• Home
  • Live Rates
  • Privacy Policy
  • Shop
  • Terms of Service
Friday, May 1, 2026
  • Home
  • Crypto News
  • Bitcoin
  • Ethereum
  • NFT
  • DeFi
  • Blockchain
  • Metaverse
  • Altcoin
  • Tether
  • Solana
    • Dogecoin
  • Live Rates
  • Shop
No Result
View All Result
XXL24
Ledger - Crypto Beginners Pack
  • Home
  • Crypto News
  • Bitcoin
  • Ethereum
  • NFT
  • DeFi
  • Blockchain
  • Metaverse
  • Altcoin
  • Tether
  • Solana
    • Dogecoin
  • Live Rates
  • Shop
No Result
View All Result
XXL24
No Result
View All Result

What the blockchain tells us about the big business of ransomware

November 18, 2023
in Blockchain
0

Above: Illustration by Seamartini/DepositPhotos.

Shiva Bissessar and Javed Samuel of Pinaka Consulting Limited evaluate the blockchain-cryptocurrency payment regime that fuels ransomware payments. Republished with their permission. Pinaka Consulting is an Information Security based consultancy with specialization in digital currency, blockchain and Central Bank Digital Currency (CBDC).

What do the following entities have in common; ANSA McAL, Massy Group, Beacon Insurance, Attorney General’s Office Trinidad and Tobago and Telecommunications Services of Trinidad and Tobago (TSTT)? Since 2020, they’ve all fallen victim to cyber incident which resulted in impact to their service delivery. At least three of these entities have confirmed their incident was ransomware related.

In the January 2023 paper, “An Anatomy Of Crypto-Enabled Cybercrimes”, Cong et al, provides key insights into such attacks and cite sources which estimate the global damages from ransomware attacks will reach 30B USD by 2023 (https://wp.lancs.ac.uk/finec2023/files/2023/01/FEC-2023-017-Daniel-Rabetti.pdf). We use this and other sources coupled with our own insights in utilizing a commercial blockchain analytics tool from Elliptic to present a ransomware primer and insights into the economic activity associated with such attacks.

Stages of attack

The groups that carry out ransomware attacks follow a set pattern of behaviours, hence knowing their identity would indicate their methods in various stages of an attack. This would also reveal, for example, the types of tools they use to, gain initial access into the external network and then to the internal network, laterally move around in the internal network, escalate privileges within the internal network, scan internal network infrastructure and exfiltrate data.

Once these stages are executed the attacker encrypts the victims files using a key known only to them, making these files effectively useless as they can no longer be read by the victim’s systems. The attackers then attempt to extort value from the victim in return for access to a tool which can be used to decrypt the files and them useful again. Having had operations incapacitated by the loss of access to critical files the victim is faced with the choice of paying the ransom or attempting to restore their information systems from uninfected backups.

The threat of leaking data

Cong et al, notes that since 2019 a new trend of double extortion is in play where the attacker may hold additional leverage over the victim via threats to leak unencrypted files onto the dark web. At a minimum, this would be a source of embarrassment and reputational damage to the victim should the security breach become known to the public via such a leak. Data privacy of employees, clients and supply chain vendors may all be at risk should such a public exposure of data take place.

We know exactly what this looks like in the wake of the recent incident at TSTT which was carried out by the RansomEXX group where there was open public discussion of the contents of the data dump with Personal Identifiable Information (PII) of clients of the victim being exposed. The authors would like to emphasize that responsible disclosure from professionals who handle and report on such data is expected, such that victims and their stakeholders are not further aggrieved by details of their data being openly discussed in public fora. Methods to obfuscate PII of victims should be employed in reporting such incidents.

Ransom demand and possible payment

Payment is demanded in crypto currency, such as Bitcoin, given that it is easily transferable across the Internet and avoids cross-border currency challenges. Negotiations may be involved where an incident response team is hired by the victim to lend expertise and attempt to buy time and lower the ransom amount being demanded. The decision to pay is up to the victim; however, sanctions lists may play a part in the decision making process. In the case of the ransomware group Conti, after publicly declaring their allegiance to Russia in 2022, post invasion of Ukraine, potential payments to Conti took on an illicit nature given Russia’s sanctioned status. Eventually, Conti had to close up shop, but affiliates of the group are suspected to still be operating.

