Trend Micro report takes a deep dive into one of the most successful threat groups in modern
HONG KONG SAR – Media OutReach – 9 June 2021 – (;), a global cybersecurity leader, today released a case study of the Nefilim ransomware group, providing insight into the inner-workings of modern ransomware attacks. The report gives valuable insight into how ransomware groups have evolved, operate under the radar and how advanced threat detection and response platforms can help stop them.
The approach of modern ransomware families makes detection and response significantly more difficult for already stretched SOC and IT security teams. This matters not only to the bottom line and corporate reputation, but also the wellbeing of SOC teams themselves.
To read the report “Modern Ransomware’s Double Extortion Tactics and How to Protect Enterprises Against Them”: https://www.trendmicro.com/vinfo/hk/security/news/cybercrime-and-digital-threats/modern-ransomwares-double-extortion-tactics-and-how-to-protect-enterprises-against-them.
“Modern ransomware attacks are highly targeted, adaptable and stealthy – using proven approaches perfected by APT groups in the past. By stealing data and locking key systems, groups like Nefilim look to extort highly profitable global organizations,” said Bob McArdle, director of cybercrime research for Trend Micro. “Our latest report is a must-read for anyone in the industry who wants to understand this fast-growing underground economy inside-out, and how solutions like Trend Micro Vision One can help them hit back.”
Of the 16 ransomware groups studied from March 2020 to January 2021, Conti, Doppelpaymer, Egregor and REvil led the way in terms of number of victims exposed—and Cl0p had the most stolen data hosted online at 5TB.
However, with its ruthless focus on organizations posting more than $1 billion in revenue, Nefilim extorted the highest median revenue.
As the report reveals, a Nefilim attack typically involves the following stages:
- Initial access that exploits weak credentials on exposed RDP services or other externally facing HTTP services.
- Once inside, legitimate admin tools are used for lateral movement to find valuable systems for data theft and encryption.
- A “call home” system is set up with Cobalt Strike and protocols that can pass through firewalls, like HTTP, HTTPS and DNS.
- Bulletproof hosting services are used for C&C servers.
- Data is exfiltrated and published on TOR-protected websites later to extort victim. Nefilim published around 2TB of data last year.
- Ransomware payload is launched manually once enough data has been exfiltrated.
Trend Micro has previously warned of the widespread use of legitimate tools such as AdFind, Cobalt Strike, Mimikatz, Process Hacker, PsExec, and MegaSync, to help ransomware attackers achieve their end goal while staying hidden. This can make it challenging for different SOC analysts looking at event logs from different parts of the environment to see the bigger picture and spot attacks.
Trend Micro Vision One monitors and correlates suspicious behavior across multiple layers—endpoints, emails, servers, and cloud workloads—to ensure there’s no hiding space for threat actors. This makes for faster incident response times, and teams can often stop attacks before they’ve had a chance to make a serious impact on the organization.
About Trend Micro
Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information. Fueled by decades of security expertise, global threat research, and continuous innovation, Trend Micro’s cybersecurity platform protects hundreds of thousands of organizations and millions of individuals across clouds, networks, devices, and endpoints. As a leader in cloud and enterprise cybersecurity, the platform delivers a powerful range of advanced threat defense techniques optimized for environments like AWS, Microsoft, and Google, and central visibility for better, faster detection and response. With 7,000 employees across 65 countries, Trend Micro enables organizations to simplify and secure their connected world. www.trendmicro.com.hk
#TrendMicro
Services
Stakeholder mapping, analysis, engagement and communication needs to be detailed to avoid business losses or even worse, a crisis. How can you do this effectively to prevent failure? ...
Data-driven business decisions have never been as crucial, especially in this era. MGBF leverages off, technology, experience and market presence to aid businesses in making accurate decisions. ...
MGBF provides comprehensive strategic advice and results-focused solutions to solve clients' problems in business-government relations so they can focus on their core business. ...
A critical business challenge is meeting the right decision-makers and potential buyers through the best channel and platform. How will you improve your business competency? ...
Upcoming Events
In this episode of 'A Working Lunch with Nordin', MGBF's Nordin Abdullah and regional commentator Eddin Khoo will discuss the biggest threats and opportunities for businesses as we look to manage change in the South China Sea.
This MGBF Roundtable will feature thought leaders form Japan, Australia, Singapore and Malaysia dealing with the critical issues of manipulation of public listed companies and government and their financial impacts.
A series of networking sessions with various business associations and trade organisations exploring high-value opportunities for business leaders and entrepreneurs looking to build the relationships that matter.
This integrated event will include a forum, dedicated business matching, site visits, a gala dinner and a round of golf. Aptly themed, the focus will be on regional food security issues and trends in the context of the supply chain, agriculture technology and trade regulations and policies.
