SANS Ransomware Summit 2023
A RaaS-ipe for Disaster: The Evolving Ransomware-as-a-Service (RaaS) Space, as Told Through Tools, Techniques, and Procedures (TTPs)
Speaker: Jono Davis, Senior Analyst, PwC Global Threat Intelligence Team
The Ransomware-as-a-Service (RaaS) environment has evolved markedly since the introduction of the double extortion method; a technique that alone rocked the threat intelligence and wider cybersecurity industry as it prepared to contend with not just the encryption of data, but the exfiltration of sensitive information. The double extortion technique has found such success that RaaS programs, as well as private ransomware operations, have relied heavily on it for their success. We have even observed a recent shift in resources, with operators seemingly spending fewer resources on their ransomware binaries, and more time on the surrounding phases that increase the chances of a successful attack; such as initial access, credential access, lateral movement, and exfiltration. In this talk, PwC analysts present a look at the evolving RaaS space, analyzing the techniques that appear to have become more homogenous across phases of the individual operations; from initial access to credential access to lateral movement, through to encryption. We also focus on the codebases of the most prolific RaaS binaries – where the threat actor thought process is most visible – in order to highlight how the malware development has seemingly taken a back seat in the overall ransomware operation. The purpose of this talk is to provide defenders with practical solutions to combatting the ransomware threat by highlighting techniques that have become almost “industry standard” through both malware and endpoint detection rules. We also take this opportunity to offer a higher level, but still evidenced-based, overview of the behaviors of these ransomware actors within an ever-changing environment; appropriate for the C-Suite or Board level.
View upcoming Summits: http://www.sans.org/u/DuS