news.mlab.sh
Back to the feed
threat-intel

Stronger Security Drives Ransomware Groups to Recruit From Within

High
Summary

Ransomware groups are increasingly relying on malicious insiders to gain access to organizations, driven by improved defenses making it harder to breach systems directly. As companies bolster their security, attackers are now targeting employees – both disgruntled and willing – to bypass traditional defenses and gain direct access to valuable data and systems. The cost of these insider-assisted attacks is significantly higher than traditional breaches, and the trend is expected to continue as ransomware-as-a-service groups seek new methods for initial access. Organizations need a comprehensive approach, combining cybersecurity with HR and procurement practices, to mitigate these risks.

Ransomware groups are increasingly relying on malicious insiders to gain access to organizations, driven by improved defenses making it harder to breach systems directly. As companies bolster their security, attackers are now targeting employees – both disgruntled and willing – to bypass traditional defenses and gain direct access to valuable data and systems. The cost of these insider-assisted attacks is significantly higher than traditional breaches, and the trend is expected to continue as ransomware-as-a-service groups seek new methods for initial access. Organizations need a comprehensive approach, combining cybersecurity with HR and procurement practices, to mitigate these risks.

Insider-assisted ransomware attacks are becoming more prevalent, with groups offering payments to employees for access to VPNs, remote desktop protocols, and email credentials. The cost of these attacks is substantial, with an average of $4.9 million per event for malicious insiders with elevated privileges, and a total annual cost of $19.5 million per organization. This rise is linked to layoffs, which create a pool of potentially disgruntled employees, and the increasing sophistication of ransomware-as-a-service groups, who are now actively recruiting insiders to facilitate their operations.

Several cases illustrate this trend. Christopher Dobbins, for example, was sentenced for hacking his former employer and sabotaging its electronic shipping records, costing the company over $200,000 and delaying shipments of personal protective equipment during the COVID-19 pandemic. Flashpoint found that over 75% of threat actor posts on the Dark Web originated from insiders advertising their access to malicious third parties. In another instance, an alleged member of the Medusa ransomware-as-a-service gang offered a BBC correspondent 25% of any ransom payment in exchange for access to his PC.

Organizations need to move beyond simply strengthening their defenses. Jamie Levy, senior director of adversary tactics at Huntress, emphasizes that a healthy reporting culture is crucial, encouraging employees to report mistakes without fear of reprisal. Tammy Harper, a certified Dark Web investigator, notes that insiders may be paid up to $15,000 for providing access, or receive a percentage of ransom payments.

To combat this growing threat, Rawlins, senior adviser and director of security at NCC Group, recommends a holistic approach involving people, identity, supplier, and incident response disciplines. This includes implementing least-privilege access, regular recertification, and robust offboarding procedures – ensuring accounts are disabled immediately upon departure. Levy also stresses the importance of making privilege expensive and temporary, particularly protecting backups, hypervisors, and endpoint detection and response consoles. Remote monitoring and management abuse has jumped 277% year-over-year, highlighting the need to closely monitor and control remote access.

Ultimately, organizations must proactively address the human element of their security posture, recognizing that a disgruntled or compromised employee can be a far more effective entry point than any technical vulnerability.

Read the full article at Dark Reading