MGBF In The News
Planet QEOS and China Machinery Engineering Corporation (CMEC) are interested in investing RM10 billion to co-develop advanced Megawatt peak (MWp) agrovoltaic in Baram, to further boost Sarawak’s green energy initiative and food security. Sarawak Premier Datuk Patinggi Tan Sri Abang Johari Tun Openg was briefed on Friday by both the […]
Last week SPM results came out, 373,974 aspirants who have been waiting patiently over the last few months would now know their fate. Some 10,109 have received all A’s, the golden standard of academic success and the ticket to those looking to study the “more advanced” subjects in university. Proudly, […]
The classic knee-jerk reaction is to say, fire the coach, change the leadership of associations, and reduce the funding till they start performing better. This kind of negative reinforcement may work for kindergarten children, but we are dealing with high-performance adults – individuals much further along in their psychological and […]
Since its earliest tea plantations in 1929, Cameron Highlands has grown to become a key player in the agricultural landscape of Malaysia, producing 40 per cent of all vegetables grown. Despite Malaysia shifting its economic focus away from agriculture, the industry remains imperative for food security and the livelihoods of […]
Although at first glance the travel industry and the agricultural sector appear to have nothing in common, they actually share more than meets the eye. The economic benefits of tourism to the agricultural sector can be multiplied several times over. “Tourism brings the end consumers closer to the source, which […]
The Malaysia Global Business Forum (MGBF) recently held a high-level roundtable themed ‘Designing the Future of the Digital Economy’, attended by industry leaders and business associations. The guest of honour was Yang Berhormat Syerleena Abdul Rashid, the Member of Parliament (MP) for Bukit Bendera in Penang. The MP’s Special Session […]
The Malaysia Global Business Forum (MGBF) will be hosting a roundtable on ‘Designing the Future of the Digital Economy’ on 23 February 2023. It is the culmination of the first three MGBF Exclusive Roundtable Series titled ‘The Evolving Threat Matrix in the Digital Economy’ held throughout 2022. According to the […]
The Founding Chairman of the Malaysia Global Business Forum (MGBF), Nordin Abdullah, today spoke on Bernama TV’s leading English talk show, The Brief, hosted by Jessy Chahal, on the topic of a stable political reality and what that means for the Malaysian economy. Nordin said, “The first thing that it […]
More than 1,100 years ago, Muhammad ibn Musa al-Khwarizmi was developing the mathematical formulas that we know today as algorithms which now have become so intertwined with the business fortunes of global media giants and the very fabric of geopolitics. A series of recent high level international reports have revealed […]
KSK Land has been recognised by the Malaysia Global Business Forum (MGBF) for its role in attracting high net-worth individuals to Malaysia post-pandemic. The first challenge in investor attraction is “selling” the country. In the context of Asia, Malaysia is competing with some very established investment destinations. The second […]
Malaysia, in particular Kuala Lumpur, continues to position itself as a regional centre to do business, educate a family and enjoy a global lifestyle. One company, KSK Land, has taken the lead in positioning itself and the city of Kuala Lumpur as a property investment destination for the global citizen […]
The upcoming budget represents an opportunity to build resilience in the critical sectors that will form the backbone of the country’s future-facing economic ambitions. This however needs to be achieved in the context of managing the community sectors most impacted by COVID-19 over the past two years. The Keluarga Malaysia (Malaysian Family) […]
Malaysia Global Business Forum (MGBF) has moved to support the creative economy as the overall economy moves into a recovery phase following the COVID19 pandemic. As a step in the direction of normalcy, the MGBF has agreed to host the art exhibition “I Know You’re Somewhere So Far” by one […]
Congratulations to Datuk Seri Ismail Sabri Yaakob for taking up the mantle of the ninth prime minister of Malaysia. There is nothing normal about the situation; it could not have been scripted but it has kept the spectrum of media, mainstream and social, gripped. The first order of business for […]
In a stirring speech to the nation, President Joseph R. Biden, Jr. stamped his brand of leadership on the presidency, in his first act as the 46th president of the United State of America, it signaled several shifts. Perhaps the weather was foreboding with snow falling before the ceremony that […]
KUALA LUMPUR, 6 July 2022 – As the global economy continues to deal with unprecedented levels of disruption caused by the pandemic and the conflict between Russia and Ukraine, the convergence of energy security and food security issues has become a front-of-mind issue faced by policy makers and consumers alike. […]
KUALA LUMPUR, 23 June 2022 — Malaysia Global Business Forum (MGBF) ties up with scoutAsia to ensure that businesses are equipped with deeper regional insights. The past two years has seen a massive shift in the way businesses are conducted with digitisation, digitalisation and automation continuously being adopted to improve […]
KUALA LUMPUR, 25 May 2022 – The Malaysia Global Business Forum (MGBF)’s exclusive roundtable on ‘Security Concerns in Critical Value Chains’ was held in a hybrid setting yesterday at the Eastin Hotel Kuala Lumpur. The guest of honour was Yang Berbahagia Tan Sri Dato’ Seri Rafidah Aziz, former minister of […]
We live in the age of crisis. At the heart of any crisis is the threat of rapid change. Change too deep or too wide that the current coping mechanisms for an individual, corporation or government are unable to remain resilient. An unwelcome paradigm shift, like the proverbial spider, that […]