in an attack on the French engineering consultancy company, Altran Technologies. 40 Its IT networks and all the applications went down and the company’s operations in several countries were affected. LockerGoga is dropped and executed by the PsExec tool, which is a light-weight telnet replacement, able to pass some security checks as semi-valid software. 11 Once installed, the user accounts in the targeted system are modified and the system is forcibly logged-off. In addition, the tool files are self-renamed and self- relocated, and, as a result they become almost impossible to be located. In later versions of LockerGoga, the lock-down is so tight that the victims are not even able to see the ransomware note or the instructions for recovery, even if the demands are met. Only a few anti-malware and anti-virus products are able to detect and defend systems against LockerGoga and a specific decryptor does not exist. 10 Other than Altran Technologies, NorskHydro and two United States-based chemical companies, Hexion and Momentive were targeted by LockerGogain 2019. 41 For the NorskHydro attack alone, the cost of the damage was estimated at US $50 million (ca. €42 million). 21 KATYUSHA_ is a ransomware trojan first used in October 2018. It encrypts the victim’s files, deletes shadow copies and delivers attachments by e- mail. Katyusha uses the EternalBlueand DoublePulsar exploits to spread. 45 Unfortunately, no tools or decryptors are yet available for defence. JIGSAW_ not only encrypts the victim’s files, but it also deletes them if the demands are not met within the, most commonly, 24 hour deadline given. Furthermore, if the victim attempts something like shutting down their computer, the deletion rate increases. It is not an accident that this ransomware was named after a horror movie character. 45 However, security companies constantly releases updates for an efficient Jigsaw decryptor. 46


PEWCRYPT_ was created at the beginning of 2019 and, unlike most ransomware its only goal is to force people to subscribe to the PewDiePie YouTuber channel. PewDiePie was in a popularity competition with an Indian Bollywood channel, T-Series and his fans decided to use PewCrypt to increase their idol’s chances of winning. PewCrypt is a typical ransomware spread by spam e-mails and malicious online advertisements. It was created in the Java programming language. In March 2019, the author himself released a decryption tool. 47 RYUK_ first appeared in August 2018 and was assumed to be associated with North Korean hacking groups. Soon enough, the Ryuk authors were proved to be the same group that became known for using the Hermes ransomware while also stealing its code. Ryuk’s main characteristics are its use of military algorithms and its targeted attacks on big enterprises. Moreover, most of its victims are asked to pay the ransom in Bitcoins. 45 DHARMA_ is a crypto virus that first appeared in 2016 but new versions are still being released. Dharma not only encrypts the victim’s files but also deletes any shadow copies. In 2019, it was spread by contaminated files with popular, harmful or legitimate extensions such as ‘.gif’, ‘.AUF’, ‘.USA’, ‘.xwx’, ‘.best’ and ‘.heets’. In September 2019, a security researcher released the Rakhnidecryptor 42 to help Dharma victims decrypt their files. GANDCRAB_ was used for the first time in January 2018 and infected more than 50,000 systems in less than a month, becoming one of the most popular ransomwares of 2018. 43 It exploits Microsoft Office macros, VBScript and PowerShell to attack undetected. 45 GandCrab is similar to Cerber, it is based on the ransomware-as-a-service (RaaS) model and allows the developers and the criminals to share profit. A team created by Europol, the Romanian police, the General Prosecutor’s Office and Bitdefender managed to produce a decryptortool 44 after hacking the GandCrab servers. The operators of GandCrab announced their retirement in Q2 2019 after collecting more than US $2 billion in ransom payments. However, the Sodinokibi ransomware, which is observed in small campaigns, is alleged to be GandCrab’s successor. 10



