Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - 2018 Ransomware Trends
Articles

2018 Ransomware Trends

ISBuzz TeamBy ISBuzz TeamMarch 7, 2018Updated:May 2, 20256 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Warning Issued About BianLian Ransomware Attacks By CISA & FBI
Warning Issued About BianLian Ransomware Attacks By CISA & FBI
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot
  1. Opportunistic Ransomware is generally on the decline

Ransomware worked well for so long because bad guys made money, and made money quickly from ransomware campaigns. Starting in 2017 and continuing to 2018 there has a been a steady decline in ransomware campaigns. The reasons for that are twofold, but interconnected:

  • Exploit Kits (EK) have virtually disappeared. The EK market has always been volatile, but as one EK faded away there was generally another one to take its place. That has not been the case. As the big EKs of 2016/2017, Sundown, Neutrino, and RIG, have fallen off, no new EKs have stepped in to fill the void. This has occurred, in part, because there are fewer 0-day browser exploits to use in these EKs, rendering them less effective. Of course, this is somewhat of a chicken and an egg problem. The most popular 0-day exploits in years past were those targeting Adobe Flash. However, Adobe Flash installations are at an all-time low ), so there is a much smaller attack surface, meaning even if there were a large number of Adobe Flash 0-Day exploits, there would be fewer victims to target. With fewer active EKs there are fewer delivery mechanisms for ransomware, forcing attackers to rely more heavily on phishing campaigns, which are becoming less effective.
  • The EKs that are still around, such as RIG, have switched to delivering cryptocurrency miners rather than ransomware ).

In general, there has been a move away from ransomware to cryptocurrency miners, largely for the same reasons that lead to the rise of ransomware in the first place. At this point,  cryptocurrency miners are more profitable than ransomware. They are also more difficult to defend against. Organizations have gotten better at securing their networks to prevent successful ransomware attacks, but blocking cryptocurrency miners is a much bigger challenge. Until the security community catches up, cryptocurrency miners will continue to be profitable for attack groups.

  1. There will still be some industries that are targeted

 Some industries are still being targeted and will continue to be targeted by ransomware campaigns. Industries like healthcare, and more specifically hospitals, have continued to be lucrative targets by attackers. Figure 1 shows that hospital attacks have not abated recently, instead they continue to move along at a steady pace and continue to be effective.

This is part of the trend mentioned last year that has continued: “Ransomware will become just another tool in the hacker utility belt.” While overall cyber criminal based ransomware attacks are on the decline in 2018, ransomware is still used on a case by case basis rather than large scale ransomware campaigns.

Figure 1: Ransomware attacks on hospitals continues to rise

  1. Boutique Ransomware campaigns will continue

 While large-scale ransomware declined toward the end of 2017 the balkanization of ransomware continues to increase. There are ransomware campaigns happening, but they are reaching smaller audiences. At the end of January 2017 Recorded Future was tracking 635 different ransomware variants, while at the end of February 2018 we are tracking 1105 different variants. That is a 74% increase in the number of variants we are tracking in just 13 months.

2015, 2016, and early 2017 saw the emergence of a few, widely distributed, ransomware campaigns like Locky and Cerber. While these ransomware variants are still being distributed, albeit on a much smaller scale than in previous years, there has been a growth in other ransomware families that pop up for a few weeks or months and then disappear.

These new smaller campaigns are generally distributed to hundreds of thousands of potential victims, rather than tens of millions at a time. This trend will continue in 2018 as malware developers look to continue to add ransomware to newly discovered attacks techniques.

  1. The line between cyber criminals and nation state attacks will continue to blur

 In 2017 I wrote “Similarly, there will not be a Mirai-style botnet installing ransomware.” I was partially correct. While there was not a Mirai-style botnet installing ransomware, 2017 did see the rise of the so-called ransomworm, with WannaCry, NotPetya and Bad Rabbit leading the way. These worms were interesting for two reasons:

  1. The sheer amount of damage and destruction they were able to cause in a very short period of time.
  1. They demonstrate the interplay between cyber criminal organizations and nation state actors.

WannaCry and NotPetya were not criminal campaigns, they were at best distraction campaigns and at worst destruction campaigns and both appear to have been launched by nation state actors using what had traditionally been cyber criminal tools. But, even in nation state style attacks, ransomware can be an effective tool in disrupting operations. While the nation state actors may not care about collecting the ransom, they certainly care that their targets are unable to access their files and that their workflow is disrupted for days, weeks, or in some cases months.

On the other hand, Bad Rabbit appears to have been carried out by a cyber criminal, using techniques learned studying the WannaCry and NotPetya campaigns. This doesn’t just apply to ransomware, it is happening across all types of cyber attacks. Cyber criminals are learning from nation state actors while nation state actors are learning from, and using the tools of, traditional cyber criminal activity. This trend will continue to grow in 2018 and beyond.

  1. Ransomware-as-a-Service (RaaS) will continue to be popular

The one area of ransomware that appears poised to remain popular is RaaS. RaaS allows attackers to rent ransomware infrastructure rather than develop it themselves. The attacker generally pays an upfront fee and the author of the RaaS keeps a small percentage of each ransom paid. Generally, the rentee is allowed to set the ransom price and build the attack campaign.

RaaS is attractive to less experienced attackers because it allows them to get into the ransomware game quickly and painlessly and, they think, they can start making money quickly.

But RaaS appeals to more experienced hackers as well because it guarantees them a revenue stream, selling the RaaS to inexperienced newcomers. In fact, the three most popular ransomware strains of 2018, GandCrab, Saturn and Data Keeper have all been RaaS ransomware families (see Figure 2). Because there are always people looking to make a quick buck and there are always those who are willing to take their money it seems like RaaS will continue to thrive through at least 2018.

Figure 2: Mentions of GandCrab, Saturn and Data Keeper Ransomware Families

Conclusion

While it won’t be as big of a menace in 2018 as it was in 2016 and 2017, ransomware will continue to be a threat to both individuals and organizations. Some industries, such as healthcare, will continue to be heavily targeted by ransomware campaigns, but most industries should expect to see a drop in ransomware, overall. That being said, some of the tools developed by the actors behind ransomware, including fileless malware and encryption techniques, will continue to be used by those actors, as well as others, in different types of attacks. Don’t be surprised if there are more state-sponsored disruption campaigns in 2018 using tools originally designed for ransomware attacks.

[su_box title=”About Allan Liska” style=”noise” box_color=”#336588″][short_info id=’104126′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}