back to article Breaking the economy of trust: How busts affect malware gangs

Some of the world's most notorious ransomware and malware-as-a-service (RaaS/MaaS) operators have shut up shop in the past 12 months thanks to international law enforcement efforts, but just because household names like Conti, LockBit, and ALPHV/BlackCat are on the ropes, it doesn't mean we're free from the threat of commodity …

  1. Doctor Syntax Silver badge

    We need to see a few affiliates getting busted soon, otherwise this will become the new normal and they'll start getting active again.

    1. Eclectic Man Silver badge

      Not every one uses affiliates

      "An unnamed Fortune 50 corporation paid a stonking $75 million to a ransomware gang to stop it leaking terabytes of stolen data.

      The underworld outfit, which calls itself Dark Angels, doesn't go for the shotgun approach a lot of other malware-slinging teams use, in which multiple victims are infected at a time indiscriminately in hope that at least some pay up. Nor does Dark Angels appear to use affiliates or outside help to get into networks."

      https://www.theregister.com/2024/08/02/dark_angels_ransomware/

  2. Dr Paul Taylor

    terminology

    Please explain what part "affiliates" and "operatives" play.

  3. Phil O'Sophical Silver badge

    I wonder if there's any scope for an OS to use technology (I hesitate to say AI) to detect when ransomeware is running? Perhaps spot large read/encrypt/write patterns and pop up a warning? It shouldn't be impossible to spot unusual patterns like that, the security services do it all the time. It would mean they wouldn't have to look for specific malware signatures, so would be less dependent on having frequently updated signature data.

    1. An_Old_Dog Silver badge

      Detecting Executing Ransomware

      I think there's no effective way for a computer to correctly decide whether a piece of data is encrypted or not.

      There might be some patterns in CPU use+memory access+file access which could indicate ransomware is being executed.

  4. M.V. Lipvig Silver badge
    Trollface

    "managers grinding employees"

    I feel like this would have a different meaning in a criminal organization than in a legit place.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like