Ransomware, data disclosure and malware-as-a-service on the dark web. 1/2
21 May 2021 · 3 min

With the recent health crisis, cybersecurity has become a genuine cornerstone of our environment. It has to ensure the resilience of state and healthcare information systems, and it has to provide lasting conditions for remote working for those who can carry out their work from a distance.
2020, a year ripe for a rise in attacks
That resilience is severely tested by successive attacks on organisations across every sector. Cyberattacks, benefiting from an unprecedented crisis, show up as exponential growth in social engineering, phishing and the compromise of commercial assets — and, finally, a resurgence of malware and ransomware.
Hackers capitalise on the confusion and fear surrounding the pandemic, to take advantage of it and improve their odds of reaching a target. Phishing attacks have risen by around 665% since the crisis began, destabilising and paralysing ever more organisations, public and private alike. Examples include the hospital sector, with the cyberattack on AP-HP in March 2020*, the private sector with Sopra Steria in November 2020**, and local government with the city of Angers in January 2021***.
In 2020, ransomware ranked first among the most frequent and most dangerous risks of recent years.
[*] https://www.aphp.fr/contenu/les-echos-lap-hp-victime-dune-cyberattaque
Statement by the hackers behind the Maze malware, posted on the dark web, about Covid-19

What is a ransomware attack?
Ransomware attacks aimed at companies or institutions are meant, in the first instance, to obtain payment of a sum of money in exchange for releasing the encrypted data. Publicity is not part of the plan: everything can happen in complete discretion between attacker and victim. It is nevertheless common for attacks to be publicised on certain channels.
The main reason an attacker goes public is the victim’s refusal to pay the ransom. The ransomware operators then fall back on a far more classic practice: threatening to publish the victim’s data. This is a further step in the attempted extortion. The threat takes the form of a dedicated website run directly by the hacking team — very often a deep web site, backed by a mirror* on the dark web to counter attempts at domain name blocking.
Screenshots: threatening to publish the victim’s data.

On their site, the hackers list every victim who refuses to give in.
To begin with, they make a text file freely available giving the list of files they hold.
Extract from a list of encrypted files published by a hacking team.

What happens if the victim refuses?
Where the victim keeps refusing, the hackers trigger the first phase of retaliation: partial publication of the data itself. We have not been able to identify any common practice in the choice of which data goes out first. Depending on the case, it is more or less strategic and sensitive.
Publication of a first batch of data from a victim of the Egregor group.

If partial publication is not enough to make the victim yield, further files are released, up to the complete leak of the data. In this the process is exactly that of the very familiar blackmail-by-disclosure. Ultimately, the only novelty introduced by a ransomware attack conducted this way is the phase of encrypting the target’s data — in itself already a major handicap for the victim.
Classic blackmail-by-disclosure activity, with no ransomware involved.


The data is most often released as archives of varying size, depending on the mass of data the hackers collected. Some leaks run to several hundred gigabytes in total. Hackers also sometimes offer each file for download separately in an unsorted list. Others let you browse the data by reproducing the victim’s directory tree.
Unsorted data leak.

Reproduction of the victim’s directory tree

What is the profile of the victims? How do the hackers operate? What do we recommend?
The answers are in the next article: ‘Ransomware, data disclosure and malware as a service on the dark web, part 2/2.’