Ransomware, data disclosure and malware-as-a-service on the dark web. 2/2
3 June 2021 · 3 min

In part one of this article, we described what a ransomware attack is. We also described what can happen when victims refuse to pay the ransom. Finally, we illustrated the forms that data disclosure can take on the dark web.
Here is the second part.
Very small businesses are affected too
The profile of victims of groups such as Egregor — some of whom were arrested in Ukraine in February 2021 — confirms that the threat of a ransomware attack does not concern only companies or institutions of international scale and standing. Among the targets we do find large groups, but also mid-sized companies, such as a firm of 340 employees in the Rhône, or even a Canadian logistics company with fewer than 60.
Ransomware operators work on opportunity. The target’s economic profile matters little to them: it is the vulnerability of the IT system that determines how likely an attack is.
It will therefore be more profitable for a team to target several poorly protected small organisations than to spend effort breaking into the well-locked systems of a company alert to the risks.
Information system security is unfortunately neither everyone’s concern nor something every organisation can afford.
Ease of execution, combined with multiplied intrusion channels, is what made ransomware one of the most profitable attacks so quickly. The method is very widespread on the dark web, with an attack surface that keeps growing and a malware-as-a-service market taking shape.


Examples of ‘malware-as-a-service’ offered by hackers on the dark web.
ANSSI issues alerts, and recommendations too
This threat — cheap in means and potentially lucrative for attackers — is now embedded in the cyber threat landscape.
In September 2020, ANSSI issued an alert bulletin about Emotet, a particularly widespread piece of malware, noting a surge in French entities being targeted by this malicious code. France did not appear to be the only country affected: New Zealand and, notably, Japan were hit as well.

Discussions on a dark web forum about new targets (captured by Aleph Search Dark)

A paid request from a user seeking to use coronavirus as a propagation vector for the Emotet ransomware (captured by our software)
Beyond last September’s alert bulletin, the agency also published, on 29 October 2020, a study on malware-as-a-service, using Emotet’s activity as its example. This new trend allows a cyberattack to be outsourced to a hacker for a fee, with no knowledge required. This ‘uberisation’ of the cyberattack only amplifies existing threats. Anyone with the means can now buy a hacker’s services — from compromising a simple social media or email account to destabilising an entire information system.

Example of resources made available on the dark web for carrying out ransomware attacks.

‘Classic’ hacking services on the dark web
France remains a favoured target for hackers where this type of attack is concerned. The network affiliated with this ransomware was dismantled at the end of January 2021 by Europol. As attack vectors multiply, hackers take the opportunity to organise their activity into a genuine cyberattack trade. Not only is this the most widespread form of computer attack, its consequences are heavy for the organisations hit.
Caution seems the best first recommendation, because hackers’ imagination appears to have no limit. ANSSI publishes a number of recommendations in its guide. Every company is concerned, whatever its size, and so is every member of it, because the success of this kind of attack depends on human error.