Blockchain Analytics In Ransomware

Once the payment is fulfilled the victim should receive decryption tools which they can use to decrypt their encrypted files; however this is not guaranteed. From the leaks which eventually follow ransomware attacks, we can infer that not all victims pay. When payment does occur the possibility exists to follow the crypto currency trail to wallets associated with the ransomware group and their affiliates.

The FBI was able to utilize blockchain analytics as part of its investigation to trace the 75 Bitcoin which was paid to Darkside in 2021 and eventually recovered 63.7 Bitcoin or 2.3M USD. This payment was related to the Colonial Pipeline attack which resulted the halting of 5500 miles of pipeline operations ultimately negatively affecting consumers on the eastern seaboard and causing a state of emergency to be declared in more than 17 US states. 45% of pipeline operation in the US was affected.

REvil/Sodinokibi

In 2020, the ransomware group REvil/Sodinokibi evaded security measures employed at ANSA McAL affecting operations in both Trinidad and Tobago and Barbados. Using a commercial blockchain analytics tool from Elliptic we can see a cluster of wallet addresses on the Bitcoin network associated with REvil/Sodinokibi, which reveals activity going back to 2019 when the group was formed.

Elliptic tool showing USD$14M of inflows and outflows to the REvil group since 2019

The value attributed to this particular cluster of wallets shows inflows of 14M USD and outflows of 13.9M USD from first transaction in June 2019 to the latest transaction in June 2021. Cong et al, attributes 282 victims to the REvil/Sodinokibi group over the period May 2020 to June 2021. They further estimate that the total USD value received by this group, for the period 2021 to 2022, places them fourth overall in terms of ransomware groups receiving such value. For the same period, the Conti group is number one, estimated to have received 50.9M USD.

If we look at some of the illicit activity identified within the Elliptic tool attributable to REvil/Sodinokibi we can highlight an 11M USD transaction from an unknown source which also had a simultaneous but much smaller 6.4K USD transaction with Conti.

On a global scale, ransomware actors are seen a serious threat to operations which rely on the Internet. In November 2021, an international law enforcement effort, carried out by 17 countries and including INTERPOL, called Operation GoldDust, resulted in the take down of REvil/Sodinokibi ransomware group and its infrastructure. Almost simultaneously, the US Department of Justice issued a 10M USD reward for information leading to the capture of leaders of REvil/Sodinokibi.

Conclusion

While seemingly defunct now, we should be concerned that the fourth largest ransomware group for 2021 to 2022 executed an attack on a large Caribbean conglomerate. The increasing number cyber incidents that we are seeing on larger entities should lead us to be apprehensive over what may be taking place at small and medium enterprises. The most recent attack by RansomEXX on TSTT is also cause for trepidation as according to TrendMicro, this group is known to specifically target its victims; evidence of this pre-planning being the victim’s names found hardcoded in binaries during post attack forensics.

These concerns must be recognized by corporate entities as they prepare their response to the increasing risk of cyber incident. Having a dedicated Information Security function within your organisation which can pay attention to not just technology, but the people and process dimensions as well, is a requirement. Awareness must be built from the ground all the way up to the C-Suite and board members as the initial access into a network can be a phishing email.

In the wake of the Colonial Pipeline incident an executive order was issued in the US demanding greater attention to national cybersecurity. Would these threats be recognised locally at the national level given these attacks can cripple critical infrastructure?

Should this be our Colonial Pipeline moment?