_ The most wanted

REVIL or SODINOKIBI or SODIN_ first appeared in a web attack on the Italian WinRAR tool in June 2019. It is also suspected to be involved in three MSP attacks and a fourth one against the American company PerCSoft, the clientele of which is mainly from the healthcare sector. 48 Sodinokibi seems to be a product of the well-known cyber-espionage group FruityArmor, which has been active since 2016. Sodinokibi has affected several countries worldwide. Taiwan has suffered 17,56% of all recorded Sodinokibi attacks so far, making it Sodinokibi’s most targeted country. In Europe, the most targeted countries are Germany (8,05%), Italy (5,12%) and Spain (4,88%). Sodinokibi is distributed by a RaaS model and encrypts the files needed for an attack to take place in a per-system manner. The attackers embed a ‘skeleton key’ within their code allowing them to remotely decrypt files, regardless of the original encryption. 49 However, if a computer has Russian, Armenian, Syrian or certain other keyboard layouts it is no possible for Sodinokibi’s to encrypt it, a fact probably pointing to the origin of the authors. 50 SAMSAM_ continues to target critical infrastructure globally for a fifth consecutive year. SamSam attacks mainly focus on hospitals, healthcare companies and governmental organisations to ensure fast payment of big ransoms. It exploits vulnerabilities of the Remote Desktop Protocol (RDP). To date the group responsible for the distributing SamSam has raised more than US $6 million (ca. €5 million) in ransom payments and has cost the victims more than US $30 million (ca. €25,4 million). 45 From the 2018 attack against on the city of Atlanta alone the damage and recovery costs amounted US $17 million (ca. €14,4 million). 43


“The sophistication of threat capabilities increased in 2019, with many adversaries using exploits, credential stealing and multi- stage attacks.” in ETL 2020



_ Targeted sectors

NATION-STATES ARE STILL IN THE SPOTLIGHT_ In 2018, ransomware was used to target nation-state organisations as a money making tool. This trend continued in 2019, whereby nations or nation groups obfuscated their identity by using the very same tools created by other groups or nation-state actors. This manipulation of tools allows the attacker’s origin to remain hidden and their nation to avoid any diplomatic consequences, especially when the target is a governmental or a state organisation. In 2019, several attacks against governmental or state organisations took place such as the one in which the Californian city of Lodi 4 was asked to pay US $400.000 (ca. €340.000) in ransom to be released from a lock out of the Police Department’s phone lines, the Public Works’ emergency line, the City Hall’s numbers and the city’s payment data and financial systems. The city refused to comply and recovered from the attack by using backups. The Texas Department of Information Resources reported a coordinated ransomware attack on 23 small governmental organisations in August 2019. 5 The cost for the Texas county was estimated to be US $3,25 million (ca. €2,75 million). Baltimore suffered a RobbinHood attack causing a damage costing US $18,2 million (ca. €15,4 million), while the Lake City in Florida endured a Ryuk attack causing a loss of US $460.000 (ca. €389.768). The city of New Bedford in Massachusetts was also hit by ransomware attack in July 20196 and demanded the payment of a ransom of US $5,3 million (ca. €4,4 million). The city refused to pay the ransom and instead spent US $1 million to recover from the attack. 7


EDUCATIONAL INSTITUTIONS ARE JOINING THE PARTY_ During 2019, we observed a shift in attacks towards educational institutions. According to a report released by the security company Emsisoft, 1.051 schools and colleges were victims of 62 ransomware incidents. In 2018, the incidents affecting educational institutions were only 11. The report declares that American schools were the second more common victims after the local municipalities. 8 THE HEALTH SECTOR CONTINUOUS TO SUFFER_ Healthcare organisations were the favourite target of ransomware attackers during all of the previous years, and this trend also continued in 2019. Californian providers Wood Ranch Medical were hit during summer, and the electronic medical records of the company were completely destroyed (including the backups) as a result of its refusal to pay the ransom. The incident forced Wood Ranch Medical to announce that it would cease to operate by the end of the year. 12 In April 2019, the exact same exact sequence of events befell another medical provider, Michigan Brookside ENT and Hearing Centre 13 , which was also forced to shut down. Furthermore, in Australia, two hospital groups were attacked: the GippslandHealth Alliance and the South West Alliance of Rural Health. The result was that hospitals in several cities including Warrnambool, Colac, Geelong, Warragul, Sale, and Bairnsdale could not fulfil normal patient procedures, as their systems went offline to limit the exposure. 14 In this sector, the data loss is equally damaging to the financial loss. For instance, more than 300.000 patients’ Protected Health Information was leaked as a result of a ransomware attack placed in June 2019 against the Premier Family Medical group in Utah. 15 MSP ARE DOWN_ Numerous industries rely on managed service providers (MSP) and cloud service providers (CSP) to host sensitive information, that is essential to their operations. They also rely on them for the integrity of the data and the prevention of unauthorized access to them. 17 However, the GandCrab and Sodin ransomwares target vulnerabilities in the MSPs that expose their infrastructure and the data they host and, eventually, they allow the ransomware attack to spread to the entire MSP’s clientele. The Webroot2FA, a common MSP tool, embeds such vulnerabilities and has been used in several cases during 2019. 18 This year, several MSPs were attacked within a period of three months only, such as PM Consultants, CloudJumper, Datto, PercSoft, TSM Consulting Services Inc. and IT By Design. 19


