The use of ransomware is on the rise. Hackers and bad actors ranging from independent amateurs to sophisticated, organized cartels are using the latest malware techniques, strong encryption and secure online payment systems to extort millions of dollars from people and organizations who just want their data back.
These attacks are hitting organizations in every sector, and the federal government is by no means immune.
Ransomware — a class of malware that locks users out of a system or restricts access to data until a ransom is paid — is not new. But a surge of malicious encryption tools and the high-profit potential have made it a go-to tactic for cyber criminals.
Moreover, unprepared victims who suffer a successful attack have little recourse other than pay up or see their data lost forever.
“It’s really profitable, there’s very little risk, it’s really easy to get the ransom — to make the payoff — and you don’t have to go resell [the data] anywhere,” said Kevin Haley, director of product management for Symantec Security Response. “It’s pure profit, it’s really easy to do, so we’re seeing everybody get involved in the game.”
While no federal agencies have admitted to suffering from a successful, large-scale ransomware attack, it’s likely only a matter of time, according to officials.
But feds have been targeted. According to figures from the Department of Homeland Security, there have been 321 incidents since June 2015 in which bad actors attempted to put ransom malware on federal systems, affecting some 29 separate agency networks.
Fortunately, tTo date, the majority of successful attempts only affected user workstations and not entire network enterprises.
“In all cases, the system was removed from the network and replaced with a new, clean system with minimal impact to the user and agency,” according to a letter from DHS in response to questions from Sen. Tom Carper, D-Del. “The department is not aware of any instances in which federal agencies paid a malicious actor to remove ransomware from a government computer.”
But just because ransomware hasn’t had a significant effect on federal networks “doesn’t mean it won’t,” Phyllis Schneck, deputy undersecretary for cybersecurity and communications at DHS’s National Protection and Programs Directorate (NPPD), told Federal Times. “And it certainly doesn’t mean it isn’t just waiting,” with malware lurking behind the scenes ready to pounce, she added.
The amount of sensitive data agencies hold and the critical nature of many of their missions make the federal government a prime target. And as ransomware becomes more widespread and the business model improves, it’s only a matter of time before an agency is faced with a difficult decision: pay the criminals or lose the data.
A real trend and a significant threat
“Our data does show that ransomware is more prevalent in this year’s data set than in years past,” said Mark Spitler, lead author of Verizon’s annual Data Breach Investigations Report. “That is certainly not just something that is being sensationalized — it’s something that’s out there. It’s a very, very real threat.”
The FBI agrees, logging more than 2,500 complaints reported to the Internet Crime Complaint Center (IC3) in 2015. As of April, the IC3 has received more than 800 reports of ransomware already in 2016, with victims paying a combined $3.7 million to get access restored.
The numbers are on the rise but ransomware is not a new phenomenon. Improved tactics for embedding the malware in a system, ensuring secure, anonymous payments and the use of unbreakable encryption has morphed the threat into a prime money-making venture for criminals.
The first piece of malware to be called “ransomware” — known as Gpcoder — was identified in 2005.
“There were two problems with this: One, the encryption wasn’t very good, so you could break it,” Haley said. Further, the hackers asked victims to send the money through Western Union. When the criminals showed up to get their ransom, police were there waiting for them.
“It never really took off,” Haley explained. “This guy didn’t make much money and it kind of disappeared.”
For a time.
Researchers began to see a resurgence in ransomware around 2012 as secure online payment methods like Bitcoin emerged.
Then in 2013, “Really good encryption comes along,” Haley said, making it easier for the adversary to get strong encryption tools and making it almost impossible for victims to unlock their systems after a successful attack.
According to Symantec’s research, some 39 percent of ransomware victims are paying to have their systems unlocked. Per DHS, feds have yet to succumb to this extortion.
Variation on an old crime
And that’s what ransomware is: extortion.
“Ransomware really is a variation on an old physical crime,” according to Brett Leatherman, assistant section chief with the FBI Cyber Division. “In the past, we’d see extortions and ransoms happen as a result of criminal actors holding sensitive information they may have grabbed or illicit information they may have grabbed from somebody. In this case, cyber is a vehicle to commit the underlying offense.”
While extortion and malware aren’t new by themselves, the combination of the two crimes has created a threat unlike any other.
“Ransomware is unique,” Leatherman said. “We talk in many malware campaigns about the remediation. But there’s very little remediation” in response to a ransomware attack. “The remediation is wiping your servers and restoring from legitimate backups.”
Once ransomware is successfully loaded onto a system, there are really only two options: wipe and restore using backups — if they exist — or pay the ransom.
Leatherman said the FBI does not advocate paying the ransom — despite some comments made last year — as it only emboldens the criminals and doesn’t guarantee a victim will actually get access to their data.
“We recognize that business decisions are made based on the needs of the business,” he said. “But many times if you pay a ransom you might be funding illicit activities by criminal groups and terrorist groups, as well.”
The only real defense is to be prepared, according to Schneck.
Backup to basics
All the experts Federal Times spoke with agreed having secure, up-to-date backups is the best strategy, as organizations can just wipe the infected system and replace it without having to pay. Beyond that, ransomware should be treated like every other cyber threat.
“This is nothing more than malware,” Schneck said. “It’s malware with quite a feature at the other end when it executes, but it’s malware.”
From that perspective, tactics like basic cyber hygiene, strong firewalls, privileged access management and continuous monitoring go a long way to preventing a successful attack.
For federal agencies, NPPD programs like Einstein watching the perimeter and Continuous Diagnostics and Mitigation (CDM) monitoring what’s going on inside the network will prevent infection from known threats and some emerging attack vectors.
As the threat evolves, Schneck is more concerned about how ransomware attacks will affect critical infrastructure and the growing Internet of Things.
“My worry is not so much what we see right now but what are the things in our actual physical infrastructure — the water and the lights and our emergency services — that are at risk and what about our appliances?” she said. “What are the things that you’ll come downstairs in the morning and find yourself locked out of until you pay? What are the infrastructures that will stop working until one pays?”
Leatherman agreed.
“What it comes down to is the information you hold,” he said. “If that information keeps you in business, if it’s sensitive in nature and if it’s something that can be encrypted and if they deny the availability of it to you, they know there’s probably a propensity for you to pay that ransom. They really don’t discriminate on who you are, they discriminate based on the data you hold. And that includes almost any company and any sector.”