What the blockchain tells us about…
November 17, 2023
Kent Western appointed TSTT CEO (ag), Lisa Agard “departs”
Kent Western appointed TSTT CEO (ag),…
November 14, 2023
PriceSmart issues statement on data breach
PriceSmart issues statement on data breach
November 14, 2023
Taran Rampersad:  Are websites increasing cybersecurity vulnerabilities?
Taran Rampersad: Are websites increasing cybersecurity…
November 13, 2023
TSTT’s dark night of the soul
TSTT’s dark night of the soul
November 13, 2023
Courts responds to notice of data breach
Courts responds to notice of data…
November 12, 2023
TSTT’s week of evasion and half-truths
TSTT’s week of evasion and half-truths
November 12, 2023
ShopCourts, Pricesmart online data breached
ShopCourts, Pricesmart online data breached
November 12, 2023
TSTT CEO issues statement on company data breach
TSTT CEO issues statement on company…
November 12, 2023
TTCSIRT on response to TSTT data breach
TTCSIRT on response to TSTT data…
November 8, 2023
Parasram: Nothing to be done about data exposure
Parasram: Nothing to be done about…
November 6, 2023
Updated: Are you in the TSTT data dump? Find out here…
Updated: Are you in the TSTT…
November 6, 2023
50 Things I learned about the RansomEXX group
50 Things I learned about the…
November 5, 2023

This news is republished from another source.


Previous Post

Decentraland (MANA) Hosts Immersive Musical Metaverse Experience

Next Post

3 métricas que los traders de DeFi pueden usar en el próximo mercado alcista

Next Post

3 métricas que los traders de DeFi pueden usar en el próximo mercado alcista

Name Price
Kinza Babylon Staked BTC
Kinza Babylon Staked BTC (KBTC)
$83,270.00
Steakhouse EURCV Morpho Vault
Steakhouse EURCV Morpho Vault (STEAKEURCV)
$0.000000
Eureka Bridged PAX Gold (Terra)
Eureka Bridged PAX Gold (Terra) (PAXG)
$4,182.54
Vested XOR
Vested XOR (VXOR)
$3,404.23
ICPanda DAO
ICPanda DAO (PANDA)
$0.003106
TruFin Staked APT
TruFin Staked APT (TRUAPT)
$8.02
kpk ETH Prime
kpk ETH Prime (KPK ETH PRIME)
$2,036.25
ApeSwap
ApeSwap (BANANA)
$0.000000
bitcoin
Bitcoin (BTC)
$77,246.00
ethereum
Ethereum (ETH)
$2,287.58

Dogecoin

Will Dogecoin Recover or Dive Below $0.1? 5thScape Set to Dominate 2024! %

July 15, 2024

Investors Shift to Clandeno (CLD) ICO Amid Global Market Uncertainty as Dogecoin (DOGE) and Polkadot (DOT) Drop

July 14, 2024

Dogecoin (DOGE) and Solana (SOL) Lead Crypto Market Recovery as Bitcoin (BTC) Reclaims $60K

July 14, 2024

DOGECOIN PRICE ANALYSIS & PREDICTION (July 13) – Doge Trades Calmly At $0.1, Can It Gain Strength From This Key Level? 

July 14, 2024

Analyst Who Bought Solana At $0.11 And Sold For $250 Says Buy ETFSwap (ETFS) At $0.01831 Now Instead Of Dogecoin (DOGE)

July 13, 2024

Leap Ahead with MOONHOP Presale As 4900% Growth Projection Dwarfs Notcoin & Dogecoin’s Declines

July 13, 2024

Metaverse

Ciz Verse Announces the Launch of Its Bitcoin-Powered Metaverse

July 15, 2024

Mil.k partners AirAsia rewards and The Sandbox to engage consumers in the metaverse

July 15, 2024

Lado Okhotnikov Reveals The Secrets Of The Realistic Meta Force Metaverse

July 14, 2024

GensoKishi Metaverse (MV) Price Down 18.4% This Week

July 14, 2024

The 3 Smartest Metaverse Stocks to Buy With $500 Right Now

July 14, 2024

Top 3 Metaverse Tokens For 3X Surge This Bull Rally!

