GARAGE

Heard of software as a service? Now there's a hacker equivalent

The 'ransomware as a service' model, involving clients and partners, resemble legitimate business operations

Claudia Chong
Published Mon, Sep 6, 2021 · 09:50 PM

    Singapore

    LAST month, Singapore-based payments startup Pine Labs was exposed as a victim of ransomware after hackers made away with confidential documents involving some prominent Indian banks.

    A gang called BlackMatter took responsibility for the attack. While its tactics were nothing unusual, the way it presented itself was.

    "We are a team that unites people according to one common interest - money," a description on its website read. "We provide the best service for our clients and partners compared to our competitors. We rely on honesty and transparency in our dealings with our victims."

    BlackMatter is part of a group of cybercriminals who are increasingly operating like modern-day businesses. Their model has been dubbed "ransomware as a service" (RaaS) and has helped fuel the global outbreak of large-scale cyber attacks that have implicated companies such as Accenture and Bangkok Airways.

    Clients of this service are able to outsource different aspects of a ransomware operation, lowering the barriers to initiating an attack and putting more businesses at risk.

    Ransom negotiators, for instance, are now reportedly in high demand. These players spam-call victims, threaten to publicly shame them, or disrupt their online services to harass them into paying up.

    Traditionally, hackers would steal data or lock up a company's systems. They then profit from demanding a ransom in exchange for the stolen data or to decrypt important files.

    But with more businesses going digital and increasing the pool of potential targets, these criminals are now turning to selling their services instead. The last 18 months have marked the rapid rise of RaaS models where ransomware developers lease their technology, similar to how software developers lease "software as a service" products.

    A RaaS kit may include technical support, bundled offers and user reviews, according to cybersecurity company CrowdStrike. It's a competitive market where individual players advertise their services on the Dark Web and have websites that look eerily legitimate.

    "I like the challenge of doing things where most others give up," read one advertisement seen by The Business Times. The services of the hacker, who called themselves Vladimir, included remote control of someone's mobile phone and getting personal data of high-profile individuals.

    Attacks in the cyber sphere have real-world consequences. In Germany, a patient died after a hospital's systems were disrupted by ransomware, forcing the patient to be sent to another emergency department.

    What's fuelling the success of these nefarious operations is that ransomware attacks are no longer a single-person show.

    An administrator runs the service and often validates the capabilities of operators before admitting them to the programme. Another group identifies how to gain initial access to the victim organisation.

    A ransomware operator then strikes the victim with malware, said Mark Goudie, services director for Asia-Pacific and Japan at CrowdStrike. Each player then takes a cut of the profit or operates on a fixed fee model.

    A hacker advertises their services on the Dark Web. Some have adopted an ''e-commerce model'' where buyers can simply click and make a purchase. PHOTO: CYFIRMA

    Such an organised network of crime has helped turn the ransomware economy into what experts estimate is a multibillion-dollar industry.

    "The ransomware ecosystem is a distorted mirror of corporate culture, with everything from job interviews to procedures for handling disputes," said a May 2021 article co-published by MIT Technology Review and ProPublica.

    Cyfirma chief executive Kumar Ritesh said REvil, which was responsible for the high-profile attack on meat supplier JBS, supposedly had up to a thousand individuals in its network at one point.

    CrowdStrike's observations show that RaaS gangs lease kits that range from US$40 per month to several thousand dollars per month. In contrast, the average ransomware demand was US$6.3 million over the first six months of 2021.

    "It gives these very potent weapons to people in organisations that don't really understand the damage that they're creating," said Mr Goudie.

    Ransomware's quick rise has unnerved the Cyber Security Agency of Singapore (CSA). Its chief executive David Koh worries that local businesses aren't defending themselves well against the threat.

    Tokio Marine Singapore recently fell victim to ransomware, while another attack at private eye clinic Eye & Retina Surgeons compromised the personal data and clinical information of over 73,000 patients.

    Part of the problem is that no one wants to talk about the issue. "It's just bad press. There's just no way of explaining it away," said a CEO who spoke on condition of anonymity. His company was hit by ransomware five years ago and in the past two years, he's seen at least seven of his peers affected as well.

    CSA received reports of 68 cases in the first half of 2021, already more than double the 31 cases in the first half of last year. Mr Koh thinks these cases are just the tip of the iceberg.

    A business owner, who also requested anonymity, said one of his startup clients recently found personal information of thousands of customers wiped from an e-commerce database and replaced with a ransom note. The client failed to have a maintenance contract for the database that would have improved cybersecurity defences.

    The hacker demanded a relatively small sum of 0.02 Bitcoin, equivalent to roughly S$1,400, to restore the information. It's been a week since the company paid up, with still no sign of the data.

    The general advice among cybersecurity experts, including CSA, is to not pay the ransom. Doing so would embolden criminals and make the company a soft target.

    But the situation might not always be that straightforward. Take, for instance, companies that get their intellectual property files stolen and potentially exposed to competitors.

    "The whole investment into research for five, 10 years will just turn to dust," said Cyfirma's Mr Kumar.

    Mr Kumar has also seen a case where cyber criminals trawled through data of a high net worth individual and deduced he was having an affair. They threatened to publicly expose him. "The last 30 to 50 years would have gone to dust too if that kind of information goes up," Mr Kumar said.

    Companies can protect themselves by constantly backing up their data, updating their software and having protections against phishing, said Eric Nagel, Asia-Pacific general manager at Cybereason. They should also look into endpoint security and threat hunting technologies, he added.

    With the constant evolution of cyber threats, the next generation of cybersecurity will involve using artificial intelligence to analyse massive amounts of data and search for behavioral patterns that indicate systems are compromised.

    "It's very much a game of data and visibility," said Mr Nagel.

    READ MORE:

    • Garage is BT's startup vertical. Read more news, analyses and opinions at bt.sg/garage.