Attack vectors

_ How

A new ransomware called Sodinokibi exploits the recently announced CVE- 2019-2725 Oracle WebLogic Server’s vulnerability to gain remote code execution abilities. The victim is infected with no action taken. Official patches have also been released for the Oracle WebLogic Server versions and 51 The same attack exploits the CVE-2018-8453 vulnerability to gain more (elevate) user privileges, terminate blacklisted processes, delete blacklisted files and exfiltrate host information. 48 Another vulnerability, the CVE-2019-0708, is also used for planting ransomware. It allows unauthorized connection via Microsoft’s remote desktop protocol (RDP). In May 2019, Microsoft released patches for the current operating system (OS) versions as well as for those versions that are not supported any more. 51



















__ Incidents

 The Baltimore County incident 1  Alabama hospitals attack 7  Lodi California City incident 4  Texas (Texas Department of Information Resources) incident 5  Lake City (Florida) Ryuk attack 7  New Belford (Massachusetts) incident 6  Ransomware attacks on > 500 schools and universities 8  Wood Ranch Medical (California) case 12  Michigan Brookside ENT and Hearing Centre incident 13  Gippsland Health Alliance and the South West Alliance of Rural Health (Australia) incidents 14  Premier Family Medical group (Utah) incident 15  MSPs PM Consultants, CloudJumper, Datto, PercSoft, TSM Consulting Services Inc. and IT By Design incidents 19

 Microsoft Azure data centre incident 51  Altran Technologies LockerGoga attack 40  Norsk Hydro LockerGoga attack 7  Hexion and the Momentive LockerGoga attacks 41  Albany IT incident 60  Jackson County (Georgia) incident 61  Riviera Beach (Florida) incident 62  New Orleans incident 63  Danish hearing aid manufacturer Demant attack 64



_Proposed actions

 Maintain reliable backups that follow the 3-2-1 rule (i.e. maintain at least three copies, in two different formats, keeping one of those copies off-site). 5  Invest in a cyber insurance policy covering ransomware attack damages. 21  Use network segmentation, data encryption, access control, and policy enforcement to ensure minimum exposure of data.

 Use methods such as monitoring to quickly identify infections.

 Monitor access to and status of the public infrastructure used.

 Create a security operation centre (SOC) staffed by skilled security personnel within every organisation or company.

 Use appropriate and updated tools for ransomware prevention.

 Define exactly and implement a minimum set of user data access rights to minimise the impact of attacks (i.e. fewer rights, less data encrypted).

 Implement robust vulnerability and patch management.

 Implement content filtering to filter out unwanted attachments, e- mails with malicious content, spam and unwanted network traffic.  Install end-point protection by means of anti-virus programs but also by blocking execution of files (e.g. block execution in Temp folder).

 Use policies to control external devices and port accessibility.

 Use whitelisting to prevent unknown executables from being executed at endpoints.  Invest in raising users’ awareness of ransomware especially with regard to secure browsing behaviour.



Significant progress has been achieved by EUROPOL  and 163 partners with the ‘No more ransom project’  . The portal has added 28 tools in 2019 and can now decrypt 140 different types of ransomware infections. 65 A handful of ransomware decryptors have been develop and many others updated. Examples are listed below.



Aurora 52 , Muhstik 53 , Ryuk 54


Rakhni, Aura, Autoit, Pletor, Rotor, Lamer, Lortok, Democry, TeslaCrypt, Chimera, Crysis, Jaff, Dharma, Cryakl, Yatron, FortuneCrypt, 55, 56

Kaspersky Lab

Europol, Romanian Police and GPO, Bitfender

GandCrab 44

Jigsaw 46


Mira 57


Nemty 58


PewCrypt 47

PewCrypt author



