10/07/2023
The has issued a crucial to companies operating in the , urging them to remain vigilant in the face of an emerging - Attacks.
Specifically, the FBI is warning about dual ransomware attacks, where a single target is hit by two different ransomware variants in quick succession. This trend was initially observed in July 2023, involving various combinations of ransomware variants such as , , , , , , and . These attacks result in , file exfiltration, and financial losses from ransom payments. The second ransomware attack on an already compromised system can be particularly devastating.
Some threat actors even employ two ransomware variants simultaneously, and there have been instances where brokers have sold access to multiple ransomware operations, leading to attacks occurring within hours of each other. When multiple ransomware variants are used, victims are required to pay each group separately to decrypt and recover stolen data. Additionally, they are resorting to data destruction tactics by using custom wiper tools when victims decline ransom negotiations.
Furthermore, the FBI warns that ransomware groups are increasingly using custom data theft, wiper, and tools. This trend, which was first observed in early 2022, involves malware with dormant wiper tools that activate after a predefined period, corrupting data in alternating intervals.
In response to these evolving threats, the FBI has shared recommended mitigations in their recent Private Industry Notification. These measures are designed to help network defenders counter common system and discovery techniques employed by ransomware groups and reduce the risk of compromise.
www.tectorconsulting.com