July 13, 2024

transcosmos launches Roblox metaverse services with EbuAction

July 13, 2024
No Result
View All Result

Pages

  • Home
  • Live Rates
  • Privacy Policy
  • Shop
  • Terms of Service

Tether

Zimbabwe ZiG Hits Record Low as Interest in Tether (USDT) Rises

July 15, 2024

Solana

How Solana flipped Ethereum, Bitcoin in NFT Adoption

July 15, 2024

Solana Reaches Market Capitalization of $67.27 Billion (SOL)

July 14, 2024

Advertisement

  • Shop
  • Privacy Policy
  • Terms of Service

© 2023 XXL24


No Result
View All Result
  • Home
  • Crypto News
  • Bitcoin
  • Ethereum
  • NFT
  • DeFi
  • Blockchain
  • Metaverse
  • Altcoin
  • Tether
  • Solana
    • Dogecoin
  • Live Rates
  • Shop

© 2023 XXL24


  • Kinza Babylon Staked BTCKinza Babylon Staked BTC(KBTC)$83,270.000.00%
  • Steakhouse EURCV Morpho VaultSteakhouse EURCV Morpho Vault(STEAKEURCV)$0.000000-100.00%
  • Eureka Bridged PAX Gold (Terra)Eureka Bridged PAX Gold (Terra)(PAXG)$4,182.540.23%
  • Vested XORVested XOR(VXOR)$3,404.231,000.00%
  • ICPanda DAOICPanda DAO(PANDA)$0.003106-39.39%
  • TruFin Staked APTTruFin Staked APT(TRUAPT)$8.020.00%
  • kpk ETH Primekpk ETH Prime(KPK ETH PRIME)$2,036.250.01%
  • ApeSwapApeSwap(BANANA)$0.0000000.00%
  • bitcoinBitcoin(BTC)$77,246.001.88%
  • ethereumEthereum(ETH)$2,287.581.82%
  • kpk ETH Yieldkpk ETH Yield(KPK ETH YIELD)$2,031.88-0.04%
  • tetherTether(USDT)$1.000.00%
  • JPool Staked SOLJPool Staked SOL(JSOL)$170.103.95%
  • rippleXRP(XRP)$1.380.53%
  • binancecoinBNB(BNB)$619.980.43%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$84.141.51%
  • tronTRON(TRX)$0.3262350.76%
  • staked-etherLido Staked Ether(STETH)$2,262.76-3.72%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.25%
  • dogecoinDogecoin(DOGE)$0.1095303.26%
  • Gaj FinanceGaj Finance(GAJ)$0.0059271.46%
  • WhiteBIT CoinWhiteBIT Coin(WBT)$57.927.44%
  • Content BitcoinContent Bitcoin(CTB)$24.482.55%
  • USD OneUSD One(USD1)$1.000.11%
  • USDSUSDS(USDS)$1.000.02%
  • Wrapped stETHWrapped stETH(WSTETH)$2,773.89-3.48%
  • UGOLD Inc.UGOLD Inc.(UGOLD)$3,042.460.08%
  • HyperliquidHyperliquid(HYPE)$40.411.93%
  • leo-tokenLEO Token(LEO)$10.31-0.56%
  • ParkcoinParkcoin(KPK)$1.101.76%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$76,102.00-3.36%
  • cardanoCardano(ADA)$0.2493701.19%
  • Binance Bridged USDT (BNB Smart Chain)Binance Bridged USDT (BNB Smart Chain)(BSC-USD)$1.00-0.07%
  • bitcoin-cashBitcoin Cash(BCH)$443.98-0.52%
  • Wrapped Beacon ETHWrapped Beacon ETH(WBETH)$2,462.35-3.82%
  • Wrapped eETHWrapped eETH(WEETH)$2,462.97-3.62%
  • moneroMonero(XMR)$381.541.22%
  • Yay StakeStone EtherYay StakeStone Ether(YAYSTONE)$2,671.07-2.84%
  • chainlinkChainlink(LINK)$9.181.05%
  • Coinbase Wrapped BTCCoinbase Wrapped BTC(CBBTC)$76,319.00-3.28%
  • PengPeng(PENG)$0.60-13.59%
  • CantonCanton(CC)$0.150657-1.29%
  • zcashZcash(ZEC)$347.126.06%
  • stellarStellar(XLM)$0.1599010.20%
  • wethWETH(WETH)$2,264.05-3.78%
  • MurasakiMurasaki(MURA)$4.32-12.46%
  • USD1USD1(USD1)$1.00-0.03%
  • sUSDSsUSDS(SUSDS)$1.090.12%
  • USDT0USDT0(USDT0)$1.00-0.11%